September 9, 2026
Key Points
- EU Cyber Resilience Act reporting requirements begin on Sept. 11 for manufacturers of connected products.
- CRA compliance requires cybersecurity expertise, vulnerability management, software supply chain security and incident reporting.
- Manufacturers need clear governance and documented evidence to demonstrate CRA readiness.
Today’s connected devices are no longer merely software-enabled hardware. Many of these sophisticated devices operate within digital ecosystems, relying on cloud services, third-party code, over-the-air updates and continuous data flows, which can increase cybersecurity risks.
In response to the evolving cyber risk profile for manufacturers, the European Union’s Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements across their life cycle.
Full application of the EU CRA will begin on Dec. 11, 2027, but the first major operational test arrives this month. Beginning on Sept. 11, manufacturers that market in Europe must report actively exploited vulnerabilities and severe incidents affecting products with digital elements. This obligation applies to products already on the EU market and may also affect products still in development that fall within the scope of the CRA. Non-compliance could result in fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
The scale of the challenge is growing. The number of connected devices worldwide is forecast to rise from approximately 21.1 billion in 2025 to 39 billion by 2030. As connectivity spreads across industrial systems, infrastructure, medical devices and consumer products, weaknesses in cybersecurity or data resilience can have an enormous, enduring impact on an organization’s reputation and business performance.
Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches begin with software vulnerabilities and that threat actors are using generative AI during multiple stages of attack. As data breaches have made headlines around the globe, stakeholders now expect security to be built in from the start.
For manufacturers, the CRA matters because it links cybersecurity directly to product acceptance. Secure-by-design development is increasingly important to market readiness, alongside such critical factors as safety, quality and environmental performance.
Leading manufacturers now strive to embed cybersecurity throughout the product life cycle, supported by risk assessments, secure development practices, vulnerability disclosure processes and ongoing maintenance.
Proactively Addressing Security
Software supply chain security is one of the most closely watched CRA readiness issues. Today’s products can contain thousands of components from multiple sources, creating visibility and governance challenges. ENISA’s 2025 threat landscape analysis reviewed 4,875 incidents across the EU threat ecosystem, highlighting the scale of the cyber risk environment for manufacturers.
Component visibility, software bills of materials (SBOMs), vulnerability handling and supplier governance all play critical roles in product cybersecurity. Organizations that address these areas early will be better positioned to move from reactive issue management to proactive, structured product security governance.
Navigating an Increasingly Complex Regulatory Landscape
The CRA lands in a crowded European regulatory landscape that includes the Network and Information Security directive (NIS2), the Digital Operational Resilience Act (DORA), the Data Act and other cybersecurity reforms. Each is reshaping expectations around resilience, incident reporting, governance and supply chain security.
For businesses, a key challenge is knowing where these requirements overlap. A strategic, cohesive approach can help organizations use existing investments more effectively, rather than building a separate program for each new obligation.
A Critical Milestone
The CRA’s first major operational milestone arrives this month. Starting on Sept. 11, manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements through the CRA Single Reporting Platform, with an early warning within 24 hours and a full notification within 72 hours.
For some lower-risk products, manufacturers may be able to follow a self-declaration route, but they still need robust technical documentation, cybersecurity evidence and governance to demonstrate conformity.
The CRA reporting timeline begins as soon as an organization becomes aware of a reportable event. It is not affected by normal business hours, weekends or holidays. Manufacturers therefore need clear triage, escalation and reporting processes in place before an incident occurs.
Manufacturers will need to have a firm grasp of the following factors:
- Which products are in scope
- Who owns reporting decisions
- Which Computer Security Incident Response Team (CSIRT) is relevant
- How notifications will be prepared
- The reporting process for manufacturers without an EU presence
These factors make CRA reporting an operational capability. Product security, engineering, legal, compliance and communications teams need a shared workflow that enables evidence-based action in hours, not days.
How UL Solutions Can Help Organizations Prepare
For manufacturers, CRA readiness will require structured evidence, robust product security processes and clear governance across the product life cycle. By combining testing, inspection and certification (TIC) services, conformity assessment, surveillance and advisory services, UL Solutions is helping organizations understand how existing cybersecurity processes, technical evidence and quality systems can support their preparation for CRA implementation.
UL Solutions supports manufacturers as they translate CRA compliance requirements into actionable initiatives throughout the product life cycle. That support is underpinned by continued investment in cybersecurity expertise, assessment methodologies and regulatory readiness. As part of this work, the certification entity UL International (Netherlands) B.V. has made significant progress toward becoming a CRA Notified Body. It has achieved EN ISO/IEC 17065 accreditation (under registration C 648) from the Dutch Accreditation Council (RvA) for CRA Module B, EU Type Examination activities. While the final notification process remains ahead, this accreditation represents an important step in the CRA journey.
Looking Beyond Compliance
The CRA reflects a broader shift in market expectations: Customers, regulators, investors and supply chain partners increasingly expect products to be secure, transparent and resilient by design.
The organizations best able to adapt will treat cybersecurity as a business capability, not a compliance burden. And if their products are exposed to real-world exploitation, their reporting processes must be able to respond swiftly, avoiding excessive downtime.
The Cyber Resilience Act is intended to be an important building block for a more secure digital economy. For leading manufacturers, the shift from compliance to confidence has already begun.
More information on key dates and business strategy is available on the Cyber Resilience Act guide page at UL.com.