BOOK A CALL BACK
Have a question? Fill in the form below to book a call
About:
Full Name*
Business Email*
Contact Number*
Booking Date*
Menu
REMOTE SUPPORT
 NETWORK STATUS
020 7471 3277
Book a call
ALL BLOGS

What are the EU Cyber Resilience Act (CRA) reporting obligations — and do they apply to you?

TL;DR: The EU Cyber Resilience Act makes security a legal requirement for connected products, and UK businesses selling into the EU are in scope too.

  • The CRA requires products with digital elements to be secure by design and supported with updates throughout their life
  • Reporting duties for actively exploited vulnerabilities and severe incidents began on 11 September 2026
  • Full technical compliance rules apply from 11 December 2027
  • UK businesses that manufacture, import, distribute or resell products into the EU, including IT resellers, have obligations under the CRA

If your business buys, sells or relies on connected hardware or software that touches the EU market, the EU Cyber Resilience Act is worth putting on your radar now rather than later. Reporting obligations started on 11 September 2026, and the fuller set of rules lands in December 2027. The obligations don’t stop at the manufacturer’s door, either. Here’s what it means for your business, and what to do about it.

What is the EU Cyber Resilience Act?

The Cyber Resilience Act (CRA) is EU law, specifically Regulation (EU) 2024/2847, that sets mandatory cyber security requirements for “products with digital elements” sold on the EU market. That’s a wide net: laptops, routers, smart devices, operating systems, mobile apps, industrial IoT equipment and more.

The principle behind it is simple. For years, security has often been treated as something to patch in after a product ships. The CRA flips that: products need to be secure by design, kept updated, and manufacturers need to be upfront about how long that support will last.

When do the CRA rules take effect?

The CRA is rolling out in stages rather than all at once, per the European Commission’s implementation timeline:

  • 10 December 2024: the CRA entered into force, starting the transition period
  • 11 June 2026: rules on notifying authorities and conformity assessment bodies began to apply
  • 11 September 2026: mandatory reporting duties began. In-scope organisations must report actively exploited vulnerabilities and severe incidents affecting products on the EU market
  • 11 December 2027: the full technical compliance requirements apply

That reporting isn’t a loose deadline either. Under the Single Reporting Platform run by ENISA, an initial report is due within 24 hours of becoming aware of a qualifying vulnerability or incident, with further detail following shortly after.

Does the CRA apply to UK businesses?

Yes. The CRA applies based on the EU market, not the manufacturer’s home country. If a UK business manufactures, imports, distributes or sells in-scope products into the EU, it has duties under the regulation. The specific obligations depend on which role you play in the supply chain:

  • Manufacturers: carry the heaviest duties, including secure design, vulnerability handling, documentation, and ongoing updates
  • Importers: the first business to bring a non-EU product into the EU market
  • Distributors: businesses that sell on an already-compliant product without altering it

What if we just resell hardware or software to clients?

Buying laptops or software licences from a manufacturer and reselling them to clients puts a business in the distributor category, a lighter set of duties than manufacturing, but not nothing. Distributors are still expected to check that products genuinely carry the required conformity marking before selling them on, keep storage and handling from undermining that compliance, and pass the manufacturer’s security and support information through to the end customer.

If a distributor becomes aware a product doesn’t comply, or discovers a vulnerability, it can’t simply keep selling and stay silent. The manufacturer needs to be told, and in serious cases, the relevant authorities too. One thing worth flagging for anyone doing white-labelling: putting your own branding on a product, or modifying it substantially, can shift you from distributor into manufacturer territory, with everything that entails.

What should businesses do to prepare?

Even though the full technical rules aren’t mandatory until December 2027, the reporting obligations are already live. It’s worth using this window to get ahead rather than scrambling later:

  • Map which products, software or connected devices your business sells or relies on that could fall in scope
  • Review suppliers of critical hardware and software: can they demonstrate compliance and clear support periods?
  • Check contracts and procurement processes for where cyber security responsibility actually sits
  • Confirm vulnerability disclosure and update processes exist and are documented
  • Update incident response plans so staff know how to escalate a qualifying vulnerability or incident
  • Keep evidence of risk assessments and supplier checks, you may need to show your working

Most businesses in this position don’t need to become CRA experts overnight. They need someone reviewing their supplier chain, checking that security and reporting processes actually hold up, and translating “in scope” into a short, practical list of fixes. That’s exactly what our managed cyber security service is built to do, backed by our own ISO 27001 certification. If you need to demonstrate baseline security controls to clients or regulators, our fully managed Cyber Essentials certification service is a practical, fast way to get there.

The CRA is a reminder that cyber security is no longer just an internal IT concern. It’s becoming a legal and contractual one, running through every link of the supply chain. If you’re not sure where your business stands or what your suppliers can actually demonstrate, get in touch with our team. We’ll walk through it with you before December 2027 arrives.