{"id":102,"date":"2026-08-11T20:36:17","date_gmt":"2026-08-11T15:06:17","guid":{"rendered":"https:\/\/rainverse.com\/insights\/?p=102"},"modified":"2026-08-11T21:30:25","modified_gmt":"2026-08-11T16:00:25","slug":"the-cyber-resilience-act-what-the-eus-new-software-law-means-for-every-digital-product","status":"publish","type":"post","link":"https:\/\/rainverse.com\/insights\/the-cyber-resilience-act-what-the-eus-new-software-law-means-for-every-digital-product\/","title":{"rendered":"The Cyber Resilience Act: What the EU&#8217;s New Software Law Means for Every Digital Product"},"content":{"rendered":"\n<h4>Part: One<\/h4> <div class=\"rainverse-audio-player\" style=\"background: rgba(255,255,255,0.05); border: 1px solid rgba(255,255,255,0.1); border-radius: 8px; padding: 16px 20px; margin-bottom: 24px;\"> <div style=\"display: flex; align-items: center; gap: 10px; margin-bottom: 12px; font-size: 14px; color: #aaa;\"> <span style=\"font-size: 18px;\">\ud83d\udd0a<\/span> <span style=\"flex: 1; font-weight: 500;\">Listen to this article (~8 min)<\/span> <\/div> <audio controls=\"\" preload=\"metadata\" style=\"width: 100%; height: 40px;\"> <source src=\"http:\/\/rainverse.com\/audio_tts\/cyber_resilience_act_article_1_tts.mp3\" type=\"audio\/mpeg\"> <\/audio> <\/div> <p class=\"text-justify\"><strong>A quiet deadline is approaching. On 11 September 2026, the first major deadline under one of the most consequential pieces of software regulation in modern history arrives \u2014 and most companies that will be affected don&#8217;t know it yet.<\/strong><\/p> <p class=\"text-justify\">The European Union&#8217;s <strong>Cyber Resilience Act<\/strong> (CRA) is a horizontal, binding legal framework that applies to essentially every hardware and software product with digital elements sold on the EU market. It&#8217;s not a niche directive for critical infrastructure. It covers the smart watch on your wrist, the app on your phone, the software inside your car, and the platform you build on.<\/p> <p class=\"text-justify\">It is also the clearest statement yet that <strong>&#8220;secure by design&#8221; is no longer a best practice \u2014 it&#8217;s becoming the law.<\/strong> The Act itself rolled out in stages: it entered into force in December 2024, its first obligations apply from September 2026, and its full requirements follow in December 2027. To be precise about what lands when, we&#8217;ve linked the authoritative sources straight into this article \u2014 because with a regulation this consequential, you should be able to check our work.<\/p> <p class=\"text-justify\">This article is the first of two. Here, we lay out what the CRA actually is, what it requires, and the two deadlines that matter. In the second, we&#8217;ll look at the strategic opportunity hiding inside it \u2014 and why the smartest builders are already ahead.<\/p> <hr> <h3>What the CRA is \u2014 and why it exists<\/h3> <p class=\"text-justify\">Officially, the CRA is <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/2847\/oj\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">Regulation (EU) 2024\/2847<\/a>. Per the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">European Commission<\/a>, it entered into force on <strong>10 December 2024<\/strong>.<\/p> <p class=\"text-justify\">Its purpose is straightforward: for decades, digital products have been built to work first and hardened later. Vulnerabilities are patched reactively \u2014 after a breach, after an exploit, after the damage is done. The CRA flips that assumption.<\/p> <p class=\"text-justify\">Under the new rules, manufacturers must meet <strong>mandatory cybersecurity requirements at every stage of the value chain<\/strong> \u2014 planning, design, development, and ongoing maintenance. They must handle vulnerabilities across the entire lifecycle of their products. And for products of particular cybersecurity relevance, a <strong>third-party assessment by a notified body<\/strong> may be required before they can be sold in the EU.<\/p> <p class=\"text-justify\">Compliant products carry the <strong>CE marking<\/strong>, and national market-surveillance authorities will enforce the rules.<\/p> <p class=\"text-justify\">The CRA doesn&#8217;t stand alone. It builds on the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cybersecurity-strategy\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">EU&#8217;s 2020 Cybersecurity Strategy<\/a> and, as the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">Commission notes<\/a>, complements the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/nis-directive\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">NIS2 Directive<\/a> \u2014 together forming a coherent European approach to cybersecurity.<\/p> <hr> <h3>The two deadlines that matter<\/h3> <p class=\"text-justify\">The CRA is rolling out in two distinct waves, and they create two very different kinds of pressure.<\/p> <h4>Wave one \u2014 11 September 2026: the reporting duty that never rests<\/h4> <p class=\"text-justify\">The Commission&#8217;s <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">reporting obligations<\/a> page confirms that, from <strong>11 September 2026<\/strong>, manufacturers must report <strong>actively exploited vulnerabilities<\/strong> and <strong>severe security incidents<\/strong> affecting their products.<\/p> <p class=\"text-justify\">The clock doesn&#8217;t start when you&#8217;re ready. It starts the moment you become aware, on these exact timeframes:<\/p> <ul> <li>An <strong>early warning<\/strong> must be filed within <strong>24 hours<\/strong>.<\/li> <li>A <strong>full notification<\/strong> within <strong>72 hours<\/strong>.<\/li> <li>A <strong>final report<\/strong> follows \u2014 within <strong>14 days<\/strong> for a vulnerability, or within one month for a severe incident.<\/li> <\/ul> <p class=\"text-justify\">These figures are stated directly by the Commission in its <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">official guidance on reporting obligations<\/a>.<\/p> <p class=\"text-justify\">Two details catch people out.<\/p> <p class=\"text-justify\">First, <strong>this duty reaches your entire installed base.<\/strong> Even products placed on the market before the law applied are in scope for reporting. If a vulnerability in something you shipped years ago is actively exploited and you become aware of it on or after 11 September 2026, you report it \u2014 whether or not the product was ever modified.<\/p> <p class=\"text-justify\">Second, <strong>this is an always-on obligation, not a one-time checklist.<\/strong> It attaches to your whole team, around the clock, for as long as your products are out there.<\/p> <h4>Wave two \u2014 11 December 2027: security becomes a design requirement<\/h4> <p class=\"text-justify\">The larger wave arrives on <strong>11 December 2027<\/strong>. From this date, the CRA&#8217;s full product requirements apply: security by design and by default, baked in across the entire lifecycle, with CE marking as proof of compliance. The Commission&#8217;s own <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">guidance<\/a> frames it plainly: principal obligations from 11 December 2027, with reporting obligations already applying from 11 September 2026.<\/p> <p class=\"text-justify\">This is the moment &#8220;vulnerability handling&#8221; stops being a nice-to-have and becomes a legal, auditable requirement of making and selling a product at all.<\/p> <hr> <h3>What counts as &#8220;a product with digital elements&#8221;<\/h3> <p class=\"text-justify\">The scope is deliberately broad. It includes <strong>final products and components<\/strong> placed separately on the market. If it has a chip, a connection, or a line of code, and it reaches EU consumers, it&#8217;s likely in scope.<\/p> <p class=\"text-justify\">Two clarifications worth knowing, from the Commission&#8217;s <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">practical guidance<\/a>, published in July 2026:<\/p> <ul> <li><strong>Remote data processing solutions<\/strong> and <strong>free and open-source software<\/strong> received explicit attention on scope.<\/li> <li>The guidance also clarifies what counts as a <strong>&#8220;substantial modification&#8221;<\/strong> (which can pull older products into the full requirements), how <strong>support periods<\/strong> should be understood, and how to meet <strong>reporting and risk-assessment<\/strong> obligations.<\/li> <\/ul> <p class=\"text-justify\">The guidance is deliberately SME-friendly \u2014 per the Commission, it includes <strong>67 practical examples<\/strong>, use cases, flowcharts, and graphs, so smaller companies can find a proportionate path to compliance without unnecessary administrative burden.<\/p> <hr> <h3>The open-source angle most people miss<\/h3> <p class=\"text-justify\">There&#8217;s a lesser-known clause worth flagging: the CRA reaches <strong>open-source software stewards<\/strong> too. If you maintain a widely used library or project that&#8217;s part of a product with digital elements, your obligations around actively exploited vulnerabilities are real.<\/p> <p class=\"text-justify\">This matters beyond any single project. It means the open-source ecosystem \u2014 the shared foundation most modern software is built on \u2014 is now part of the EU&#8217;s formal security framework. Strong vulnerability handling is no longer optional for major open-source projects; it&#8217;s becoming a structural expectation.<\/p> <hr> <h3>What to do now (if you ship to the EU)<\/h3> <p class=\"text-justify\">Readiness is operational, not paperwork. The reporting obligation goes live in weeks, so the practical checklist is:<\/p> <ul> <li><strong>Build a vulnerability-reporting runbook.<\/strong> Who detects, who drafts, who files, who covers the night shift.<\/li> <li><strong>Name a primary and a backup representative.<\/strong> EU Login accounts can be created today.<\/li> <li><strong>Know your CSIRT<\/strong> \u2014 the computer security incident response team that is your point of contact (based on your main establishment in the EU, or your authorised representative&#8217;s if you&#8217;re outside the EU).<\/li> <li><strong>Keep an accurate software bill of materials (SBOM).<\/strong> You can&#8217;t report a vulnerability in a component you didn&#8217;t know you shipped.<\/li> <li><strong>Monitor continuously.<\/strong> Match your components against known-vulnerability sources so an actively exploited flaw surfaces in hours, not weeks.<\/li> <\/ul> <p class=\"text-justify\">The reporting platform itself \u2014 <a href=\"https:\/\/www.enisa.europa.eu\/topics\/product-security\/single-reporting-platform-srp\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">ENISA&#8217;s Single Reporting Platform (SRP)<\/a> \u2014 is scheduled to be operational by 11 September 2026. (Independent reporting on the SRP, such as <a href=\"https:\/\/www.cyberresilienceact.eu\/reporting.html\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">this CRA walkthrough<\/a>, notes that ENISA has indicated no application programming interface will be provided at this stage, making the human side of readiness \u2014 named people, backups, out-of-hours coverage \u2014 genuinely important.)<\/p> <hr> <h3>The bottom line<\/h3> <p class=\"text-justify\">The CRA is a statement about the future: <strong>software security is becoming a floor you must stand on, not a feature you can skip.<\/strong><\/p> <p class=\"text-justify\">For companies selling into Europe, the September deadline is real and imminent. For everyone else, the December 2027 wave is the structural shift that will reshape how digital products are designed, built, and maintained.<\/p> <p class=\"text-justify\">Either way, the direction is clear. And as we&#8217;ll explore in the second article, the builders who internalize this early aren&#8217;t just avoiding a burden \u2014 they&#8217;re building an advantage.<\/p> <p class=\"text-justify\"><em>This article is informational and does not constitute legal advice. The CRA is evolving; timelines and guidance may be updated by the European Commission and ENISA. Information reflects the position as of August 2026.<\/em><\/p> <hr> <h3>Sources (primary)<\/h3> <ul> <li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cyber-resilience-act\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">European Commission \u2014 Cyber Resilience Act policy page<\/a><\/li> <li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">European Commission \u2014 CRA reporting obligations<\/a><\/li> <li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">European Commission \u2014 practical guidance, July 2026<\/a><\/li> <li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act-implementation-frequently-asked-questions\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">European Commission \u2014 CRA implementation FAQ<\/a><\/li> <li><a href=\"https:\/\/www.enisa.europa.eu\/topics\/product-security\/single-reporting-platform-srp\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">ENISA \u2014 Single Reporting Platform<\/a><\/li> <li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/2847\/oj\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">Regulation (EU) 2024\/2847 (EUR-Lex)<\/a><\/li> <li>Independent reference (SRP reporting detail): <a href=\"https:\/\/www.cyberresilienceact.eu\/reporting.html\" target=\"_blank\" rel=\"noopener\" style=\"text-decoration: underline;\">cyberresilienceact.eu \u2014 reporting walkthrough<\/a><\/li> <\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Part: One \ud83d\udd0a Listen to this article (~8 min) A quiet deadline is approaching. On 11 September 2026, the first major deadline under one of the most consequential pieces of software regulation in modern history arrives \u2014 and most companies that will be affected don&#8217;t know it yet. The European Union&#8217;s Cyber Resilience Act (CRA) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":109,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-insights"],"_links":{"self":[{"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/posts\/102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/comments?post=102"}],"version-history":[{"count":2,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/posts\/102\/revisions"}],"predecessor-version":[{"id":108,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/posts\/102\/revisions\/108"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/media\/109"}],"wp:attachment":[{"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/media?parent=102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/categories?post=102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rainverse.com\/insights\/wp-json\/wp\/v2\/tags?post=102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}