started · updated
EU adopts new cybersecurity rules for IoT devices
From September 2026 the European Union will enforce new obligations for manufacturers of products with digital components, such as smart watches, connected washing machines, baby monitors and industrial control systems. The rules make producers responsible for the cyber‑security of their devices throughout the entire support period and give authorities the power to ban sales of non‑compliant items.
Manufacturers must report actively exploited vulnerabilities to the national CSIRT and ENISA within 24 hours, then provide additional information and a final report. They are also required to implement secure development practices, monitor emerging flaws, issue security updates and keep full oversight of all components used in the product.
The regulation responds to the rapid growth of internet‑connected devices, which rose from about 3.8 billion in 2015 to over 21 billion today and could reach 40 billion by 2030. Czech officials highlighted the need for change, noting that many devices are shipped with default passwords and unsecured Wi‑Fi. "Cybersecurity is often at the very edge of interest for these products," said Václav Svátek, director of ČMIS, while lawyer Josef Donát emphasized that manufacturers must adopt a systematic approach to vulnerability management.