For most of the history of the Internet of Things, security was something device makers chose to invest in, or chose not to. Weak default passwords, unpatched firmware and products abandoned a year after launch were common, and there was rarely a legal consequence. Buyers carried the risk.
In the European Union, that arrangement is ending. The Cyber Resilience Act, known as the CRA, turns cybersecurity into a legal requirement for almost every product with digital elements sold in the EU, from baby monitors and smart watches to industrial controllers and the software that runs on them.
The law has been on the books since late 2024, but for most companies it has felt distant. That changed this month. On 11 September 2026, the CRA’s first practical obligation came into force: manufacturers must now report actively exploited vulnerabilities in their products. The rest of the law follows in December 2027.
For IoT makers, importers and the companies that buy from them, the next fifteen months are a transition period in which a great deal needs to change.
What The Cyber Resilience Act Is
The CRA is formally Regulation (EU) 2024/2847. Unlike a directive, which each member state turns into its own national law, a regulation applies directly and uniformly across the EU. The European Commission’s CRA page describes its scope as covering products “from baby-monitors to smart watches, from apps to computer programs, connectable hardware and software.”
Products With Digital Elements
The law uses the term “products with digital elements.” In practice, that covers hardware and software that can connect to a device or network, directly or indirectly. For the IoT industry, that means most of what it makes: consumer devices, industrial equipment, gateways, embedded software, operating systems and standalone applications.
Some sectors already governed by their own security rules, such as certain medical devices and vehicles, are handled under those separate frameworks. For most connected products, though, the CRA is now the baseline.
Where The Rules Apply
The CRA applies to products placed on the EU market regardless of where the manufacturer is based, as a recent explainer by Transforma Insights noted. A device designed in the United States and built in China must meet the same requirements as one made in Germany if it is sold in the EU.
The Timeline
The law is being phased in over three years. Three dates matter most.
December 2024: The Law Takes Effect
The CRA was formally adopted in October 2024 and entered into force on 10 December 2024. That date started the clock but did not immediately impose obligations on manufacturers. It gave the industry, standards bodies and national authorities time to prepare.
September 2026: Reporting Begins
From 11 September 2026, manufacturers must report actively exploited vulnerabilities in their products and severe incidents that affect product security. This is the first obligation with real operational consequences.
The regulation sets tight timelines. For an actively exploited vulnerability, a manufacturer must send an early warning within 24 hours of becoming aware of it and a fuller notification within 72 hours, followed by a final report once a fix or mitigation is available. Reports go through a single reporting platform run by ENISA, the EU’s cybersecurity agency, to the relevant national computer security incident response team.
Importantly, the reporting duty is not limited to new products. It applies to products already on the EU market, including devices sold years before the law existed. A manufacturer that learns of an exploited flaw in an older model still has to report it.
December 2027: Full Application
From 11 December 2027, the CRA’s main obligations apply. Products placed on the EU market from that date must meet the law’s essential cybersecurity requirements, go through the appropriate conformity assessment and carry the CE marking to show compliance. National market surveillance authorities will enforce the rules.
What Manufacturers Must Do
The CRA’s requirements fall into two broad groups: how products are designed and built, and how manufacturers handle security once products are in use.
Security By Design
Products must be designed, developed and produced with an appropriate level of cybersecurity based on the risks they face. That includes shipping without known exploitable vulnerabilities, using secure default settings, protecting data and limiting the attack surface.
For IoT makers, this rules out many practices that were once routine. Universal default passwords, unnecessary open services and unencrypted communications are all difficult to justify under the new rules. Security has to be considered from the first design decisions, not added after launch.
Vulnerability Handling
The second group covers what happens after sale. Manufacturers must identify and document vulnerabilities, maintain a software bill of materials that lists the components in their products, test security regularly, run a coordinated vulnerability disclosure process so outside researchers can report problems, and provide security updates promptly.
The software bill of materials is especially significant for IoT. Many devices contain open-source libraries and third-party components that manufacturers do not track closely. When a flaw is found in a widely used library, companies without an accurate component list often cannot tell which of their products are affected.
Support Periods And Updates
The CRA also addresses the problem of devices abandoned soon after launch. Manufacturers must set a support period during which they will handle vulnerabilities and provide security updates. The regulation expects that period to reflect how long a product is reasonably expected to be used, and generally to be at least five years unless the product’s expected life is shorter.
Products should also support security updates and, where appropriate, automatic updates. As the Transforma Insights explainer put it, cybersecurity “becomes a lifecycle responsibility” that runs through a product’s expected lifetime.
For device makers, this changes product economics. Supporting a device for five years or more means keeping engineering teams, build systems and update infrastructure available long after the product stops generating new sales.
Not All Products Are Treated Equally
The CRA uses a risk-based approach. Most products fall into a default category, while a smaller number are classed as important or critical because a security failure would have greater consequences.
Default Products
Products in the default category can be self-assessed. The manufacturer carries out the conformity assessment internally, prepares technical documentation and issues a declaration of conformity. This covers a large share of ordinary connected products.
Important Products
Important products are divided into two classes. Class I includes a number of IoT-relevant categories, such as routers and modems, microcontrollers and microprocessors with security-related functions, and smart home products with security functions, including smart door locks, security cameras, baby monitors and alarm systems. Class II covers more sensitive items such as firewalls and tamper-resistant microcontrollers.
Important products face stricter conformity routes. Depending on the class and whether harmonised standards are applied, that can mean assessment by an independent notified body rather than self-assessment.
Critical Products
A small group of critical products, including smart meter gateways and smartcards or secure elements, may be subject to European cybersecurity certification. For companies in metering and secure hardware, this is the most demanding tier.
The Transforma Insights explainer made the practical point clearly: whatever route applies, “the manufacturer remains responsible for declaring (and ultimately defending) compliance.”
Who Else Is Affected
The CRA is aimed at manufacturers, but its reach extends further along the supply chain.
Importers, Distributors And Private Labels
Importers and distributors have their own duties, such as checking that products carry the right markings and documentation. More importantly for IoT, a company that sells a device under its own brand, or substantially modifies an existing product, can take on the manufacturer’s obligations. White-label and rebranded devices, common in consumer IoT, are a particular area of exposure.
Open-Source Software
Open-source software presents a special case. The CRA introduces a lighter set of obligations for “open-source software stewards,” organisations that support open-source projects intended for commercial use, rather than treating them as full manufacturers. Companies that build commercial products using open-source components, however, remain responsible for the security of the final product, including those components.
Penalties
The CRA carries substantial fines. For breaches of the essential cybersecurity requirements and the core manufacturer obligations, penalties can reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Lower tiers apply to other breaches. National authorities can also restrict or withdraw non-compliant products from the market.
The full legal text of the regulation, including the penalty provisions and product annexes, is available on EUR-Lex.
What IoT Makers Should Do Now
With reporting already live and full application fifteen months away, a few steps are worth prioritising.
The first is readiness to report. Companies need a process that can detect an actively exploited vulnerability, escalate it internally and file an early warning within 24 hours. That means knowing who is responsible, how to reach them outside working hours and how to use the reporting platform.
The second is an accurate inventory of components. Without a software bill of materials for each product line, it is difficult to respond quickly when a widely used library is found to be vulnerable.
The third is a vulnerability disclosure policy. Researchers need a clear way to report issues, and companies need a process to triage and respond to them.
The fourth is deciding support periods. Product teams should set realistic support commitments for existing and planned products, and budget for the engineering work required to keep them.
The fifth is classification. Companies should work out which of their products fall into the default, important or critical categories, because that determines the conformity route and the time needed to prepare.
The sixth is supplier management. Components, modules and software from suppliers all affect the final product’s compliance. Contracts and supplier questionnaires may need updating to ensure the necessary information and updates flow through the supply chain.
What Buyers Should Ask Suppliers
The CRA places most obligations on manufacturers, but companies that buy connected equipment have good reason to pay attention. A supplier that cannot meet the new rules may be unable to keep selling in the EU, and products without a clear support period may become harder to justify in procurement.
Buyers can use the transition period to ask practical questions. How long will this product receive security updates, and is that commitment in writing? How does the supplier handle vulnerability reports, and how quickly are fixes delivered? Can the supplier provide a software bill of materials or equivalent information about components? Which CRA category does the product fall into, and what conformity route will it follow from December 2027?
Answers to these questions will not guarantee a secure product, but they reveal whether a supplier has started preparing. For long-lived IoT deployments, that preparation matters as much as the product’s features.
Beyond Europe
The CRA applies only to products sold in the EU, but its effects are likely to spread. Few manufacturers will maintain separate, less secure versions of products for other markets. Many are likely to raise their baseline globally rather than manage two standards.
Other jurisdictions are moving in a similar direction, with rules on default passwords, security labelling and vulnerability disclosure. The details differ, but the direction is shared: connected products are expected to be secure by design and supported after sale.
A New Baseline For Connected Devices
For years, the IoT industry was criticised for treating security as optional. The CRA changes the terms. Security is now a legal condition of access to one of the world’s largest markets, with deadlines, reporting duties and penalties attached.
The first obligation is already in force. The rest arrives in December 2027. For companies that design, build, import or sell connected products in Europe, the question is no longer whether to invest in product security, but how quickly they can put the processes in place to prove it.