EU Cyber Resilience Act 2026: What Connected Hardware Founders Should Build Into the Prototype Now
For founders and product teams shipping connected hardware into the EU: what the CRA already requires now (reporting) and what must be designed into the next prototype before full application in 2027.
September 17, 20264 min read

Written by Konstantin Dolgan, Ph.D., NPDP
Founder & CEO, Product Development Engineer
Published September 17, 2026
Short answer: Regulation (EU) 2024/2847 (the Cyber Resilience Act) covers hardware and software "products with digital elements" made available on the EU market, including final products and components. It entered into force on 10 December 2024.
Main obligations apply from 11 December 2027. Chapter IV (notification of conformity assessment bodies) applies from 11 June 2026. Article 14 reporting obligations apply from 11 September 2026.
For connected-hardware founders, secure-by-design choices (unique device identity, signed OTA, vulnerability disclosure channel, SBOM and component diligence) belong in early architecture and the functional prototype, not after enclosure freeze.

What the Cra Covers
The European Commission summarizes Regulation (EU) 2024/2847 as a horizontal framework for hardware and software products with digital elements made available on the Union market. That includes final products and components placed separately on the market.
Products fall in scope when they are made available on the market and their intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
Manufacturer duties (as summarized by the Commission) include a cybersecurity risk assessment during design, development, and production. Due diligence on third-party components. Technical documentation. Conformity assessment. An EU Declaration of Conformity; CE marking. And user information that includes the end date of the support period (month and year).
Related reading: IoT idea development, IoT security, and IoT developer guidance.
Cra Timeline Milestones Founders Should Track
Milestone | Date | Why it matters for a prototype program |
|---|---|---|
CRA entered into force | 10 December 2024 | The Regulation is live law; planning windows are already open. |
Chapter IV: notification of conformity assessment bodies | 11 June 2026 | Notified-body ecosystem starts to matter for products that need third-party assessment. |
Commission practical guidance for manufacturers/developers/SMEs | 27 July 2026 | Use the Commission guidance alongside the Regulation text when scoping design evidence. |
Article 14 reporting obligations | 11 September 2026 | Actively exploited vulnerabilities and severe security incidents must be notified on CRA timelines via the Single Reporting Platform. |
Main CRA obligations / full product conformity regime | 11 December 2027 | Design, conformity assessment, CE marking, and related duties apply for placing products on the market under the full regime. |
Reporting starts before full conformity
After placing a product on the market, manufacturers must notify actively exploited vulnerabilities and severe incidents affecting product security via the CRA Single Reporting Platform (to the relevant CSIRT and ENISA): an early warning within 24 hours, a main notification within 72 hours, then final reports on the timelines in the Commission summary (including a final report no later than 14 days after a corrective or mitigating measure is available for actively exploited vulnerabilities, and within one month from the 72-hour submission for severe incidents).
Reporting obligations apply to products already made available on the Union market, including those placed before 11 December 2027. The full product conformity regime still starts on 11 December 2027 (with transitional notes in the Commission summary). Products placed before that date are generally subject to the CRA after that date only if they undergo a substantial modification, while reporting still reaches products already on the market.
Prototype-phase Security Checklist (Map to Cra Themes)
Run this once per connected-hardware program and keep answers with the design file. These are engineering sequencing prompts, not a compliance certificate.
- Unique device identity and credential provisioning planned before PCB freeze (supports authenticity and update trust).
- Signed, authenticated OTA update path designed into firmware and backend (vulnerability handling depends on being able to patch in the field).
- Vulnerability disclosure channel and internal intake process drafted before launch (needed when Article 14 reporting clocks start).
- SBOM / third-party component diligence started during architecture (manufacturer due diligence on components).
- Cybersecurity risk assessment notes captured during design reviews, not only at certification crunch.
- Support-period end date (month and year) decided as a product policy input, because user information must state it.
- Logging and incident severity criteria sketched so a 24h / 72h notification is operationally possible.
- Enclosure and debug access reviewed so field update and secure defaults are still possible after tooling.
Why this belongs before enclosure freeze
Unique identity, signed OTA, disclosure channels, and component diligence change architecture, PCB options, antenna and debug ports, and sometimes the housing. Waiting until after enclosure freeze turns a documentation task into a redesign.
Soft brand note from LA NPDT: treat these as idea-to-functional-prototype decisions, the same way you would treat DFM for a critical interface.
See also regulatory-compliant design guidance and engineering for global markets.
What this is not
- Not legal advice. Confirm scope and obligations for your product against the Regulation text and qualified counsel.
- Not a claim that every connected product needs the same conformity assessment path. Important and critical product categories have additional rules in the Commission materials.
- Not a substitute for reading the Official Journal text and the Commission guidance published 27 July 2026.
Sources
- European Commission, Cyber Resilience Act policy page (notes 27 July 2026 practical guidance)
If you are still proving the connected concept, design identity, update trust, and component diligence into the functional prototype rather than around them later. If you are already quoting tooling, freeze the enclosure only after a security-minded design review. Book a consult with LA NPDT when you want an engineering-side walkthrough of prototype sequencing for EU-bound connected hardware. This article is not legal advice.
Frequently asked questions
When Do Cra Reporting Obligations Start?
Article 14 reporting obligations apply from 11 September 2026, according to the European Commission CRA summary.
When Does the Full Cra Product Regime Apply?
Main obligations apply from 11 December 2027. Chapter IV on notification of conformity assessment bodies applies earlier, from 11 June 2026.
Does reporting apply to products already on the EU market?
Yes. The Commission summary states reporting obligations apply to products already made available on the Union market, including those placed before 11 December 2027.
What must manufacturers notify, and how fast?
Actively exploited vulnerabilities and severe incidents affecting product security, via the CRA Single Reporting Platform to the relevant CSIRT and ENISA: early warning within 24 hours, main notification within 72 hours, then final reports on the Commission summary timelines.
What should founders put into the next prototype now?
Prioritize unique device identity, signed OTA, a vulnerability disclosure channel, SBOM/component diligence, and risk-assessment notes that travel with the design file. Those choices are hard to bolt on after enclosure freeze.
Is this legal advice?
No. This is an educational overview for product and engineering sequencing. Verify against Regulation (EU) 2024/2847, the Commission summary and guidance, and counsel for your market plans.
Related articles
All articles
CPSC Lithium Battery Rules Are Moving in 2026: What Hardware Founders Should Change Before the Next Prototype
For founders and product teams building battery-powered industrial, pet, outdoor, or consumer hardware: what CPSC proposed on June 24, 2026 for lithium-ion micromobility batteries, and how to keep enclosure, BMS, and charger choices from locking you into a redesign after tooling.

Pfas Rules Are Moving in 2026: What Hardware Founders Should Change in Material Specs Before Prototype
For founders and product teams building industrial, medical, pet, outdoor, or consumer hardware: what changed in US TSCA PFAS reporting timing and the EU REACH restriction process in 2026, and how to keep early material choices from locking you into a redesign after tooling.
FDA QMSR 2026: What Medical Device Founders Should Change Before the Next Prototype
For founders and product teams building Class I/II hardware: what actually changed when FDA's QMSR replaced the old QS framework, and how to keep early prototypes from becoming regulatory debt.
Services related to this guide
- Best prototyping companiesDevelopment firms, instant-quote bureaus and local shops — who fits which job.
- Free prototype cost calculatorFive to eight questions, an instant cost range for a first prototype.
- Prototype development companiesWhich firms take a sketch to a working prototype — and which only fabricate parts.
- Rapid prototypingWorking prototypes in days, from 3D printing to vacuum casting.