If your product has a chip, a network connection, or an app that talks to it, and it ships into the EU, the Cyber Resilience Act (CRA) applies to you — regardless of where you're headquartered. A lot of US manufacturers still read it as "the EU's law" and file it under someday. The first hard deadline is closer than someday.
What the CRA actually requires
The CRA is the EU's first horizontal cybersecurity law covering hardware and software products with digital elements — not just IT gear, but connected industrial equipment, building systems, and embedded devices. It sets baseline requirements: security by design, a software bill of materials, default security updates where feasible, and defined support periods you have to disclose to customers.
None of that is exotic. It's closer to what a mature product security program should already be doing. The CRA just makes it a market-access requirement instead of a best practice.
The scope question US manufacturers get wrong
"We don't have an EU office" isn't the test. The test is whether the product reaches the EU market — sold directly, sold through a distributor, or embedded in something else that ends up there. Importers and distributors carry obligations too, which means EU customers and channel partners will start asking US manufacturers for CRA documentation well before enforcement dates, simply to protect their own compliance position.
If you export to the EU at all, assume you're in scope until you've confirmed otherwise.
Two dates, not one
The CRA rolls out in stages, and conflating them is the most common planning mistake:
- September 11, 2026 — Reporting obligations start. If you identify an actively exploited vulnerability or a severe incident affecting an in-scope product, you must notify ENISA: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a set window after a fix is available. This applies to products already on the market, not just new launches.
- December 11, 2027 — Full obligations apply, including conformity assessment and CE marking for in-scope products.
September 2026 is a reporting deadline. December 2027 is a product deadline. Manufacturers who treat them as one date usually end up unprepared for the earlier one.
What "ready" looks like before September
Getting ahead of the reporting deadline is mostly an operational problem, not a technical one:
- Inventory your CRA-relevant products — including legacy products still sold or supported in the EU.
- Define an "awareness" trigger internally. The CRA doesn't set a bright line for when the clock starts on the 24-hour window, which means your own escalation process has to.
- Map the reporting path to ENISA's platform and clarify who owns the notification once a qualifying event is confirmed.
- Check overlap with NIS2 and other reporting duties — a single incident can trigger more than one clock, to more than one authority, on different timelines.
None of this requires guessing at figures — but it does require knowing where your product sits. The CRA sorts products into risk tiers (default, Class I, Class II, and Critical) that determine whether self-assessment is enough or a notified body has to sign off. That classification is specific to what your product actually does, so it's worth confirming with counsel or a CRA readiness assessment before you commit to a conformity timeline — it's the single factor that decides how much runway you actually have.
Where this connects to what you're already doing
If you're already running vulnerability management, incident response, and vendor oversight programs, the CRA is mostly a documentation and reporting-cadence problem layered on top of controls you likely have. Our compliance and GRC services help manufacturers map existing programs against CRA obligations without starting from scratch, and teams already reporting risk to a board can extend that same reporting into CRA notification workflows through our Risk Operations Center.
We've also put together practical guides and checklists for manufacturers working through CRA scoping.
Not sure whether your product line is in scope, or what your September deadline actually requires? Talk to an MBCTG expert — a short conversation is usually enough to tell you which of the two 2026/2027 deadlines matters most for your situation.