{"id":1213,"date":"2026-10-01T09:35:40","date_gmt":"2026-10-01T09:35:40","guid":{"rendered":"https:\/\/declaer.com\/?p=1213"},"modified":"2026-10-01T09:35:44","modified_gmt":"2026-10-01T09:35:44","slug":"cyber-resilience-act-what-applies-already","status":"publish","type":"post","link":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/","title":{"rendered":"Cyber Resilience Act: What applies already?"},"content":{"rendered":"\n<div class=\"kort\">\n  <div class=\"k\">Short answer<\/div>\n  <p>The Cyber Resilience Act obligations are being introduced in two stages. The reporting obligation under Regulation (EU) 2024\/2847, known in Dutch as the Verordening cyberweerbaarheid, has been in effect since September 11, 2026. Product requirements, conformity assessment, and CE marking will follow on December 11, 2027. If you sell a product with digital elements under your own brand, you are the manufacturer.   <\/p>\n  <p class=\"kort-na\">On July 27, 2026, the European Commission published guidelines containing 67 practical examples. These are not binding, but they do demonstrate how the regulator interprets the regulation. <\/p>\n<\/div>\n\n<div class=\"abody\">\n\n  <nav class=\"toc\" aria-label=\"Inhoud van dit artikel\">\n    <details open=\"\">\n      <summary>Contents<\/summary>\n      <div class=\"tin\">\n        <div class=\"k\">In this article<\/div>\n        <ol>\n          <li><a href=\"#nu\">What applies already<\/a><\/li>\n          <li><a href=\"#wie\">When you are the manufacturer<\/a><\/li>\n          <li><a href=\"#producten\">Which products are covered<\/a><\/li>\n          <li><a href=\"#melden\">How to file a report<\/a><\/li>\n          <li><a href=\"#klasse\">When a test house is required<\/a><\/li>\n          <li><a href=\"#2027\">Cyber Resilience Act obligations from December 11, 2027<\/a><\/li>\n          <li><a href=\"#doen\">What you should arrange now<\/a><\/li>\n        <\/ol>\n      <\/div>\n    <\/details>\n  <\/nav>\n\n  <article class=\"prose\">\n\n    <h2 id=\"nu\">What applies already<\/h2>\n    <p class=\"cap\">Since September 11, 2026, a manufacturer must report every actively exploited vulnerability and every serious security incident in its product to the National Cyber Security Centre. The initial report must be sent within 24 hours. This obligation also applies to products that have been on the market for years.  <\/p>\n    <p>This is where the misunderstanding currently affecting most dossiers lies. Many brands have December 11, 2027, in their calendars and assume that nothing is required until then. That is correct for product requirements. It is not correct for the reporting obligation.   <\/p>\n    <p>Article 71 of the regulation stipulates that Article 14 applies as of September 11, 2026. Article 69, paragraph 3, extends this to all products within the scope. Products placed on the market before December 11, 2027, are also covered.  <\/p>\n    <p>The Commission&#8217;s guidelines make the distinction even sharper. For a product placed on the market before December 11, 2027, the vulnerability management requirements from Annex I Part II do not apply. The reporting obligation, however, does apply. You do not need to change anything about that product, but you must know where to report as soon as something goes wrong.   <\/p>\n    <div class=\"let\">\n      <b>No retroactive effect<\/b>\n      <p>If you were already aware before September 11, 2026, that a vulnerability was being actively exploited, you do not need to report it retrospectively. If you knew about the vulnerability but not about the exploitation, and that exploitation becomes apparent afterwards, the reporting obligation applies as usual.  <\/p>\n    <\/div>\n\n    <div class=\"tabelwrap\">\n      <table>\n        <caption>Dates from the Cyber Resilience Act<\/caption>\n        <thead>\n          <tr><th scope=\"col\">Date<\/th><th scope=\"col\">Effective date<\/th><th scope=\"col\">For which products<\/th><\/tr>\n        <\/thead>\n        <tbody>\n          <tr><td class=\"num\">December 10, 2024<\/td><td>Entry into force<\/td><td>No obligations yet<\/td><\/tr>\n          <tr><td class=\"num\">June 11, 2026<\/td><td>Notification of test houses<\/td><td>Not applicable to manufacturers<\/td><\/tr>\n          <tr><td class=\"num\">September 11, 2026<\/td><td>Reporting obligation Article 14<\/td><td>All products within scope, including existing ones<\/td><\/tr>\n          <tr><td class=\"num\">December 11, 2027<\/td><td>Product requirements, assessment, CE marking<\/td><td>Products placed on the market thereafter<\/td><\/tr>\n          <tr><td class=\"num\">June 11, 2028<\/td><td>End of validity for old type certificates<\/td><td>Certificates from other harmonization legislation<\/td><\/tr>\n        <\/tbody>\n      <\/table>\n    <\/div>\n\n    <h2 id=\"wie\">When you are the manufacturer<\/h2>\n    <p class=\"cap\">You are a manufacturer as soon as you place a product with digital elements on the market under your own name or trademark. Who actually manufactures the product is irrelevant. An importer selling an Asian design under their own brand therefore bears all the obligations the regulation imposes on a manufacturer.  <\/p>\n    <p>Article 21 establishes this directly. An importer or distributor is considered a manufacturer as soon as they place the product on the market under their own name or trademark. The same applies in the event of a substantial modification to a product already on the market.  <\/p>\n    <p>For Declaer&#8217;s target audience, this is the core of the matter. If you have products manufactured in Asia and put your own brand name on the box, you are legally the manufacturer. Your supplier is not. The size of your enterprise does not change this.   <\/p>\n    <p>Small and micro-enterprises receive one mitigation. They are subject to the reporting obligation but will not be fined if they miss the initial 24-hour deadline. The report itself remains mandatory.  <\/p>\n\n    <div class=\"vraag\" id=\"vraagblok\">\n      <h3>Do you have a question about your own product?<\/h3>\n      <p class=\"intro\">Let us know briefly what it concerns. We will contact you regarding what we can do and the costs involved. <\/p>\n\n      <form class=\"wpcf7-form\" id=\"vraagform\" novalidate=\"\">\n        <div class=\"veld\">\n          <label for=\"vraag-tekst\">What is it about?<\/label>\n          <span class=\"wpcf7-form-control-wrap\" data-name=\"vraag\">\n            <textarea id=\"vraag-tekst\" name=\"vraag\" class=\"wpcf7-form-control\" required=\"\"><\/textarea>\n          <\/span>\n        <\/div>\n        <div class=\"veld\">\n          <label for=\"vraag-mail\">Email address<\/label>\n          <span class=\"wpcf7-form-control-wrap\" data-name=\"uw-email\">\n            <input id=\"vraag-mail\" name=\"uw-email\" type=\"email\" class=\"wpcf7-form-control\" autocomplete=\"email\" required=\"\"\/>\n          <\/span>\n        <\/div>\n        <input type=\"hidden\" id=\"vraag-artikel\" name=\"artikel\" value=\"\"\/>\n        <button type=\"submit\">Submit my question <span class=\"a\" aria-hidden=\"true\">\u2192<\/span><\/button>\n        <p class=\"na\">Response within 24 hours on business days.<\/p>\n        <div class=\"wpcf7-response-output\" role=\"status\" aria-live=\"polite\"><\/div>\n      <\/form>\n\n      <div class=\"klaar\" role=\"status\" aria-live=\"polite\">\n        <div class=\"vink\" aria-hidden=\"true\"><svg viewbox=\"0 0 24 24\"><path d=\"M5 12.4l4.6 4.6L19 7.2\"><\/path><\/svg><\/div>\n        <b>Your question has been received<\/b>\n        <p>We respond within 24 hours on business days. You may continue reading. <\/p>\n      <\/div>\n    <\/div>\n\n    <h2 id=\"producten\">Which products are covered<\/h2>\n    <p class=\"cap\">A product with digital elements is hardware or software that can connect to a device or a network. Examples include a baby monitor, a smart doorbell, a smartwatch, a router, or an app. Individual components such as a microcontroller also fall under the regulation.  <\/p>\n    <p>Article 3, paragraph 1, defines the term broadly: a software or hardware product and its remote data processing solutions. Individual components thereof also count. The cloud side of a smart thermostat is included, provided the product lacks a function without that connection.  <\/p>\n    <p>Products already covered by specific sectoral rules fall outside the regulation. The regulation mentions medical devices under 2017\/745 and 2017\/746, motor vehicles under 2019\/2144, and aviation products under 2018\/1139. <\/p>\n    <p>If you sell radio equipment, you are already dealing with the requirements from Article 3, paragraph 3, points d, e, and f of the Radio Equipment Directive. The essential requirements of the Cyber Resilience Act encompass all those elements. This is explicitly intended so that one set of requirements remains once the Commission withdraws or amends the old delegated regulation.  <\/p>\n\n    <h2 id=\"melden\">How to file a report<\/h2>\n    <p class=\"cap\">In the Netherlands, a report is filed via the digital reporting portal of the National Cyber Security Centre. There is no prior registration requirement. The regulation requires three messages regarding the same case: an early warning within 24 hours, a report within 72 hours, and subsequently a final report.  <\/p>\n    <p>You report in the Netherlands if your main establishment is located here. If your group has multiple European establishments, the entity with the main establishment reports to the designated CSIRT of that country. The NCSC ensures the report reaches ENISA and the other member states. You therefore report in one place.   <\/p>\n\n    <div class=\"tabelwrap\">\n      <table>\n        <caption>The deadlines from Article 14<\/caption>\n        <thead>\n          <tr><th scope=\"col\">Step<\/th><th scope=\"col\">Deadline<\/th><th scope=\"col\">What you provide<\/th><\/tr>\n        <\/thead>\n        <tbody>\n          <tr><td>Early warning<\/td><td class=\"num\">24 hours<\/td><td>Notification and in which member states your product is available<\/td><\/tr>\n          <tr><td>Report<\/td><td class=\"num\">72 hours<\/td><td>The product, the nature of the vulnerability, and your measures<\/td><\/tr>\n          <tr><td>Final vulnerability report<\/td><td class=\"num\">14 days<\/td><td>After making a solution available<\/td><\/tr>\n          <tr><td>Final incident report<\/td><td class=\"num\">1 month<\/td><td>After the 72-hour report<\/td><\/tr>\n        <\/tbody>\n      <\/table>\n    <\/div>\n\n    <p>All deadlines start the moment you become aware of the vulnerability or the incident. The Commission&#8217;s guidelines clarify this: you have knowledge as soon as you have reasonable certainty, following an initial assessment, that exploitation is occurring. You must perform that initial assessment immediately.  <\/p>\n    <p>Not everything is worth a report. A vulnerability you find yourself, one that comes from a penetration test, or one received via responsible disclosure without known exploitation, does not need to be reported. The obligation only arises upon reliable evidence of exploitation.  <\/p>\n    <div class=\"let\">\n      <b>A vulnerability in a component from your supplier<\/b>\n      <p>If the vulnerability is in a component you have purchased, you report it for your own product. If the vulnerable piece of code in your product is not accessible or demonstrably not exploited, you do not need to report it. You must, however, pass the vulnerability on to the manufacturer of that component.  <\/p>\n    <\/div>\n\n    <h2 id=\"klasse\">When a test house is required<\/h2>\n    <p class=\"cap\">The regulation distinguishes four categories. For a regular product, a self-assessment suffices. Annex III also designates important products in Class I and Class II. Annex IV lists critical products. For these categories, a notified body is required if harmonized standards are missing.    <\/p>\n    <p>Class I of Annex III is the category for consumer electronics brands to check. It includes, among others: <\/p>\n    <ul>\n      <li><strong>Smart home products with a security function<\/strong>, specifically smart door locks, security cameras, baby monitors, and alarm systems.<\/li>\n      <li><strong>Internet-connected toys<\/strong> that can speak, film, or track location.<\/li>\n      <li><strong>Personal wearables<\/strong> for health monitoring and all wearables intended for children.<\/li>\n      <li><strong>Routers, modems, and network switches<\/strong> intended for connection to the internet.<\/li>\n      <li><strong>Smart home virtual assistants<\/strong> for general purposes.<\/li>\n    <\/ul>\n    <p>For Class I, you may perform the assessment yourself, but only if you fully apply the harmonized standards. If those standards do not exist, Article 32, paragraph 2, prescribes an EU-type examination or full quality assurance. This means a <a href=\"https:\/\/declaer.com\/en\/is-a-notified-body-mandatory\/\">notified body<\/a> and therefore lead time and costs.  <\/p>\n    <p>Determining whether your product falls into a category is done based on its primary functionality. Implementing Regulation (EU) 2025\/2392 contains the technical descriptions for this. The distinction between core function and supporting function is decisive: a smartphone with a password manager on it does not itself become a password manager.  <\/p>\n\n    <h2 id=\"2027\">Cyber Resilience Act obligations from December 11, 2027<\/h2>\n    <p class=\"cap\">From December 11, 2027, a product with digital elements must comply with the essential requirements of Annex I. This includes a documented risk assessment, a technical file, a conformity assessment, an EU declaration of conformity, and the CE marking. Without that package, the product may not be placed on the market. <\/p>\n    <p>An obligation will also be added that extends beyond the sale. You determine a support period appropriate to the expected product lifetime, with a minimum of five years. During that period, you address vulnerabilities with free security updates. You must keep every released update available for a further ten years.   <\/p>\n    <p>The transition is less abrupt than it seems. Products placed on the market before December 11, 2027, only fall under the requirements if they are substantially modified thereafter. And for a model designed before that date, the guidelines state you do not need to redesign. You perform a risk assessment to demonstrate that existing measures are sufficient.   <\/p>\n    <p>What you must be able to provide is the substantiation. The risk assessment belongs in the <a href=\"https:\/\/declaer.com\/en\/what-should-be-included-in-a-technical-file\/\">technical file<\/a>, along with the information on which you based the support period. If an essential requirement is missing, you justify in that same file why it is not applicable.  <\/p>\n\n    <h2 id=\"doen\">What you should arrange now<\/h2>\n    <p class=\"cap\">For the reporting obligation, you do not need a product change, but you do need a procedure. Establish who within your organization assesses whether exploitation is occurring, who reports, and via which channel. Without such an arrangement, the 24-hour deadline will expire while you are still figuring things out.  <\/p>\n    <p>Four things that can be done now, without waiting for 2027:<\/p>\n    <ol>\n      <li><strong>Designate a central contact point<\/strong> where users and researchers can report a vulnerability. This will be mandatory from 2027. Without such a point, a report will only reach you via a detour.  <\/li>\n      <li><strong>Create an account on MijnNCSC<\/strong> or establish that you will use the open reporting form. In MijnNCSC, the warning, the report, and the final report are kept together. <\/li>\n      <li><strong>Document which components are in your product<\/strong>, down to the open-source libraries in the firmware. Without that list, you will not know if your product is affected when a vulnerability is reported. <\/li>\n      <li><strong>Contractually establish the support period with your supplier<\/strong>. You are promising the market five years of updates. Your manufacturer in Asia almost certainly has not made that commitment yet.  <\/li>\n    <\/ol>\n    <p>Sanctions are set out in Article 64. For the essential requirements and Articles 13 and 14, fines can reach 15 million euros. If 2.5 percent of the total worldwide annual turnover is higher, that amount applies. For other obligations, the limit is 10 million euros or 2 percent.   <\/p>\n    <p>In the Netherlands, the Dutch Authority for Digital Infrastructure (RDI) provides oversight. This inspectorate also designates the test houses. The NCSC is explicitly not a regulator: a report there is not a fine notification or a criminal complaint.  <\/p>\n\n    <!-- ===== BRONNEN ===== -->\n    <div class=\"bron\">\n      <div class=\"k\">Sources<\/div>\n      <ul>\n        <li>Regulation (EU) 2024\/2847 on horizontal cybersecurity requirements for products with digital elements, Articles 13, 14, 21, 32, 64, 69 and 71, <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/2847\/oj\" target=\"_blank\" rel=\"noopener\">text on EUR-Lex<\/a><\/li>\n        <li>European Commission, C(2026) 5252, guidelines on the application of the Cyber Resilience Act, July 27, 2026, <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\" target=\"_blank\" rel=\"noopener\">announcement and documents<\/a><\/li>\n        <li>Dutch Authority for Digital Infrastructure, Cyber Resilience Act, <a href=\"https:\/\/www.rdi.nl\/onderwerpen\/draadloze-apparatuur\/handel-en-apparatuur\/cra\" target=\"_blank\" rel=\"noopener\">oversight and product categories<\/a><\/li>\n        <li>National Cyber Security Centre, reporting under the Cyber Resilience Act, <a href=\"https:\/\/www.ncsc.nl\/wet-en-regelgeving\/cyber-resilience-act-cra\/melden\" target=\"_blank\" rel=\"noopener\">the Dutch reporting portal<\/a><\/li>\n      <\/ul>\n      <div class=\"gecheckt\">Legislation checked on September 30, 2026<\/div>\n    <\/div>\n\n    <!-- ===== AUTEUR ===== -->\n    <div class=\"auteur\">\n      <div class=\"av\" aria-hidden=\"true\">FF<\/div>\n      <div>\n        <div class=\"nm\">Francois Frietman<\/div>\n        <div class=\"rol\">Founder of Declaer<\/div>\n        <p>Legal expert with a background in e-commerce. Writes about the rules he applies daily in files for brands and manufacturers.  <a href=\"https:\/\/declaer.com\/en\/about-us\/\">More about Francois<\/a><\/p>\n      <\/div>\n    <\/div>\n\n    <!-- ===== VEELGESTELDE VRAGEN ===== -->\n    <div class=\"afaq\">\n      <h2 id=\"vragen\">Frequently Asked Questions<\/h2>\n      <details>\n        <summary>Do I need to do something now or only in December 2027?<\/summary>\n        <div class=\"ans\">The reporting obligation has been in effect since September 11, 2026, including for products that have been on the market for years. You do not need to change anything about the product itself for this. You must, however, know who assesses, who reports, and where that happens, as the initial deadline is 24 hours.  <\/div>\n      <\/details>\n      <details>\n        <summary>I have products manufactured in China and put my brand on them. Who is the manufacturer? <\/summary>\n        <div class=\"ans\">You are. Article 21 stipulates it as follows: whoever places a product on the market under their own name or trademark is considered the manufacturer. All obligations from Articles 13 and 14 then rest with you, regardless of the size of your enterprise. <\/div>\n      <\/details>\n      <details>\n        <summary>Must I report every vulnerability in my product?<\/summary>\n        <div class=\"ans\">No. The reporting obligation applies to vulnerabilities for which there is reliable evidence that someone is actively exploiting them. You also report serious security incidents. A vulnerability from a penetration test or from responsible disclosure without known exploitation does not need to be reported. Voluntary reporting is always permitted.    <\/div>\n      <\/details>\n      <details>\n        <summary>Do I need a notified body for my product?<\/summary>\n        <div class=\"ans\">That depends on the category. For a regular product, a self-assessment suffices. Is your product listed in Annex III or IV, such as a baby monitor, a security camera, or connected toys? Then a notified body is required as soon as harmonized standards are missing or you do not fully apply them.   <\/div>\n      <\/details>\n      <details>\n        <summary>What happens if I do not report?<\/summary>\n        <div class=\"ans\">Article 64 provides for fines of up to 15 million euros for violations of Articles 13 and 14. Or 2.5 percent of the worldwide annual turnover, if that is higher. Small and micro-enterprises are not fined for missing the 24-hour deadline, but the report itself remains mandatory.  <\/div>\n      <\/details>\n    <\/div>\n\n    <!-- ===== VERDER LEZEN ===== -->\n    <div class=\"verder\">\n      <div class=\"k\">Further reading<\/div>\n      <div class=\"verder-l\">\n        <a href=\"https:\/\/declaer.com\/en\/is-a-notified-body-mandatory\/\">\n          <div><div class=\"on\">CE<\/div><div class=\"tl\">Is a notified body mandatory?<\/div><\/div>\n          <span class=\"go\" aria-hidden=\"true\">\u2192<\/span>\n        <\/a>\n        <a href=\"https:\/\/declaer.com\/en\/what-should-be-included-in-a-technical-file\/\">\n          <div><div class=\"on\">Technical File<\/div><div class=\"tl\">What should be in my technical file?<\/div><\/div>\n          <span class=\"go\" aria-hidden=\"true\">\u2192<\/span>\n        <\/a>\n      <\/div>\n    <\/div>\n\n    <!-- ===== NAAR DE DIENST ===== -->\n    <div class=\"adienst\">\n      <span class=\"ae-vlak\" aria-hidden=\"true\"><svg viewbox=\"0 0 480 246\"><path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M115.316 1.01978C135.658 1.01978 151.512 4.90926 162.879 12.6868C174.246 20.1651 183.071 30.1857 189.353 42.7493V5.95533H249.479V33.0754C243.459 39.9242 238.222 47.381 233.794 55.4485L233.768 55.4944L233.744 55.5383C222.618 76.1682 217.258 98.5011 217.636 122.296C217.866 146.061 224.267 168.706 236.591 190.051C240.5 196.823 244.797 203.159 249.479 209.052V239.281H190.699V201.142C184.417 214.304 175.443 224.923 163.776 232.999C152.409 241.076 136.256 245.115 115.316 245.115C94.0779 245.114 74.6343 239.73 56.9854 228.961C39.6356 217.893 25.7256 203.236 15.2559 184.989C5.08526 166.442 0 145.951 0 123.516C1.05102e-05 106.765 2.99109 91.06 8.97363 76.4026C14.9563 61.4458 23.1826 48.4325 33.6523 37.3645C44.1221 25.9974 56.2378 17.1737 69.998 10.8919C84.0573 4.31094 99.1632 1.01982 115.316 1.01978ZM125.188 55.762C112.326 55.762 100.958 58.903 91.0869 65.1848C81.5146 71.1675 74.0358 79.2437 68.6514 89.4143C63.2669 99.5849 60.5752 110.803 60.5752 123.068C60.5753 134.734 63.267 145.802 68.6514 156.272C74.0358 166.442 81.5147 174.668 91.0869 180.949C100.958 187.231 112.326 190.372 125.188 190.372C138.649 190.372 150.166 187.381 159.738 181.399C169.61 175.117 177.238 166.891 182.622 156.72C188.007 146.549 190.699 135.481 190.699 123.516C190.699 111.251 188.006 100.034 182.622 89.8635C177.238 79.693 169.61 71.4667 159.738 65.1848C150.166 58.903 138.649 55.762 125.188 55.762Z\" fill=\"currentColor\"><\/path> <path d=\"M249.479 185.145C249.105 184.518 248.734 183.888 248.367 183.252C237.15 163.823 231.439 143.46 231.232 122.163C230.877 100.608 235.704 80.5505 245.713 61.9915C246.901 59.8265 248.157 57.7096 249.479 55.6389V185.145Z\" fill=\"currentColor\"><\/path> <path d=\"M413.921 228.597C393.197 240.563 372.166 246.315 350.83 245.853C329.493 245.392 309.859 239.802 291.927 229.085C274.105 217.959 259.585 202.682 248.367 183.252C237.15 163.823 231.439 143.46 231.232 122.163C230.877 100.608 235.704 80.5505 245.713 61.9915C255.981 43.2826 271.219 28.0945 291.426 16.4282C311.632 4.76197 332.145 -0.690843 352.963 0.0698457C374.041 0.680961 393.565 6.67901 411.537 18.064C429.618 29.0403 444.268 44.2432 455.485 63.6726C457.13 66.5223 458.721 69.5762 460.257 72.8345C461.792 76.0928 463.273 79.5554 464.7 83.2223L313.539 170.495C323.269 180.766 334.577 187.191 347.463 189.768C360.609 192.195 373.787 189.595 386.999 181.967C398.398 175.386 406.746 167.112 412.045 157.144C417.603 147.027 420.469 136.737 420.645 126.273L479.171 133.415C478.469 150.745 472.405 168.062 460.98 185.366C449.555 202.67 433.869 217.081 413.921 228.597ZM316.673 61.9532C304.238 69.1324 295.786 79.021 291.315 91.619C286.845 104.217 286.699 117.427 290.879 131.248L390.747 73.5893C381.465 64.095 369.973 57.9499 356.269 55.1539C342.825 52.2084 329.626 54.4748 316.673 61.9532Z\" fill=\"currentColor\"><\/path><\/svg><\/span>\n      <div class=\"adienst-in\">\n        <p class=\"adienst-kop\">Prefer not to figure it out yourself?<\/p>\n        <p>We build technical files for brands and manufacturers, from the risk assessment to the declaration you sign. Send us your product and you will receive a proposal within 24 hours with a fixed price and lead time. <\/p>\n        <a href=\"https:\/\/declaer.com\/en\/ce-marking\/\" class=\"btn btn-onink\">View the CE process <span class=\"a\" aria-hidden=\"true\">\u2192<\/span><\/a>\n      <\/div>\n    <\/div>\n\n  <\/article>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Short answer The Cyber Resilience Act obligations are being introduced in two stages. The reporting obligation under Regulation (EU) 2024\/2847, known in Dutch as the Verordening cyberweerbaarheid, has been in effect since September 11, 2026. Product requirements, conformity assessment, and CE marking will follow on December 11, 2027. If you sell a product with digital [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[1],"tags":[],"onderwerp":[10],"class_list":["post-1213","post","type-post","status-publish","format-standard","hentry","category-niet-gecategoriseerd","onderwerp-regelgeving"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Resilience Act: What applies already?<\/title>\n<meta name=\"description\" content=\"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Resilience Act: What applies already?\" \/>\n<meta property=\"og:description\" content=\"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/\" \/>\n<meta property=\"og:site_name\" content=\"Declaer | Product compliance as it should be.\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-01T09:35:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-01T09:35:44+00:00\" \/>\n<meta name=\"author\" content=\"Francois\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Francois\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/\"},\"author\":{\"name\":\"Francois\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#\\\/schema\\\/person\\\/1672332adddd8a487223043d6e517960\"},\"headline\":\"Cyber Resilience Act: What applies already?\",\"datePublished\":\"2026-10-01T09:35:40+00:00\",\"dateModified\":\"2026-10-01T09:35:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/\"},\"wordCount\":2256,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#organization\"},\"articleSection\":[\"Niet-gecategoriseerd\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/\",\"url\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/\",\"name\":\"Cyber Resilience Act: What applies already?\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#website\"},\"datePublished\":\"2026-10-01T09:35:40+00:00\",\"dateModified\":\"2026-10-01T09:35:44+00:00\",\"description\":\"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/cyber-resilience-act-what-applies-already\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/declaer.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber Resilience Act: What applies already?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/declaer.com\\\/en\\\/\",\"name\":\"Declaer | Product compliance as it should be.\",\"description\":\"Declaer regelt productcompliance van begin tot eind: CE-markering, GPSR, EPREL, testen, FCC en UKCA. Vaste prijs vooraf, offerte binnen 24 uur.\",\"publisher\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/declaer.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#organization\",\"name\":\"Declaer\",\"url\":\"https:\\\/\\\/declaer.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/declaer.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Declaer_Logo_Color1.png\",\"contentUrl\":\"https:\\\/\\\/declaer.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Declaer_Logo_Color1.png\",\"width\":1156,\"height\":246,\"caption\":\"Declaer\"},\"image\":{\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/declaer\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/declaer.com\\\/en\\\/#\\\/schema\\\/person\\\/1672332adddd8a487223043d6e517960\",\"name\":\"Francois\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g\",\"caption\":\"Francois\"},\"url\":\"https:\\\/\\\/declaer.com\\\/en\\\/author\\\/francois\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Resilience Act: What applies already?","description":"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/","og_locale":"en_US","og_type":"article","og_title":"Cyber Resilience Act: What applies already?","og_description":"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.","og_url":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/","og_site_name":"Declaer | Product compliance as it should be.","article_published_time":"2026-10-01T09:35:40+00:00","article_modified_time":"2026-10-01T09:35:44+00:00","author":"Francois","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Francois","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/#article","isPartOf":{"@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/"},"author":{"name":"Francois","@id":"https:\/\/declaer.com\/en\/#\/schema\/person\/1672332adddd8a487223043d6e517960"},"headline":"Cyber Resilience Act: What applies already?","datePublished":"2026-10-01T09:35:40+00:00","dateModified":"2026-10-01T09:35:44+00:00","mainEntityOfPage":{"@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/"},"wordCount":2256,"commentCount":0,"publisher":{"@id":"https:\/\/declaer.com\/en\/#organization"},"articleSection":["Niet-gecategoriseerd"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/","url":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/","name":"Cyber Resilience Act: What applies already?","isPartOf":{"@id":"https:\/\/declaer.com\/en\/#website"},"datePublished":"2026-10-01T09:35:40+00:00","dateModified":"2026-10-01T09:35:44+00:00","description":"The reporting obligation under the Cyber Resilience Act has been in effect since September 11, 2026, including for products placed on the market years ago. What you need to arrange now.","breadcrumb":{"@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/declaer.com\/en\/cyber-resilience-act-what-applies-already\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/declaer.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cyber Resilience Act: What applies already?"}]},{"@type":"WebSite","@id":"https:\/\/declaer.com\/en\/#website","url":"https:\/\/declaer.com\/en\/","name":"Declaer | Product compliance as it should be.","description":"Declaer regelt productcompliance van begin tot eind: CE-markering, GPSR, EPREL, testen, FCC en UKCA. Vaste prijs vooraf, offerte binnen 24 uur.","publisher":{"@id":"https:\/\/declaer.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/declaer.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/declaer.com\/en\/#organization","name":"Declaer","url":"https:\/\/declaer.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/declaer.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/declaer.com\/wp-content\/uploads\/2026\/08\/Declaer_Logo_Color1.png","contentUrl":"https:\/\/declaer.com\/wp-content\/uploads\/2026\/08\/Declaer_Logo_Color1.png","width":1156,"height":246,"caption":"Declaer"},"image":{"@id":"https:\/\/declaer.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/declaer"]},{"@type":"Person","@id":"https:\/\/declaer.com\/en\/#\/schema\/person\/1672332adddd8a487223043d6e517960","name":"Francois","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/696d5a306866e3713a7e664c2b0f5e67d4351814a1bfe949117b47971721e225?s=96&d=mm&r=g","caption":"Francois"},"url":"https:\/\/declaer.com\/en\/author\/francois\/"}]}},"_links":{"self":[{"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/posts\/1213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/comments?post=1213"}],"version-history":[{"count":2,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/posts\/1213\/revisions"}],"predecessor-version":[{"id":1217,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/posts\/1213\/revisions\/1217"}],"wp:attachment":[{"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/media?parent=1213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/categories?post=1213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/tags?post=1213"},{"taxonomy":"onderwerp","embeddable":true,"href":"https:\/\/declaer.com\/en\/wp-json\/wp\/v2\/onderwerp?post=1213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}