The Cyber Resilience Act obligations are being introduced in two stages. The reporting obligation under Regulation (EU) 2024/2847, known in Dutch as the Verordening cyberweerbaarheid, has been in effect since September 11, 2026. Product requirements, conformity assessment, and CE marking will follow on December 11, 2027. If you sell a product with digital elements under your own brand, you are the manufacturer.
On July 27, 2026, the European Commission published guidelines containing 67 practical examples. These are not binding, but they do demonstrate how the regulator interprets the regulation.
What applies already
Since September 11, 2026, a manufacturer must report every actively exploited vulnerability and every serious security incident in its product to the National Cyber Security Centre. The initial report must be sent within 24 hours. This obligation also applies to products that have been on the market for years.
This is where the misunderstanding currently affecting most dossiers lies. Many brands have December 11, 2027, in their calendars and assume that nothing is required until then. That is correct for product requirements. It is not correct for the reporting obligation.
Article 71 of the regulation stipulates that Article 14 applies as of September 11, 2026. Article 69, paragraph 3, extends this to all products within the scope. Products placed on the market before December 11, 2027, are also covered.
The Commission’s guidelines make the distinction even sharper. For a product placed on the market before December 11, 2027, the vulnerability management requirements from Annex I Part II do not apply. The reporting obligation, however, does apply. You do not need to change anything about that product, but you must know where to report as soon as something goes wrong.
If you were already aware before September 11, 2026, that a vulnerability was being actively exploited, you do not need to report it retrospectively. If you knew about the vulnerability but not about the exploitation, and that exploitation becomes apparent afterwards, the reporting obligation applies as usual.
| Date | Effective date | For which products |
|---|---|---|
| December 10, 2024 | Entry into force | No obligations yet |
| June 11, 2026 | Notification of test houses | Not applicable to manufacturers |
| September 11, 2026 | Reporting obligation Article 14 | All products within scope, including existing ones |
| December 11, 2027 | Product requirements, assessment, CE marking | Products placed on the market thereafter |
| June 11, 2028 | End of validity for old type certificates | Certificates from other harmonization legislation |
When you are the manufacturer
You are a manufacturer as soon as you place a product with digital elements on the market under your own name or trademark. Who actually manufactures the product is irrelevant. An importer selling an Asian design under their own brand therefore bears all the obligations the regulation imposes on a manufacturer.
Article 21 establishes this directly. An importer or distributor is considered a manufacturer as soon as they place the product on the market under their own name or trademark. The same applies in the event of a substantial modification to a product already on the market.
For Declaer’s target audience, this is the core of the matter. If you have products manufactured in Asia and put your own brand name on the box, you are legally the manufacturer. Your supplier is not. The size of your enterprise does not change this.
Small and micro-enterprises receive one mitigation. They are subject to the reporting obligation but will not be fined if they miss the initial 24-hour deadline. The report itself remains mandatory.
Do you have a question about your own product?
Let us know briefly what it concerns. We will contact you regarding what we can do and the costs involved.
We respond within 24 hours on business days. You may continue reading.
Which products are covered
A product with digital elements is hardware or software that can connect to a device or a network. Examples include a baby monitor, a smart doorbell, a smartwatch, a router, or an app. Individual components such as a microcontroller also fall under the regulation.
Article 3, paragraph 1, defines the term broadly: a software or hardware product and its remote data processing solutions. Individual components thereof also count. The cloud side of a smart thermostat is included, provided the product lacks a function without that connection.
Products already covered by specific sectoral rules fall outside the regulation. The regulation mentions medical devices under 2017/745 and 2017/746, motor vehicles under 2019/2144, and aviation products under 2018/1139.
If you sell radio equipment, you are already dealing with the requirements from Article 3, paragraph 3, points d, e, and f of the Radio Equipment Directive. The essential requirements of the Cyber Resilience Act encompass all those elements. This is explicitly intended so that one set of requirements remains once the Commission withdraws or amends the old delegated regulation.
How to file a report
In the Netherlands, a report is filed via the digital reporting portal of the National Cyber Security Centre. There is no prior registration requirement. The regulation requires three messages regarding the same case: an early warning within 24 hours, a report within 72 hours, and subsequently a final report.
You report in the Netherlands if your main establishment is located here. If your group has multiple European establishments, the entity with the main establishment reports to the designated CSIRT of that country. The NCSC ensures the report reaches ENISA and the other member states. You therefore report in one place.
| Step | Deadline | What you provide |
|---|---|---|
| Early warning | 24 hours | Notification and in which member states your product is available |
| Report | 72 hours | The product, the nature of the vulnerability, and your measures |
| Final vulnerability report | 14 days | After making a solution available |
| Final incident report | 1 month | After the 72-hour report |
All deadlines start the moment you become aware of the vulnerability or the incident. The Commission’s guidelines clarify this: you have knowledge as soon as you have reasonable certainty, following an initial assessment, that exploitation is occurring. You must perform that initial assessment immediately.
Not everything is worth a report. A vulnerability you find yourself, one that comes from a penetration test, or one received via responsible disclosure without known exploitation, does not need to be reported. The obligation only arises upon reliable evidence of exploitation.
If the vulnerability is in a component you have purchased, you report it for your own product. If the vulnerable piece of code in your product is not accessible or demonstrably not exploited, you do not need to report it. You must, however, pass the vulnerability on to the manufacturer of that component.
When a test house is required
The regulation distinguishes four categories. For a regular product, a self-assessment suffices. Annex III also designates important products in Class I and Class II. Annex IV lists critical products. For these categories, a notified body is required if harmonized standards are missing.
Class I of Annex III is the category for consumer electronics brands to check. It includes, among others:
- Smart home products with a security function, specifically smart door locks, security cameras, baby monitors, and alarm systems.
- Internet-connected toys that can speak, film, or track location.
- Personal wearables for health monitoring and all wearables intended for children.
- Routers, modems, and network switches intended for connection to the internet.
- Smart home virtual assistants for general purposes.
For Class I, you may perform the assessment yourself, but only if you fully apply the harmonized standards. If those standards do not exist, Article 32, paragraph 2, prescribes an EU-type examination or full quality assurance. This means a notified body and therefore lead time and costs.
Determining whether your product falls into a category is done based on its primary functionality. Implementing Regulation (EU) 2025/2392 contains the technical descriptions for this. The distinction between core function and supporting function is decisive: a smartphone with a password manager on it does not itself become a password manager.
Cyber Resilience Act obligations from December 11, 2027
From December 11, 2027, a product with digital elements must comply with the essential requirements of Annex I. This includes a documented risk assessment, a technical file, a conformity assessment, an EU declaration of conformity, and the CE marking. Without that package, the product may not be placed on the market.
An obligation will also be added that extends beyond the sale. You determine a support period appropriate to the expected product lifetime, with a minimum of five years. During that period, you address vulnerabilities with free security updates. You must keep every released update available for a further ten years.
The transition is less abrupt than it seems. Products placed on the market before December 11, 2027, only fall under the requirements if they are substantially modified thereafter. And for a model designed before that date, the guidelines state you do not need to redesign. You perform a risk assessment to demonstrate that existing measures are sufficient.
What you must be able to provide is the substantiation. The risk assessment belongs in the technical file, along with the information on which you based the support period. If an essential requirement is missing, you justify in that same file why it is not applicable.
What you should arrange now
For the reporting obligation, you do not need a product change, but you do need a procedure. Establish who within your organization assesses whether exploitation is occurring, who reports, and via which channel. Without such an arrangement, the 24-hour deadline will expire while you are still figuring things out.
Four things that can be done now, without waiting for 2027:
- Designate a central contact point where users and researchers can report a vulnerability. This will be mandatory from 2027. Without such a point, a report will only reach you via a detour.
- Create an account on MijnNCSC or establish that you will use the open reporting form. In MijnNCSC, the warning, the report, and the final report are kept together.
- Document which components are in your product, down to the open-source libraries in the firmware. Without that list, you will not know if your product is affected when a vulnerability is reported.
- Contractually establish the support period with your supplier. You are promising the market five years of updates. Your manufacturer in Asia almost certainly has not made that commitment yet.
Sanctions are set out in Article 64. For the essential requirements and Articles 13 and 14, fines can reach 15 million euros. If 2.5 percent of the total worldwide annual turnover is higher, that amount applies. For other obligations, the limit is 10 million euros or 2 percent.
In the Netherlands, the Dutch Authority for Digital Infrastructure (RDI) provides oversight. This inspectorate also designates the test houses. The NCSC is explicitly not a regulator: a report there is not a fine notification or a criminal complaint.
- Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, Articles 13, 14, 21, 32, 64, 69 and 71, text on EUR-Lex
- European Commission, C(2026) 5252, guidelines on the application of the Cyber Resilience Act, July 27, 2026, announcement and documents
- Dutch Authority for Digital Infrastructure, Cyber Resilience Act, oversight and product categories
- National Cyber Security Centre, reporting under the Cyber Resilience Act, the Dutch reporting portal
Legal expert with a background in e-commerce. Writes about the rules he applies daily in files for brands and manufacturers. More about Francois
Frequently Asked Questions
Do I need to do something now or only in December 2027?
I have products manufactured in China and put my brand on them. Who is the manufacturer?
Must I report every vulnerability in my product?
Do I need a notified body for my product?
What happens if I do not report?
Prefer not to figure it out yourself?
We build technical files for brands and manufacturers, from the risk assessment to the declaration you sign. Send us your product and you will receive a proposal within 24 hours with a fixed price and lead time.
View the CE process