As of 11 September 2026 the EU’s Cyber Resilience Act is no longer a ‘future problem’. Manufacturers of products with digital elements must now report actively exploited vulnerabilities and severe incidents to relevant authorities, on a timescale measured in hours rather than weeks. The remaining obligations, including CE marking and conformity documentation, apply from 11 December 2027. Importers, distributors and resellers also have ‘due diligence’ obligations under the regulation.
For a regulation that entered into force in December 2024, the CRA has attracted remarkably little attention outside compliance teams. That is starting to change, and not always comfortably.
If you sell hardware or software with digital elements on the EU market, be it a consumer smartwatch or a B2B backup appliance, the CRA applies to you (and to us, too!). And if you buy rather than sell, the CRA works in your favour: your resilience depends on your vendors, and you now have a common standard to hold them to.
What actually changed in September
The reporting duty is the part that requires immediate attention. A manufacturer that becomes aware of an actively exploited vulnerability in its product now has to notify the relevant national Computer Security Incident Response Team (CSIRT) and ENISA, the EU’s agency for cybersecurity. It’s a three-step process: an early warning, then a fuller assessment, and lastly a final report. The same applies to severe incidents affecting the security of the product.
That isn’t a documentation exercise you can complete the week before an audit. It requires a process for people to report problems to you, someone to assess them, named owners, and an agreed rule for deciding what has to be reported - all of it working before whatever triggers it happens.
If you resell or distribute in the EU, you are already expected to verify that this process exists, whether or not the manufacturer has an EU legal entity.
Why you might be caught off guard
Three things, mostly. The first is scope. The CRA covers products with ‘digital elements’, which is a far wider net than many vendors assumed when they first considered it. Connected hardware, standalone software, and components sold into other products all qualify.
The second is who the duty falls on: importers, distributors and resellers carry obligations too, including checking that the manufacturer has done what they were supposed to do.
The third is the timeline. December 2027 sounded comfortably distant in 2024, so it’s likely that plenty of organisations’ roadmaps deferred the work in favour of more pressing tasks - for example NIS2 or DORA regulations. But the CRA’s first milestone, the September 2026 reporting date, was always sooner and is now here, with immediate obligations.
Compliance is the starting point, not the goal
There is a more interesting question underneath the deadlines. The CRA is designed to raise the security baseline of products sold in Europe, and that is worth doing. But almost every requirement in it is about reducing the likelihood of compromise: secure development, vulnerability handling, timely updates, no default passwords shipped in the box.
None of that tells an organisation what happens on the day prevention fails, despite those precautions. Even mature, well-funded, well-staffed security programmes will inevitably get breached.
The CRA helps prevent attacks. Backup storage with Absolute Immutability helps organisations recover from them.
We applaud any effort to raise the security bar across the industry, and the CRA does that. But at Object First we treat it as a waypoint rather than the finish line. Meeting it is necessary, and we are meeting it; however the outcome customers actually care about is whether they can get their data back when an attacker gets through their defences.
Where Object First stands
As a manufacturer ourselves, our incident and vulnerability reporting processes have been in place since the September obligation took effect, aligned to the ENISA reporting requirements, and we are working to the applicable future CRA requirements ahead of December 2027, including CE marking and conformity documentation.
Two commitments matter beyond the paperwork.
The first is that security is designed into our products from the start rather than bolted on later, which is why we signed the CISA Secure by Design Pledge before any regulation required us to.
The second is that we do not expect anyone to take our security claims on trust. The CRA permits self-assessment for products like backup appliances; we think customers and partners deserve more than that, so our architecture has been independently tested by NCC Group, with Absolute Immutability, multi-factor authentication, and role-based access controls put in front of people actively trying to break them.
The evidence behind all of this now lives in our Trust Center, which is the fastest route to the documentation your own compliance team will ask for.
What to ask your vendors
If you are an importer, distributor, reseller or buyer rather than a manufacturer, the CRA has effectively handed you a due diligence checklist. Three questions get you most of the way:
- Do you have a vulnerability reporting process in place today, and can you show it to me?
- Has your security architecture been tested by someone other than you, and can I read the report in full?
- When prevention fails in my environment and attackers get in, will your product still do what it’s supposed to do?
A vendor that answers the first two and cannot answer the third has built for compliance, not for resilience. See how NCC independent security testing validates Object First’s Secure by Design storage.
