If you make, import, or sell any connected device in the European Union, the clock ran out on September 11, 2026 — and most companies are not ready.
Starting this week, the EU Cyber Resilience Act (CRA) transforms from an upcoming obligation into active law. The regulation’s first enforcement milestone requires every manufacturer of IoT devices, firmware, and connected software products available to EU customers to report actively exploited vulnerabilities to European authorities within 24 hours — or face fines of up to €15 million. With 21 billion connected devices in use worldwide and 70% of IoT devices carrying critical vulnerabilities, the gap between where the industry stands and where the law now demands it be is significant.
This article breaks down what EU Cyber Resilience Act IoT requirements mean in practice, who is affected, exactly what actions are required, and what critics say about this landmark regulation.
What Is the EU Cyber Resilience Act? A Plain-Language Overview
The EU Cyber Resilience Act is a regulation adopted by the European Commission that establishes mandatory cybersecurity requirements for any product with digital elements sold in the European Union. That definition is intentionally broad: smartphones, smart thermostats, industrial controllers, routers, baby monitors, medical devices, standalone software, firmware — virtually any product that connects to a network or another device falls within scope.
The CRA entered into force in December 2024, but its requirements roll out in phases. The first major milestone — the one generating urgent attention this week — is September 11, 2026, when vulnerability and incident reporting obligations activate. The full suite of compliance requirements, including secure-by-design mandates and mandatory software bills of materials (SBOMs), becomes enforceable from December 11, 2027.
The regulation’s reach is genuinely global. A US-based SaaS company selling subscriptions to German businesses, a Japanese IoT vendor shipping devices to France, and a Canadian embedded systems firm distributing to the Netherlands are all subject to the CRA. If your product reaches EU customers, the CRA reaches you — regardless of where your company is incorporated.
How It Works (Without the Jargon)
The CRA rests on three overlapping obligations that every affected manufacturer must understand:
1. Report fast. When you discover that a vulnerability in your product is actively being exploited in the wild, you have 24 hours to file an early warning with ENISA (the EU Agency for Cybersecurity) and your country’s designated national CSIRT (Computer Security Incident Response Team). A full technical notification must follow within 72 hours. A final report — including root cause analysis and the corrective measures taken — is due within 14 days of a patch becoming available. ENISA opened its Single Reporting Platform (SRP) on September 1, 2026, the day the portal became mandatory.
2. Build securely. Products must be designed with security as a baseline requirement, not a post-launch addition. This means threat modeling during product design, access controls such as multi-factor authentication, end-to-end encryption, a mechanism for receiving and deploying security updates over the air, and — critically — a machine-readable Software Bill of Materials (SBOM) in CycloneDX or SPDX format that catalogues every software and firmware component in the product, including all open-source dependencies.
3. Support for the long haul. Manufacturers must provide security patches and updates for a minimum of five years, or for the product’s expected operational lifetime if that is longer.
Why EU Cyber Resilience Act IoT Reporting Is Trending Right Now
The September 11, 2026 reporting deadline arrived faster than most of the industry was prepared for. TechTimes reported that ENISA’s Single Reporting Platform launched on September 1 — literally the same day the filing obligation became mandatory — giving manufacturers almost no runway to test the process before real incidents required its use.
The scale of the problem the CRA is designed to solve is substantial. According to Swif.ai’s IoT Security Statistics 2026, there are currently 21 billion connected IoT devices globally, facing approximately 820,000 daily cyberattacks. More than 70% of IoT devices across all industries carry critical vulnerabilities. Routers and switches average 32 vulnerabilities per device. In March 2026, the US Department of Justice disrupted four IoT botnets that had collectively infected more than three million devices worldwide.
The average cost of an IoT security incident is $330,000. For healthcare IoT (IoMT) breaches, that figure climbs above $7 million per incident. And 35% of IoT devices still ship with default credentials, while 33% have no built-in update mechanism — precisely the structural failures the CRA is designed to eliminate at the design stage.
Key developments in the past two weeks:
- September 1, 2026 — ENISA’s SRP portal went live, opening the official channel for CRA vulnerability filings. (TechTimes)
- September 11, 2026 — CRA reporting obligations officially activate: 24-hour early warning notifications are now legally required from all manufacturers. (European Commission)
- Compliance gap exposed — Research shows only 12.3% of SMEs are aware the CRA exists, versus 83.5% of large enterprises, revealing a massive readiness gap. (consult.red)
Real-World Applications: Who Is Already Adapting
The CRA is not abstract regulatory theory. It is already reshaping how companies across sectors design, sell, and support connected products.
How Leading Manufacturers Are Responding
Telit, one of the world’s largest IoT module makers, overhauled its vulnerability disclosure program months ahead of the September deadline, publishing a detailed CRA compliance roadmap for customers that maps specific CRA articles to engineering controls. The company developed product-level SBOMs for its full module portfolio — a process that involved auditing third-party firmware, open-source dependencies, and radio stack components across hundreds of product variants. (Telit)
Amazon Web Services published an alignment guide for its IoT services in 2026, detailing how AWS IoT Device Defender, AWS IoT Core, and related managed cloud services map to specific CRA technical requirements — effectively positioning AWS as an outsourced compliance layer that IoT developers can use to reduce their own obligation surface area. (AWS IoT Blog)
Industrial equipment manufacturers face the steepest compliance curve. Research published in May 2026 on arXiv found that industrial companies consistently underestimate the number of products within CRA scope, struggle to establish SBOM processes across legacy hardware still in active deployment, and face serious gaps in communication between engineering teams and executive leadership when explaining the breadth and cost of compliance obligations.
The Three-Step CRA Reporting Timeline
When a manufacturer discovers an actively exploited vulnerability in any product currently available to EU customers, the legal reporting workflow is as follows:
- Within 24 hours of discovery: File an early warning with ENISA’s SRP. Include product identifiers, a high-level description of the vulnerability, and confirmation of active exploitation in the wild.
- Within 72 hours: Submit a detailed technical notification covering severity rating, attack vector, affected versions, and an initial remediation or mitigation plan.
- Within 14 days of patch availability: File a final report with root cause analysis, all corrective measures taken, and a full incident timeline.
National CSIRTs receive copies of these reports and share relevant threat intelligence with EU member states. This process applies even to products shipped years before the CRA entered into force — there is no grandfather clause for legacy devices still in use by EU customers.
Key Players You Should Know
- ENISA (European Union Agency for Cybersecurity) — The central authority operating the CRA Single Reporting Platform and coordinating vulnerability disclosure across EU member states. ENISA plays a role equivalent to the US Cybersecurity and Infrastructure Security Agency (CISA).
- National CSIRTs — Each EU member state’s Computer Security Incident Response Team receives CRA vulnerability filings routed from ENISA and coordinates directly with manufacturers on incident response.
- Telit — One of the first major IoT module manufacturers to publish a public CRA compliance framework for its entire product portfolio, establishing an early industry benchmark.
- Amazon Web Services — Released an alignment guide mapping its managed IoT cloud services to specific CRA requirements, helping cloud-hosted IoT deployments build compliant architectures without rebuilding from scratch.
- Keysight Technologies — Published one of the industry’s earliest CRA countdown guides, warning manufacturers a full year in advance of what September 11, 2026 would demand. (Keysight)
- Linux Foundation EU — Has consistently challenged elements of the CRA’s open-source provisions, arguing that compliance costs could drive European SMEs off open-source toolchains entirely.
Challenges and What Critics Say
The CRA has drawn substantive criticism alongside broad industry support for its underlying goals.
The open-source community has raised the loudest concerns. The Linux Foundation EU argued that the regulation fails to adequately distinguish between commercial software vendors and open-source foundations, which operate without the revenue streams or corporate structures capable of absorbing compliance overhead. The Electronic Frontier Foundation noted that requiring products to ship without any known exploitable vulnerabilities sets a standard that is effectively unachievable, given the pace at which zero-day vulnerabilities are discovered and disclosed. GitHub submitted formal comments to EU regulators making the same argument — that the zero-known-vulnerabilities standard risks criminalizing normal software engineering reality. (Infosecurity Magazine)
The impact on small and medium-sized enterprises is compounding. Research found that only 12.3% of SMEs are aware the CRA exists — meaning the majority of smaller businesses affected by the regulation do not yet know they are subject to it. For companies where open-source software constitutes 95% or more of their product stack, auditing and maintaining SBOMs for every dependency would dwarf engineering budgets. The broader economic risk has been estimated in the hundreds of billions of euros if SME compliance costs materialize at scale.
Industrial manufacturers face their own challenge: design-phase requirements that are straightforward for new products must somehow be retrofitted to legacy hardware deployed in factories and infrastructure for years without any SBOM documentation. The regulation makes no exemption for products manufactured prior to its entry into force if those products are still being offered to EU customers today. This creates a genuine operational risk: many companies will encounter their first live CRA filing not in a planned compliance exercise, but under the pressure of a real, active exploitation event.
What This Means for Your Business
If your organization manufactures, imports, or distributes any product with digital elements to EU customers, the CRA affects you directly — regardless of your company’s location.
The immediate priority is establishing a vulnerability management process capable of meeting the 24-hour early warning requirement. This demands three things simultaneously: knowing every component in every product you ship (which requires an SBOM), maintaining a monitored channel through which external security researchers or customers can report vulnerabilities to you, and having a defined internal escalation path that reaches ENISA’s SRP within the legal window. According to Mend.io, companies that did not have SBOM infrastructure in place before September 11 are already out of compliance.
For software developers and firmware engineers, the practical shift is toward continuous, automated dependency scanning — monitoring every component in your product against newly published CVEs on an ongoing basis, not as a periodic manual audit. Tools that generate and maintain CycloneDX or SPDX SBOMs are no longer optional for teams shipping to the EU market.
For product managers and executives, the CRA signals an irreversible change in how connected product liability works. Cybersecurity failures now carry legal exposure comparable to physical product safety violations. Treating security as a launch-day checkbox is no longer legally defensible.
Looking Ahead: What to Watch in 2027
September 11’s reporting deadline is the opening act. The CRA’s full requirements — mandatory CE marking for compliant products, the five-year minimum support obligation, and the complete suite of secure-by-design engineering controls — activate on December 11, 2027.
Industry analysts and compliance specialists are forecasting several market shifts before that date:
- Product market bifurcation: Products unable to meet CRA requirements will be withdrawn from EU sale, opening market share in connected device categories currently dominated by lower-cost, non-compliant hardware — particularly from manufacturers in regions with historically weaker security standards.
- SBOM tooling standardization: The CRA’s mandate for CycloneDX or SPDX SBOMs is expected to accelerate global adoption of software supply chain transparency tooling, including in markets where it is not yet legally required. The EU is effectively exporting its standard worldwide.
- Cyber insurance reshaping: Major cyber insurers have signalled that CRA-compliant SBOM practices and documented vulnerability management programs will factor into IoT product liability premiums by 2027, creating a financial incentive for compliance independent of regulatory enforcement.
The cost of non-compliance — up to €15 million or 2.5% of global annual turnover, whichever is higher — makes even expensive compliance infrastructure look modest by comparison. And with cybercrime costs projected to exceed $20 trillion globally by 2026, the business case for security investment has never been stronger on its own merits.
Conclusion
The EU Cyber Resilience Act represents the most significant regulatory shift in connected product security in a generation. For the first time, security is not a voluntary engineering decision — it is a legal obligation enforced by financial penalties measured in tens of millions of euros. With the September 11 reporting deadline now active, the time for preparation has ended. Whether you make IoT sensors, ship enterprise firmware, or distribute connected consumer devices to EU customers, the CRA defines your new compliance baseline. The manufacturers who respond by building genuine, lasting security infrastructure — real SBOMs, real vulnerability management programs, real support commitments — will be better positioned legally and commercially as the connected device market grows toward an estimated 39 billion units by 2030.
Sources:
- Keysight: One Year Countdown to EU CRA Compliance
- Crowell & Moring: EU CRA September 11 Reporting Deadline
- Mend.io: EU Cyber Resilience Act 2026 Compliance Guide
- Telit: CRA Vulnerability Reporting
- Telit: EU CRA What IoT Manufacturers Need to Know
- Cavli Wireless: IoT Devices CRA Compliance Guide
- Swif.ai: IoT Security Statistics 2026
- TechTimes: EU CRA Filing Portal Launches Same Day It Becomes Mandatory
- European Commission: CRA Reporting Obligations
- Anchore: EU CRA SBOM Requirements
- arXiv: Effects of the CRA on Industrial Equipment Manufacturers
- Linux Foundation EU: Will the CRA Help the European ICT Sector Compete?
- Infosecurity Magazine: CRA — EU Regulators Must Strike the Right Balance
- AWS IoT Blog: EU CRA Alignment Guide for IoT Services
- consult.red: EU CRA Q3 2026 Update