The reporting requirements of the EU Cyber Resilience Act come into force in September 2026.
If you place products with digital elements onto the EU market, including mobile apps, you are likely to be affected and might need to take action to be compliant.
Download Bedrock Cyber’s EU CRA Factsheet to quickly learn what you should know today.
What the factsheet covers
- Scope what counts as a product “with digital elements”, how remote data processing is treated, where importers and distributors pick up obligations, and what is excluded.
- The two dates 11 September 2026 for reporting, 11 December 2027 for full application.
- Reporting obligations the 24-hour, 72-hour and 14-day clocks, the ENISA Single Reporting Platform, and who else has to be told.
- Core obligations secure by design and default, no known exploits at release, support periods, vulnerability handling, and the documentation you have to keep.
- Who does the work an example of how compliance activity lands across engineering, supply chain, legal, support and leadership.
- A pathway six practical steps to take before the harmonised standards arrive.
Complying with the act is not a one-size-fits-all exercise. The standard doesn’t change with company size, but the practical implementation does.
It is common for teams to already be doing more security work than they realise or can currently point to evidence for.