Skip to Primary Navigation

EU Cyber Resilience Act: New incident reporting obligations take effect

a hacker with an Anonymous mask on his face and a hood on his head uses a computer
Photo: Chesnot/Getty Images

The Cyber Resilience Act (CRA) brings manufacturers of products with digital elements under strict deadlines and new compliance responsibilities.

Manufacturers of hardware and software products with digital elements (PDE) placed on the EU market face new reporting requirements as of September 11,2026, under the Cyber Resilience Act (CRA).

The CRA, which entered into force in December 2024, is a horizontal framework that aims to strengthen EU’s approach to cybersecurity and

Get full access, free for a month

This is a Premium article. Start your 28-day free trial to continue reading and access all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience