Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

Cyber Resilience Act

Is Your Organisation Ready for the First Deadline?

HuFiCon Management Memo:
Journey with the CISO

A mountain climb to cyber security resilience. Find out how to get to the summit of cyber security resilience in Inge van der Beijl's management memo, from her presentation at the Human Firewall Conference (HuFiCon) on the 14.11.2024.

The climb will take you from the base camp of foundational security to the high-camp of a security conscious culture, all the way to the summit consisting of strategic security integration. 

inge_van_der_beijl
Inge van der Beijl

Director Innovation

Digital-Autonomy-EU
Published: August 2026

Is your organisation ready for the first CRA deadline?

On 11 September 2026, the first deadline of the European Cyber Resilience Act (CRA) goes into effect. While most organisations know that the majority of CRA requirements only become applicable in December 2027, many overlook that an important obligation arrives much earlier.

From September 2026 onwards, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. That may sound like a relatively small requirement. However, in practice it requires much more than simply filling in a reporting form. Organisations first need to know:

  • which products they have on the market
  • which products fall within the scope of the CRA
  • how those products are built
  • who owns the response process
  • how information flows between technical and business teams

Bear in mind that this regulation is not without teeth. Non-compliance can incur significant fines: up to €15 million or 2.5% of global annual turnover. With so much on the line, manufacturers can’t afford to procrastinate. To get started today, here are answers to questions about the CRA that we often hear from manufacturers and a free, practical checklist to prepare for the first compliance milestone.

How to determine if the CRA applies to your products

For many organisations, the first task is identifying the products that are in scope. Without that inventory, complying with the reporting obligations is almost impossible.

The CRA applies to most products with digital elements placed on the EU market.

Examples include:

  • Industrial products such as PLCs, production robots and smart energy systems.
  • IoT devices including smart cameras, thermostats, doorbells and wearables.
  • Software products such as operating systems, antivirus software, password managers and mobile applications.

Software offered purely as a hosted service (SaaS) is generally outside the scope of the CRA.

For more information about which products fall under the CRA, visit this webpage with explanations provided by the European Union.

Digital-Autonomy-EU

What new deadlines for incident reporting mean for manufacturers

The majority of CRA requirements start in December 2027. However, as of 11 September 2026, organisations with products in scope will now have tight deadlines for reporting incidents.

The reporting timeline immediately starts whenever a manufacturer becomes aware that:

  • a vulnerability is being actively exploited 
    or
  • a severe security incident impacts one of its products

Then, the organisation must be able to:

  • submit an initial notification within 24 hours
  • follow up with a more detailed report within 72 hours

Those deadlines leave very little room for organisations that still need to figure out ownership, affected products, or technical impact.

“You cannot report what you cannot identify.”

Why organisations should prioritise CRA compliance today

While the September 2026 deadline only introduces reporting obligations, this requirement lays your foundation for full CRA compliance with:

  • a comprehensive product inventory
  • clear view of which products are in the CRA scope
  • insight into software components and dependencies (for example, with an SBOM)
  • vulnerability monitoring
  • incident response procedures
  • internal escalation paths
  • communication plans
  • clear ownership across teams

As many organisations experienced with NIS2 and DORA, implementation often starts only shortly before the deadline. However, security-by-design, product inventories, SBOM management and incident response capabilities require time to mature. By using the coming months to establish governance, product visibility and vulnerability management, you will reduce implementation pressure and prevent compliance from becoming a bottleneck for both product development and commercial opportunities.

Moreover, organisations that prioritise the CRA’s reporting and security standards will benefit beyond compliance. Demonstrating mature vulnerability management, secure development practices, and well-defined reporting processes is a competitive advantage for suppliers aiming to win new contracts and renew business partnerships.

Stars-2

How Northwave Supports CRA Compliance and Product Security

Although this regulation introduces security measures that will be new for many manufacturers, they’re not new for Northwave. We have 20 years of experience implementing the security standards the EU has now enshrined into law, including:

  • secure-by-design development
  • vulnerability handling throughout the product lifecycle
  • technical documentation
  • security updates, risk assessments, and conformity assessments
  • clear governance and reporting practises

For organisations working to achieve their first CRA compliance milestones, we’ve developed a free readiness checklist that translates the reporting obligations into concrete actions before and after the September 2026 deadline.

And, we’ve designed a CRA Quick Scan to help manufacturers gain a fast, structured view of where they stand today and what to do next. If you have questions or would like hands-on support in your CRA compliance journey, get in touch with us today.

We are here for you

Need help with your cyber security or wondering how secure your business really is?
Get in touch and we will help you find the best solution.


.