Piotr Polak

Cybersecurity and standardization expert


The Cyber Resilience Act is an EU regulation that requires products with digital elements to be secure when placed on the EU market and to remain secure over their supported lifetime.

Key dates

  • 11 September 2026 - reporting obligations for manufacturers are enforced: actively exploited vulnerabilities and severe incidents affecting products already on the EU market must be reported
  • 11 December 2027 - products must be fully compliant with the CRA; on the same date the RED Delegated Act is repealed
Cyber Resilience Act timeline

Reading guide

These articles walk through the regulation from the manufacturer’s perspective:

Questions about how the CRA applies to your products? Get in touch.