Piotr Polak
Cybersecurity and standardization expert
The Cyber Resilience Act is an EU regulation that requires products with digital elements to be secure when placed on the EU market and to remain secure over their supported lifetime.
Key dates
- 11 September 2026 - reporting obligations for manufacturers are enforced: actively exploited vulnerabilities and severe incidents affecting products already on the EU market must be reported
- 11 December 2027 - products must be fully compliant with the CRA; on the same date the RED Delegated Act is repealed

Reading guide
These articles walk through the regulation from the manufacturer’s perspective:
- Cyber Resilience Act: an Overview - scope, product classes, timeline, and obligations
- Cyber Resilience Act: Reporting Obligations - what counts as an actively exploited vulnerability or severe incident, and how and when to report
- RED Delegated Act vs Cyber Resilience Act - how the two regulations differ in scope, protected assets, and requirements
- CRA Guidance: Public Consultation Now Open - the draft Commission guidance and what it tries to clarify
- RED Delegated Act is Repealed - the transition from the RED DA to the CRA
- Webinar | CRA: The Manufacturer’s Perspective - an event page for a manufacturer-oriented CRA introduction
Questions about how the CRA applies to your products? Get in touch.