started · updated
EU Cyber Resilience Act deadline for manufacturers: July 31 2026
The European Union’s Cyber Resilience Act (CRA) mandates that companies offering products with digital components register by 31 July 2026. Registration triggers a suite of obligations, including security‑by‑design, regular security updates, and proactive vulnerability management. Non‑compliant firms face fines of up to €15 million or 2.5 % of worldwide annual turnover, and missing the registration deadline can incur penalties of up to €500 000.
From 11 September 2026, manufacturers must report exploited vulnerabilities or serious security incidents to ENISA and the relevant national CSIRT within 24 hours, submit a full report within 72 hours, and provide remediation evidence within 14 days (or one month for severe cases). Companies often struggle with unclear responsibility, unrealistic timelines, incomplete product inventories, and insufficient lifecycle monitoring, which can lead to missed deadlines and hefty fines.