Which product requirements apply when selling on Bol?

Anyone selling on Bol is responsible for product requirements under European legislation. These include CE marking, general product safety under the GPSR, energy labeling via EPREL, and requirements for batteries and packaging. Furthermore, for each of these, you must be able to substantiate with documentation that your product complies.

Exactly which rules apply depends on what you are selling. The most common product requirements are therefore as follows:

The common thread is evidence. After all, a marketplace, a regulator, or a buyer does not just want to hear that it is correct. They want to see the file. In short, that is what product requirements are all about.

Why does Bol check these product requirements?

Bol checks product requirements because the marketplace itself has a duty of care. Since the GPSR came into force in December 2024, platforms must verify whether products comply with European rules. Bol therefore asks sellers for a verifiable file. If this is missing, a listing may be blocked or a request from the regulator may follow.

Furthermore, the responsibility does not lie solely with the manufacturer. After all, the GPSR also imposes a duty on the marketplace. As a result, Bol must be able to show that the products on the platform comply with the rules. It then passes that requirement on to the sellers.

For you, product requirements are shifting from an afterthought to a prerequisite. After all, a complete file is the difference between selling undisturbed and a blocked listing or questions from the regulator.

What does this mean for you as a seller on Bol?

For you as a seller on Bol, it means that product requirements are no longer a side issue. You need a file that covers CE, GPSR, EPREL, batteries, and packaging, and that holds up if Bol, a regulator, or a buyer requests it. A recognized partner takes that work off your hands and delivers a file that passes the test.

The good news is that you don’t have to figure it out yourself. What many sellers get stuck on is not the rule itself, but the question preceding it. Does this apply to my product? What do I ask my supplier? And where do I start?

Ask your supplier for supporting documentation, not just the CE logo

A supplier claiming CE does not always have the reports. The first question is therefore not whether the product has CE, but which test reports and declarations they can send today. That determines whether your file holds up if Bol or a regulator asks for it.

Declaer answers those questions and subsequently builds the underlying file. This way, with a fixed price in advance and a proposal within 24 hours, you know exactly where you stand before you begin.

Do you sell on Bol and have doubts about your file?

Briefly let us know what kind of product it is. We will determine the route and send a fixed-price quote within 24 hours.


    If it concerns a product, briefly mention what it is and what it does.


    This is where we send the answer.


    Only fill this in if you prefer to be called.

    Declaer is a recognized compliance partner of Bol

    Declaer is a recognized compliance partner of Bol and is listed on the Bol Certified Partners platform under the Legislation and Certification category. Additionally, Declaer holds bronze partner status, the highest rank for a product compliance partner. This is proof that we manage product requirements on Bol for sellers every day.

    The partner platform is a showcase, not a referral. Bol uses it to highlight parties that sellers can work with to get their affairs in order. Under the Legislation and Certification category, you will find the agencies that help ensure products demonstrably comply with European rules. Furthermore, Declaer was the first to be admitted under the tightened conditions.

    Official label: bol. partner, bronze product compliance
    The official Bol partner label. Bronze is the highest partner rank for product compliance.

    The rank is called bronze. That may sound modest, but it is the ceiling for a compliance partner. A party in this category cannot achieve a higher rank. The fact that Declaer is the first to enter under the new conditions speaks to the way we build our files.

    Sources
    Sources verified on October 2, 2026
    Francois Frietman
    Founder of Declaer

    Legal expert with a background in e-commerce. Writes about the rules he applies daily in files for brands and manufacturers. More about Francois

    Frequently Asked Questions

    Which product requirements does Bol check?
    Bol looks at the rules that apply per product group: CE marking, general product safety under the GPSR, energy labeling via EPREL, and requirements for batteries and packaging. Furthermore, you must be able to substantiate with documentation that your product meets those requirements.
    Does Bol refer sellers directly to Declaer?
    No. The Bol Certified Partners platform promotes verified parties, but Bol does not automatically refer sellers. A seller chooses a partner from the overview themselves. Declaer is listed there under the Legislation and Certification category.
    Does Declaer only work for sellers on Bol?
    No. Declaer manages product compliance for brands and manufacturers, regardless of the sales channel. The recognition by Bol is a confirmation, not a limitation. The same approach and documentation apply outside of Bol as well.

    Prefer not to figure it out yourself?

    We build the compliance file for brands and manufacturers, from the scope to the declaration you sign. This way, you receive a quote within 24 hours with a fixed price and lead time.

    View our services
    Short answer

    Since September 27, 2026, a series of prohibitions apply to sustainability claims on packaging under all circumstances. Terms such as green, ecological, or climate-friendly are only permitted when accompanied by a recognized eco-label. Proprietary sustainability logos without a certification scheme are no longer allowed. Climate-neutral claims based on offsetting are completely prohibited.

    The rules are set out in Article 6:193g of the Civil Code, points ab through am. The ACM (Authority for Consumers and Markets) oversees compliance. There is no exception for packaging already printed in your warehouse, though there is an agreement on how regulators handle such cases.

    Which sustainability claims on packaging are now prohibited

    Since September 27, 2026, Dutch law includes twelve new commercial practices that are considered misleading under all circumstances. These are listed in Article 6:193g of the Civil Code, points ab through am. Four concern environmental claims and labels, one concerns legal requirements as a selling point, and the remainder concern lifespan and repair.

    These provisions originate from Directive (EU) 2024/825, commonly known as the EmpCo Directive. The Netherlands implemented this through the Implementation Act for the Directive on Improving Sustainability Information for Consumers, Bulletin of Acts and Decrees 2026, 152. The law amends Book 6 of the Civil Code. The Authority for Consumers and Markets (ACM) has been designated as the regulator.

    Misleading under all circumstances means that the regulator does not need to prove that the consumer was actually misled. The practice is blacklisted. Consequently, it is prohibited regardless of the context.

    The new points of Article 6:193g Civil Code
    PointWhat is prohibitedPrimarily affects
    abDisplaying a sustainability label that is not based on a certification scheme or established by a public authorityProprietary logos on the box
    acMaking a generic environmental claim without recognized excellent environmental performanceGreen, eco, environmentally friendly
    adMaking an environmental claim about the entire product when it only applies to a specific partRecycled material
    aeClaiming that a product has a neutral or positive impact through greenhouse gas offsettingClimate neutral, CO2 neutral
    afPresenting legally mandatory requirements as a distinguishing feature of your offerCE, RoHS, EU standards in listings
    ag, ahWithholding that a software update has a negative impact. Presenting an update as necessary when it only adds functionsProducts with an app
    aiAdvertising a product with a feature that deliberately limits its lifespanPlanned obsolescence
    ajFalsely claiming that a product has a certain lifespanLasts ten years
    akPresenting a product as repairable when it is notRepairable, sustainable design
    al, amInducing premature replacement of consumables. Falsely claiming that non-original parts impair functionalityFilters, cartridges, accessories

    Whether you can still use ‘eco’

    A general environmental claim such as green, ecological, environmentally friendly, or biodegradable is only permitted when you can demonstrate recognized excellent environmental performance. This can be achieved in three ways: the EU Ecolabel, a national Type I ecolabel such as Milieukeur, or a top-tier rating under other European legislation, such as the energy label.

    The legislator specifies the terms covered in the recitals of the directive itself: environmentally friendly, eco-conscious, green, nature-friendly, ecological, ecologically responsible, climate-friendly, gentle on the environment, low-carbon, energy-efficient, biodegradable, and bio-based.

    There is a second route, which is the most practical for most brands. An environmental claim is only generic when the specification is missing. If you place the substantiation clearly on the same medium—such as the same box or the same product page—then the claim is not generic. The prohibition of point ac then does not apply.

    The difference in an example

    ‘Climate-friendly packaging’ is a generic claim. ‘100 percent of the energy used to produce this packaging comes from renewable sources’ is a specific claim. The latter does not fall under the prohibition, but it must, of course, be true and substantiated.

    Be careful about what you use as a specification. The claim and the substantiation must concern the same thing. ‘Energy-efficient’ may be substantiated with an energy label under Regulation (EU) 2017/1369. ‘Biodegradable’ cannot be substantiated with the EU Ecolabel if that label does not set biodegradability requirements for your product group.

    Terms such as ‘conscious’, ‘sustainable’, or ‘responsible’ fall outside the ecolabel escape route anyway. These words refer not only to environmental characteristics but also to social characteristics, which an eco-label says nothing about.

    You may only display a sustainability label if it is based on a certification scheme or established by a public authority. A self-designed green circle with the word ‘eco’ in it is no longer allowed. According to the Commission, labels from public authorities outside the European Union are also excluded unless they are backed by a certification scheme.

    A certification scheme is strictly defined in the law. It must be open to all traders under fair conditions. The requirements must be developed with experts. There must be a procedure for non-compliance, including suspension or withdrawal of the label. Oversight must be conducted by an independent third party. A proprietary brand program without external auditing does not meet these criteria.

    For brands manufacturing in Asia, there is a second pitfall. In its Q of September 22, 2026, the Commission states that labels from public authorities outside the Union do not fall under the exception. A national environmental label from the country of production is therefore not a free pass unless a certification scheme is behind it.

    The concept of a ‘label’ is broader than just a logo with a name. The Commission explicitly warns against visual elements in the artwork. Green leaves, water droplets, and similar nature icons can be interpreted by the average consumer as an implicit environmental claim or as a voluntary label. This depends on the context, placement, and the overall impression of the packaging.

    The test applied by the regulator

    The benchmark is the average consumer: reasonably well-informed, observant, and circumspect. This is not a statistical test. The ACM does not need to conduct consumer research to determine that your leaf icon comes across as a label.

    Why ‘CE-approved’ is no longer a selling point

    Since September 27, 2026, it is misleading under all circumstances to present a legal obligation as a distinguishing feature of your offer. CE marking, RoHS, or an EU safety standard applies to every product in the category. Including such a requirement in your product description as a benefit is therefore no longer permitted.

    This is point af, listed as point 10 bis of the blacklist in the directive. It is placed among the environmental provisions but does not concern sustainability. For brands selling via marketplaces, this is an immediate issue. The type of bullet point targeted by this prohibition includes ‘CE-approved’, ‘meets all EU safety standards’, or ‘RoHS-compliant’.

    The prohibition does not concern the marking itself. Affixing the CE marking remains mandatory where legislation requires it. The Declaration of Conformity remains the document you sign. It concerns the presentation: you may not present the obligation as something that distinguishes your offer.

    There is an exception, which is strictly limited. The Commission confirms that the prohibition does not apply if the requirement only applies to a part of the category. Competing products on the Union market would then fall outside of it. If the requirement applies to everything in your category, you fall under the prohibition. The same reasoning applies to requirements from third countries.

    A related prohibition is found in Article 6:193c of the Civil Code: advertising a benefit that is both irrelevant and does not result from any characteristic of the product. The directive cites ‘gluten-free bottled water’ as an example. Water naturally contains no gluten, so it is not a characteristic of that brand. ‘Nickel-free jewelry’ is permitted, as some jewelry does indeed contain nickel.

    What to do with packaging that has already been printed

    There is no transitional arrangement for old stock. The rules also apply to packaging that was already printed or delivered before September 27, 2026. However, European consumer authorities have agreed that in cases of genuine transitional problems, they will enforce in phases and not immediately demand destruction or recall.

    This agreement is set out in the ‘Common Understanding on old stock situations’ by the Consumer Protection Cooperation Network, the association of European consumer authorities. The ACM published the document on July 1, 2026, with a Dutch explanatory note. It is explicitly not a binding interpretation of the directive, but a shared approach for how regulators exercise their powers.

    The core principle is that authorities can take objective constraints into account: packaging cycles, stock volumes, previously placed production orders, supply chain dependencies, long shelf life, and the technical feasibility of a correction. They may refrain from requiring destruction or a recall if it would result in disproportionate costs or unnecessary environmental damage.

    In return, they expect certain efforts from you. The document lists the actions they consider reasonable:

    • Removing or correcting online claims. Digital communications can be adjusted today, so that is the first thing they will look at.
    • Updating advertisements and promotional materials. The same argument as above.
    • Adjusting new packaging and new orders. What has not yet been printed must go to press correctly.
    • Applying stickers or removing labeling where feasible and proportionate.
    • Displaying corrective information at the point of sale, including online, for the products concerned.
    • Coordinating with suppliers and other parties in the chain.
    • Documenting what you did and when, including internal guidelines and substantiation work.

    This last point is the one brands often underestimate. The phased approach applies to those who are demonstrably taking action. Without a file showing what you adjusted and when, you have no demonstrable effort. In that case, there is nothing for the regulator to take into account.

    Do you have doubts about a claim on your packaging?

    Briefly let us know which product is involved. We will contact you regarding what we can do and the associated costs.

    Response within 24 hours on business days.

    Your question has been received

    We respond within 24 hours on business days. You may continue reading.

    How the Packaging Regulation overlaps

    Two regimes overlap on packaging. Consumer rules determine whether you may make a claim. The Packaging Regulation additionally sets requirements for claims about recyclability, recycled content, and reusability. Those claims may only be made if they exceed the legal minimum requirement. You must demonstrate this in your technical documentation.

    Article 14 of Regulation (EU) 2025/40, the PPWR, has been in effect since August 12, 2026. It sets two requirements for an environmental claim about a packaging property for which the regulation itself provides rules. The claim may only concern what exceeds the minimum requirements, calculated according to the methods in that regulation. Additionally, the claim must specify what it applies to: the packaging unit, a part thereof, or all packaging you place on the market.

    The final sentence of that article is what determines the workload. Compliance with these requirements must be evident from the technical documentation accompanying the packaging, as referred to in Annex VII. A recyclability claim is therefore no longer a marketing choice but a file item alongside your conformity assessment.

    In practical terms, this means the following: ‘100 percent recyclable’ has only been a valid claim since August 12, 2026, if you can show that your packaging exceeds the minimum requirement of the PPWR. You calculate this using the rules from that regulation. Anyone without that substantiation is making a claim that goes too far under both the Packaging Regulation and Article 6:193g of the Civil Code.

    What to remove from your box now

    Start with the artwork files held by your supplier, not your website. Inventory every claim, every logo, and every green visual element on the box, label, and manual. Document the basis for each claim. Only then should you determine what must be removed, what you will specify, and what can remain.

    1. Retrieve the artwork from your supplier. Not the sales photo, but the print file, including multilingual variants. These often contain claims that never passed through your marketing department.
    2. Mark three categories. Text claims. Logos and labels. Visual elements such as leaves, earth, water droplets, and green areas.
    3. Find the substantiation for each claim. A test report, a certificate, a calculation, or nothing. ‘Nothing’ is also a result. Then you know the claim must be removed.
    4. Test the labels. Is the label based on a certification scheme with independent oversight, or was it established by an EU public authority? If not, it must be removed.
    5. Delete offsetting claims. ‘Climate neutral’ and ‘CO2 neutral’ based on offsetting have no substantiation that overrides this prohibition.
    6. Check your listings against point af. CE, RoHS, EU standards, and other obligations do not belong in the selling points.
    7. Document the planning. Which communication you will adjust and when, which stock is running out, and when the new artwork will go to the printer.

    The last point is also the most cost-effective. You can adjust online communications yourself. Printed stock is the expensive part. For that specifically, the documented planning serves as proof of a demonstrable effort.

    Sources
    • Directive (EU) 2024/825 as regards empowering consumers for the green transition, text on EUR-Lex
    • Civil Code Book 6, Article 193a and Article 193g, text on wetten.overheid.nl
    • Implementation Act for the Directive on Improving Sustainability Information for Consumers, Bulletin of Acts and Decrees 2026, 152
    • European Commission, Questions and Answers on the ECGT Directive, September 22, 2026, Commission page
    • Consumer Protection Cooperation Network, Common Understanding on old stock situations, June 2026, ACM explanatory note
    • ACM, Guidelines on Sustainability Claims version 2, ACM page
    • Regulation (EU) 2025/40 on packaging and packaging waste, Article 14, text on EUR-Lex
    Legislation checked on October 1, 2026
    Francois Frietman
    Founder of Declaer

    Legal expert with a background in e-commerce. Writes about the rules he applies daily in files for brands and manufacturers. More about Francois

    Frequently Asked Questions

    Can I still put ‘sustainable’ or ‘green’ on my packaging?
    Only if you can demonstrate recognized excellent environmental performance. There is a second way: specify the claim on the same packaging. If you clearly state exactly what the sustainability benefit is, it is not a generic claim and the prohibition of point ac does not apply.
    Does this also apply if I only sell to businesses?
    No. The rules originate from consumer law and apply to commercial communication directed at consumers. If you sell exclusively to businesses, your communications are not covered. However, as soon as your product reaches consumers via a customer or marketplace, it applies to the claims the consumer sees.
    Do I have to destroy my existing stock?
    No. The rules do not have a transitional arrangement, but European consumer authorities have agreed to enforce in phases for genuine transitional issues. They may refrain from destruction or recall if it causes disproportionate costs or unnecessary environmental damage. To qualify, you must be able to show what steps you have taken and when.
    Can I put ‘CE-approved’ in my product description?
    No, not as a selling point. Point af of Article 6:193g of the Civil Code prohibits presenting legally mandated requirements as a distinguishing feature of your offer. The CE marking itself, of course, remains mandatory where legislation requires it. The prohibition concerns touting it, not the marking itself.
    Does a green leaf on my box count as a claim?
    It can. The European Commission states that nature icons such as leaves and water droplets count. The average consumer may interpret them as an implicit environmental claim or as a voluntary label. Whether this is the case depends on the placement, the combination with text, and the overall impression of the packaging.
    Who is liable if my supplier put the claim on the box?
    You are, as soon as you sell the product under your own brand in the European Union. The rules target the trader who conducts the commercial communication. The fact that your supplier provided the artwork does not change this, just as it does not change responsibility for the Declaration of Conformity.

    Prefer not to figure it out yourself?

    We assess packaging, labels, and manuals for brands and manufacturers and document the substantiation in your file. Quote within 24 hours with a fixed price and turnaround time.

    View the packaging service
    Short answer

    The Cyber Resilience Act obligations are being introduced in two stages. The reporting obligation under Regulation (EU) 2024/2847, known in Dutch as the Verordening cyberweerbaarheid, has been in effect since September 11, 2026. Product requirements, conformity assessment, and CE marking will follow on December 11, 2027. If you sell a product with digital elements under your own brand, you are the manufacturer.

    On July 27, 2026, the European Commission published guidelines containing 67 practical examples. These are not binding, but they do demonstrate how the regulator interprets the regulation.

    What applies already

    Since September 11, 2026, a manufacturer must report every actively exploited vulnerability and every serious security incident in its product to the National Cyber Security Centre. The initial report must be sent within 24 hours. This obligation also applies to products that have been on the market for years.

    This is where the misunderstanding currently affecting most dossiers lies. Many brands have December 11, 2027, in their calendars and assume that nothing is required until then. That is correct for product requirements. It is not correct for the reporting obligation.

    Article 71 of the regulation stipulates that Article 14 applies as of September 11, 2026. Article 69, paragraph 3, extends this to all products within the scope. Products placed on the market before December 11, 2027, are also covered.

    The Commission’s guidelines make the distinction even sharper. For a product placed on the market before December 11, 2027, the vulnerability management requirements from Annex I Part II do not apply. The reporting obligation, however, does apply. You do not need to change anything about that product, but you must know where to report as soon as something goes wrong.

    No retroactive effect

    If you were already aware before September 11, 2026, that a vulnerability was being actively exploited, you do not need to report it retrospectively. If you knew about the vulnerability but not about the exploitation, and that exploitation becomes apparent afterwards, the reporting obligation applies as usual.

    Dates from the Cyber Resilience Act
    DateEffective dateFor which products
    December 10, 2024Entry into forceNo obligations yet
    June 11, 2026Notification of test housesNot applicable to manufacturers
    September 11, 2026Reporting obligation Article 14All products within scope, including existing ones
    December 11, 2027Product requirements, assessment, CE markingProducts placed on the market thereafter
    June 11, 2028End of validity for old type certificatesCertificates from other harmonization legislation

    When you are the manufacturer

    You are a manufacturer as soon as you place a product with digital elements on the market under your own name or trademark. Who actually manufactures the product is irrelevant. An importer selling an Asian design under their own brand therefore bears all the obligations the regulation imposes on a manufacturer.

    Article 21 establishes this directly. An importer or distributor is considered a manufacturer as soon as they place the product on the market under their own name or trademark. The same applies in the event of a substantial modification to a product already on the market.

    For Declaer’s target audience, this is the core of the matter. If you have products manufactured in Asia and put your own brand name on the box, you are legally the manufacturer. Your supplier is not. The size of your enterprise does not change this.

    Small and micro-enterprises receive one mitigation. They are subject to the reporting obligation but will not be fined if they miss the initial 24-hour deadline. The report itself remains mandatory.

    Do you have a question about your own product?

    Let us know briefly what it concerns. We will contact you regarding what we can do and the costs involved.

    Response within 24 hours on business days.

    Your question has been received

    We respond within 24 hours on business days. You may continue reading.

    Which products are covered

    A product with digital elements is hardware or software that can connect to a device or a network. Examples include a baby monitor, a smart doorbell, a smartwatch, a router, or an app. Individual components such as a microcontroller also fall under the regulation.

    Article 3, paragraph 1, defines the term broadly: a software or hardware product and its remote data processing solutions. Individual components thereof also count. The cloud side of a smart thermostat is included, provided the product lacks a function without that connection.

    Products already covered by specific sectoral rules fall outside the regulation. The regulation mentions medical devices under 2017/745 and 2017/746, motor vehicles under 2019/2144, and aviation products under 2018/1139.

    If you sell radio equipment, you are already dealing with the requirements from Article 3, paragraph 3, points d, e, and f of the Radio Equipment Directive. The essential requirements of the Cyber Resilience Act encompass all those elements. This is explicitly intended so that one set of requirements remains once the Commission withdraws or amends the old delegated regulation.

    How to file a report

    In the Netherlands, a report is filed via the digital reporting portal of the National Cyber Security Centre. There is no prior registration requirement. The regulation requires three messages regarding the same case: an early warning within 24 hours, a report within 72 hours, and subsequently a final report.

    You report in the Netherlands if your main establishment is located here. If your group has multiple European establishments, the entity with the main establishment reports to the designated CSIRT of that country. The NCSC ensures the report reaches ENISA and the other member states. You therefore report in one place.

    The deadlines from Article 14
    StepDeadlineWhat you provide
    Early warning24 hoursNotification and in which member states your product is available
    Report72 hoursThe product, the nature of the vulnerability, and your measures
    Final vulnerability report14 daysAfter making a solution available
    Final incident report1 monthAfter the 72-hour report

    All deadlines start the moment you become aware of the vulnerability or the incident. The Commission’s guidelines clarify this: you have knowledge as soon as you have reasonable certainty, following an initial assessment, that exploitation is occurring. You must perform that initial assessment immediately.

    Not everything is worth a report. A vulnerability you find yourself, one that comes from a penetration test, or one received via responsible disclosure without known exploitation, does not need to be reported. The obligation only arises upon reliable evidence of exploitation.

    A vulnerability in a component from your supplier

    If the vulnerability is in a component you have purchased, you report it for your own product. If the vulnerable piece of code in your product is not accessible or demonstrably not exploited, you do not need to report it. You must, however, pass the vulnerability on to the manufacturer of that component.

    When a test house is required

    The regulation distinguishes four categories. For a regular product, a self-assessment suffices. Annex III also designates important products in Class I and Class II. Annex IV lists critical products. For these categories, a notified body is required if harmonized standards are missing.

    Class I of Annex III is the category for consumer electronics brands to check. It includes, among others:

    • Smart home products with a security function, specifically smart door locks, security cameras, baby monitors, and alarm systems.
    • Internet-connected toys that can speak, film, or track location.
    • Personal wearables for health monitoring and all wearables intended for children.
    • Routers, modems, and network switches intended for connection to the internet.
    • Smart home virtual assistants for general purposes.

    For Class I, you may perform the assessment yourself, but only if you fully apply the harmonized standards. If those standards do not exist, Article 32, paragraph 2, prescribes an EU-type examination or full quality assurance. This means a notified body and therefore lead time and costs.

    Determining whether your product falls into a category is done based on its primary functionality. Implementing Regulation (EU) 2025/2392 contains the technical descriptions for this. The distinction between core function and supporting function is decisive: a smartphone with a password manager on it does not itself become a password manager.

    Cyber Resilience Act obligations from December 11, 2027

    From December 11, 2027, a product with digital elements must comply with the essential requirements of Annex I. This includes a documented risk assessment, a technical file, a conformity assessment, an EU declaration of conformity, and the CE marking. Without that package, the product may not be placed on the market.

    An obligation will also be added that extends beyond the sale. You determine a support period appropriate to the expected product lifetime, with a minimum of five years. During that period, you address vulnerabilities with free security updates. You must keep every released update available for a further ten years.

    The transition is less abrupt than it seems. Products placed on the market before December 11, 2027, only fall under the requirements if they are substantially modified thereafter. And for a model designed before that date, the guidelines state you do not need to redesign. You perform a risk assessment to demonstrate that existing measures are sufficient.

    What you must be able to provide is the substantiation. The risk assessment belongs in the technical file, along with the information on which you based the support period. If an essential requirement is missing, you justify in that same file why it is not applicable.

    What you should arrange now

    For the reporting obligation, you do not need a product change, but you do need a procedure. Establish who within your organization assesses whether exploitation is occurring, who reports, and via which channel. Without such an arrangement, the 24-hour deadline will expire while you are still figuring things out.

    Four things that can be done now, without waiting for 2027:

    1. Designate a central contact point where users and researchers can report a vulnerability. This will be mandatory from 2027. Without such a point, a report will only reach you via a detour.
    2. Create an account on MijnNCSC or establish that you will use the open reporting form. In MijnNCSC, the warning, the report, and the final report are kept together.
    3. Document which components are in your product, down to the open-source libraries in the firmware. Without that list, you will not know if your product is affected when a vulnerability is reported.
    4. Contractually establish the support period with your supplier. You are promising the market five years of updates. Your manufacturer in Asia almost certainly has not made that commitment yet.

    Sanctions are set out in Article 64. For the essential requirements and Articles 13 and 14, fines can reach 15 million euros. If 2.5 percent of the total worldwide annual turnover is higher, that amount applies. For other obligations, the limit is 10 million euros or 2 percent.

    In the Netherlands, the Dutch Authority for Digital Infrastructure (RDI) provides oversight. This inspectorate also designates the test houses. The NCSC is explicitly not a regulator: a report there is not a fine notification or a criminal complaint.

    Sources
    • Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, Articles 13, 14, 21, 32, 64, 69 and 71, text on EUR-Lex
    • European Commission, C(2026) 5252, guidelines on the application of the Cyber Resilience Act, July 27, 2026, announcement and documents
    • Dutch Authority for Digital Infrastructure, Cyber Resilience Act, oversight and product categories
    • National Cyber Security Centre, reporting under the Cyber Resilience Act, the Dutch reporting portal
    Legislation checked on September 30, 2026
    Francois Frietman
    Founder of Declaer

    Legal expert with a background in e-commerce. Writes about the rules he applies daily in files for brands and manufacturers. More about Francois

    Frequently Asked Questions

    Do I need to do something now or only in December 2027?
    The reporting obligation has been in effect since September 11, 2026, including for products that have been on the market for years. You do not need to change anything about the product itself for this. You must, however, know who assesses, who reports, and where that happens, as the initial deadline is 24 hours.
    I have products manufactured in China and put my brand on them. Who is the manufacturer?
    You are. Article 21 stipulates it as follows: whoever places a product on the market under their own name or trademark is considered the manufacturer. All obligations from Articles 13 and 14 then rest with you, regardless of the size of your enterprise.
    Must I report every vulnerability in my product?
    No. The reporting obligation applies to vulnerabilities for which there is reliable evidence that someone is actively exploiting them. You also report serious security incidents. A vulnerability from a penetration test or from responsible disclosure without known exploitation does not need to be reported. Voluntary reporting is always permitted.
    Do I need a notified body for my product?
    That depends on the category. For a regular product, a self-assessment suffices. Is your product listed in Annex III or IV, such as a baby monitor, a security camera, or connected toys? Then a notified body is required as soon as harmonized standards are missing or you do not fully apply them.
    What happens if I do not report?
    Article 64 provides for fines of up to 15 million euros for violations of Articles 13 and 14. Or 2.5 percent of the worldwide annual turnover, if that is higher. Small and micro-enterprises are not fined for missing the 24-hour deadline, but the report itself remains mandatory.

    Prefer not to figure it out yourself?

    We build technical files for brands and manufacturers, from the risk assessment to the declaration you sign. Send us your product and you will receive a proposal within 24 hours with a fixed price and lead time.

    View the CE process