The Cyber Resilience Act Clock: What Changes on 11 September 2026
TL;DR: On 11 September 2026 the Cyber Resilience Act switches on its reporting obligations. From that date, any manufacturer whose product with digital elements is on the EU market must report an actively exploited vulnerability within 24 hours, file a full notification within 72 hours, and close it out within 14 days. Brexit does not exempt you: the Cyber Resilience Act follows the market, not the manufacturer’s address. Fines reach 15 million euro or 2.5% of worldwide annual turnover, whichever is higher. Full application follows on 11 December 2027.
Last updated: 28 July 2026
On this page
Key takeaways
- Reporting obligations under the Cyber Resilience Act start on 11 September 2026. Full application is 11 December 2027.
- The trigger is an actively exploited vulnerability or a severe incident: 24 hours to an early warning, 72 hours to a full notification, 14 days to a final report.
- Scope follows the market. A UK manufacturer placing a product with digital elements on the EU market is in scope regardless of where it is established.
- Fines run to 15 million euro or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential requirements.
- If you buy connected hardware rather than make it, the Cyber Resilience Act is a procurement question: support periods, SBOMs and declared conformity now belong on the spec sheet.

What is the Cyber Resilience Act?
The Cyber Resilience Act is the first EU-wide law setting mandatory cybersecurity requirements for products with digital elements, covering hardware and software across the whole product lifecycle. The Cyber Resilience Act entered into force on 10 December 2024 and applies in full from 11 December 2027, with obligations phasing in before that.
Products with digital elements, the category the Cyber Resilience Act governs, is deliberately wide. It takes in IoT sensors, gateways, industrial routers and switches, controllers, embedded firmware and the software that runs on any of it. If it processes or transmits data and it reaches the EU market, the regulation is interested in it.
What the Cyber Resilience Act asks for is unglamorous and familiar to anyone who has read IEC 62443: security by design against the essential requirements in Annex I, a documented risk assessment across planning through maintenance, effective vulnerability handling for a declared support period, technical documentation, an EU declaration of conformity and CE marking before the product goes on the market. The support period end date has to be stated at the point of purchase.
Does it apply to UK companies?
Yes, if your product reaches the EU market. The Cyber Resilience Act attaches itself to where a product is made available, not to where the manufacturer is established, so a company outside the EU that sells into the Union is in scope and must have an economic operator inside the EU responsible for the relevant obligations.
The Cyber Resilience Act therefore catches more UK businesses than the headline suggests. A UK integrator shipping a configured gateway to an EU site is placing a product on the EU market. So is a firmware vendor distributing an update to EU customers, whether or not money changes hands, because availability free of charge still counts.
The practical read for most UK industrial buyers is different, though, and it is the one worth acting on: you are far more likely to be affected as a customer of in-scope manufacturers than as a manufacturer yourself. That changes what you should be doing about it, and we come back to it below.
What changes on 11 September 2026
From 11 September 2026 the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of their products. The clock is short and it starts when you become aware, not when you finish investigating.
| Deadline | What is due |
|---|---|
| 24 hours | Early warning of an actively exploited vulnerability or severe incident |
| 72 hours | Full notification |
| 14 days | Final report on an actively exploited vulnerability, once a corrective measure is available |
| 1 month | Final report on a severe incident |
Reporting goes through a single route. Manufacturers file once via the CRA Single Reporting Platform to the CSIRT in the territory of their main establishment, and the information is made available to ENISA at the same time unless exceptional circumstances apply. The receiving CSIRT then shares it without delay with CSIRTs in every territory where the product is available. ENISA‘s responsibility for developing the platform sits in Article 16, and the platform is to be operational by 11 September 2026 with testing beforehand.
One earlier date is easy to miss. Member States had to notify conformity assessment bodies by 11 June 2026, which means the certification capacity that Class I, Class II and critical products will need is only now coming online.

The three product classes
How much external scrutiny a product needs under the Cyber Resilience Act depends on which class it falls into. The regulation sets three tiers, and the assessment burden rises sharply between them.
- Default products. The large majority. Self-assessment against the essential requirements, or third-party review if the manufacturer prefers.
- Important products, Class I and Class II. Third-party assessment or certification, with Class II carrying the heavier route.
- Critical products. Mandatory third-party assessment.
For industrial IoT the Cyber Resilience Act bites hardest around network and security infrastructure, where devices that segment or protect a network tend to sit above the default tier. It is worth checking classification early, because the difference between a self-assessment and a notified-body assessment is a difference in lead time, not just in paperwork.

What it costs to get wrong
Article 64 sets three penalty tiers, and each is expressed as a fixed sum or a share of worldwide turnover, whichever is higher. That second limb is what makes the numbers serious for a large group and survivable for nobody.
| Breach | Maximum fine |
|---|---|
| Essential cybersecurity requirements (Annex I) and Articles 13 and 14 | 15 million euro or 2.5% of worldwide annual turnover |
| Other specified obligations | 10 million euro or 2% of worldwide annual turnover |
| Incorrect, incomplete or misleading information to authorities | 5 million euro or 1% of worldwide annual turnover |
Two Cyber Resilience Act carve-outs are worth knowing. Microenterprises and small enterprises are exempt from fines for missing the 24-hour reporting deadline specifically, and open-source software stewards are exempt from CRA penalties. Neither exemption removes the underlying obligations.

If you buy industrial IoT rather than build it
Most UK estates and plants reading this are buyers, not manufacturers, and the Cyber Resilience Act reaches them anyway. The Cyber Resilience Act still changes your job, because it hands you leverage you did not previously have. Every question below now has a documented answer somewhere, and a supplier who cannot produce it is telling you something.
- What is the support period, and when does it end? The end date must be stated at purchase. A sensor with a ten-year design life and a three-year support period is a replacement plan, not a purchase.
- Is there a software bill of materials? An SBOM is what makes vulnerability tracking possible at all. Ask for it now rather than during an incident.
- How will I be told about an exploited vulnerability? The manufacturer’s 24-hour clock is with the regulator. Yours is with them, and it needs to be contractual.
- Which class is this product, and how was conformity assessed? Self-assessed or notified body, and against what.
- Who is the EU economic operator? For a non-EU manufacturer, somebody must hold the obligations. Knowing who is knowing whether the chain is real.
None of this is exotic. It is the same discipline behind IT and OT segmentation, and it complements rather than replaces the architectural controls we cover in data diodes and IT/OT segmentation and OT cybersecurity best practices, and it sits alongside the OT cybersecurity for CNI work we do. A regulation that forces manufacturers to declare a support period does more for real-world security than most bolt-on controls, because it kills the silently abandoned device.
Five steps before September
Six weeks is enough for Cyber Resilience Act preparation and not enough for a programme. Prioritise accordingly.
- Decide whether the Cyber Resilience Act makes you a manufacturer. If anything you build, configure or rebrand reaches the EU market, you are in scope and the rest of this list is mandatory rather than prudent.
- Inventory the connected estate. Every device with firmware, its vendor, its version and its support status. You cannot report on what you cannot list.
- Get SBOMs where you can. Ask each vendor. Note who refuses, because that is a risk register entry.
- Write the notification path. Who inside your organisation receives a vendor advisory, and what happens in the first 24 hours.
- Put the questions into procurement. Support period, SBOM, product class, conformity route and EU economic operator, on every purchase order from now.

Frequently asked questions
Does the Cyber Resilience Act apply after Brexit?
It applies to products placed on the EU market regardless of where the manufacturer is established. UK companies exporting products with digital elements into the EU are in scope and must have an EU-based economic operator responsible for the relevant obligations. The UK has no equivalent regime for products with digital elements, though the Cyber Security and Resilience Bill introduces its own 24 and 72 hour reporting clock for operators of essential and digital services.
What counts as a product with digital elements?
Hardware or software whose intended use includes a direct or indirect data connection. In practice that covers IoT sensors, LoRaWAN gateways, industrial routers and switches, controllers, embedded firmware and standalone software. Availability free of charge still counts as placing on the market.
What has to be reported within 24 hours?
An early warning about an actively exploited vulnerability in your product, or a severe incident affecting its security. A full notification follows within 72 hours and a final report within 14 days once a corrective measure exists, or within a month for a severe incident.
Do I need an SBOM to comply?
Manufacturers must handle vulnerabilities effectively throughout the declared support period, and in practice that is not achievable without knowing what components a product contains. Treat an SBOM as the working prerequisite for the vulnerability-handling obligations rather than a separate box to tick.
What are the fines under the Cyber Resilience Act?
The Cyber Resilience Act allows up to 15 million euro or 2.5% of total worldwide annual turnover, whichever is higher, for breaching the essential requirements. Lower tiers of 10 million euro or 2%, and 5 million euro or 1%, apply to other obligations and to supplying misleading information to authorities.
Ask your suppliers, or ask us
The Cyber Resilience Act rewards buyers who ask early. Every product we sell comes with its manufacturer datasheet and a named brand behind it, so the support-period and conformity questions above have somewhere to go. If you are auditing a connected estate ahead of September and want the vendor answers gathered in one place, send us the device list and we will come back inside one working day. Start with our OT security range, the BlackBear data diode line, or request a quote.
Next step
Get a priced kit list for your site
Answer three quick questions and tell us where to send it. An engineer replies within one working day with the parts, the prices and the lead time.
Rather talk it through? Call 023 9223 3611
Received. An engineer has it.
You will hear back within one working day with the parts, the prices and the lead time. A confirmation is on its way to your inbox.
If it is urgent, call 023 9223 3611.