The Cyber Resilience Act is Europe’s attempt to make cybersecurity part of the price of selling digital products in the EU.
At its core, the law requires manufacturers to build security into software and hardware, keep track of vulnerabilities, provide security updates and maintain products securely over their expected lifetimes. The goal is straightforward: fewer insecure products reaching customers and fewer vulnerabilities left to rot after they do.
The rollout is already underway. The CRA entered into force in December 2024. Some provisions began applying this June. Sept. 11, 2026, is the first deadline most security teams will actually feel. That’s when manufacturers must begin reporting actively exploited vulnerabilities and severe product-security incidents, with an initial warning due within 24 hours and additional information within 72 hours. The rest of the law becomes broadly applicable on Dec. 11, 2027.
The flag on the company headquarters does not matter. U.S. manufacturers that sell software, hardware or anything with a digital element into the EU can be subject to the CRA. They must play by the same rules as a company in Berlin or Brussels.
[Related: The Cyber Resilience Act: America’s Next EU Compliance Headache]
By 2027, CRA violations can ultimately expose companies to regulatory penalties, corrective orders and restrictions on products that do not meet the law’s cybersecurity requirements. Those include the possibility that a product has to be recalled from the EU market. The law’s top administrative fine reaches €15 million (or $17.5 million) 2.5% of worldwide annual revenue, whichever is higher.
The reporting rule is mandatory. The €15 million fine is not yet in play.
Beginning Sept. 11, manufacturers subject to the CRA must report actively exploited vulnerabilities and severe product-security incidents. An early warning is due within 24 hours of becoming aware, followed by a more detailed notification within 72 hours. That obligation is live — not voluntary, not a dress rehearsal.
But most of the rest of the CRA does not begin applying until Dec. 11, 2027. That includes Article 64, which establishes fines of up to €15 million or 2.5% of worldwide annual turnover for violations that include the Article 14 reporting requirements.
In plain English: a company can violate a mandatory CRA reporting obligation beginning Sept. 11, 2026, but the CRA’s €15 million administrative-fine provision does not itself begin applying until December 2027.
That creates an unusual 15-month transition period: the duty arrives before the CRA’s biggest statutory stick.
That does not make ignoring the rule consequence-free. A missed report is still a failure to comply with a legal obligation. The underlying cyber event may also trigger other disclosure laws, customer or contractual obligations, and scrutiny from European customers, importers or regulators. But it would be misleading to tell readers that a company missing the 24-hour deadline this September immediately risks a €15 million CRA fine.
There is also no separate timetable for American companies. A U.S. manufacturer whose product falls under the CRA and is made available on the EU market faces the same Sept. 11, 2026 reporting date as an EU manufacturer. There is no U.S. grace period.
Then, on Dec. 11, 2027, the equation changes sharply. The CRA becomes broadly applicable, its product-security and conformity requirements come into force, and its administrative-fine regime applies. At that point, violations of key requirements, including Articles 13 and 14, can carry the fines: €15 million or 2.5% of worldwide annual turnover, whichever is higher.