UKRAINE · POLAND · EUROPEA publication by Mitchell Strategic Solutions Group
MSSG News

Defence. Technology. European security.

Policy & markets
Explainer

Cyber Resilience Act: reporting duties start this September

11 September marks the start of reporting obligations. The main product requirements follow in December 2027.

Cyber Resilience Act: reporting duties begin
  • From 11 September 2026
  • Full application: December 2027
Thematic illustration: cybersecurity. jaydeep_ / Wikimedia Commons (CC0) · Image source · Licence

The European Commission’s implementation timetable sets 11 September 2026 as the start of reporting obligations under the Cyber Resilience Act. Full application follows on 11 December 2027. These are different milestones for manufacturers of products with digital elements.

Guidance published in July addresses scope, support periods, substantial modifications and reporting. The Commission describes it as non-binding. A company must still establish whether its particular product falls within the regulation.

For dual-use software and connected-device suppliers, our practical priority is ownership: who receives a security report, decides what it means and coordinates the response? Leaving that responsibility undefined creates avoidable delays. The timetable alone does not answer product-specific legal questions.

Sources & context

  1. European Commission: CRA implementation timetable
  2. European Commission: July implementation guidance

Published by Mitchell Strategic Solutions Group. See our editorial standards and corrections policy. Read more →

CYBER RESILIENCE ACTUkraineEurope