EU Cyber Resilience Act 2026: What Connected Hardware Founders Should Build Into the Prototype Now

For founders and product teams shipping connected hardware into the EU: what the CRA already requires now (reporting) and what must be designed into the next prototype before full application in 2027.

September 17, 20264 min read

Konstantin Dolgan

Written by Konstantin Dolgan, Ph.D., NPDP

Founder & CEO, Product Development Engineer

Published September 17, 2026

Short answer: Regulation (EU) 2024/2847 (the Cyber Resilience Act) covers hardware and software "products with digital elements" made available on the EU market, including final products and components. It entered into force on 10 December 2024.

Main obligations apply from 11 December 2027. Chapter IV (notification of conformity assessment bodies) applies from 11 June 2026. Article 14 reporting obligations apply from 11 September 2026.

For connected-hardware founders, secure-by-design choices (unique device identity, signed OTA, vulnerability disclosure channel, SBOM and component diligence) belong in early architecture and the functional prototype, not after enclosure freeze.

Connected hardware prototype on a lab bench (interim image while CRA soft-brand hero awaits static deploy)
Secure-by-design choices belong in architecture and the functional prototype, before you freeze the enclosure.

What the Cra Covers

The European Commission summarizes Regulation (EU) 2024/2847 as a horizontal framework for hardware and software products with digital elements made available on the Union market. That includes final products and components placed separately on the market.

Products fall in scope when they are made available on the market and their intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.

Manufacturer duties (as summarized by the Commission) include a cybersecurity risk assessment during design, development, and production. Due diligence on third-party components. Technical documentation. Conformity assessment. An EU Declaration of Conformity; CE marking. And user information that includes the end date of the support period (month and year).

Related reading: IoT idea development, IoT security, and IoT developer guidance.

Cra Timeline Milestones Founders Should Track

Milestone
Date
Why it matters for a prototype program
CRA entered into force
10 December 2024
The Regulation is live law; planning windows are already open.
Chapter IV: notification of conformity assessment bodies
11 June 2026
Notified-body ecosystem starts to matter for products that need third-party assessment.
Commission practical guidance for manufacturers/developers/SMEs
27 July 2026
Use the Commission guidance alongside the Regulation text when scoping design evidence.
Article 14 reporting obligations
11 September 2026
Actively exploited vulnerabilities and severe security incidents must be notified on CRA timelines via the Single Reporting Platform.
Main CRA obligations / full product conformity regime
11 December 2027
Design, conformity assessment, CE marking, and related duties apply for placing products on the market under the full regime.

Reporting starts before full conformity

After placing a product on the market, manufacturers must notify actively exploited vulnerabilities and severe incidents affecting product security via the CRA Single Reporting Platform (to the relevant CSIRT and ENISA): an early warning within 24 hours, a main notification within 72 hours, then final reports on the timelines in the Commission summary (including a final report no later than 14 days after a corrective or mitigating measure is available for actively exploited vulnerabilities, and within one month from the 72-hour submission for severe incidents).

Reporting obligations apply to products already made available on the Union market, including those placed before 11 December 2027. The full product conformity regime still starts on 11 December 2027 (with transitional notes in the Commission summary). Products placed before that date are generally subject to the CRA after that date only if they undergo a substantial modification, while reporting still reaches products already on the market.

Prototype-phase Security Checklist (Map to Cra Themes)

Run this once per connected-hardware program and keep answers with the design file. These are engineering sequencing prompts, not a compliance certificate.

  • Unique device identity and credential provisioning planned before PCB freeze (supports authenticity and update trust).
  • Signed, authenticated OTA update path designed into firmware and backend (vulnerability handling depends on being able to patch in the field).
  • Vulnerability disclosure channel and internal intake process drafted before launch (needed when Article 14 reporting clocks start).
  • SBOM / third-party component diligence started during architecture (manufacturer due diligence on components).
  • Cybersecurity risk assessment notes captured during design reviews, not only at certification crunch.
  • Support-period end date (month and year) decided as a product policy input, because user information must state it.
  • Logging and incident severity criteria sketched so a 24h / 72h notification is operationally possible.
  • Enclosure and debug access reviewed so field update and secure defaults are still possible after tooling.
Related: a connected product (hardware + app) is exactly the class of product with digital elements CRA planning needs to reach early.
Video page ↗

Why this belongs before enclosure freeze

Unique identity, signed OTA, disclosure channels, and component diligence change architecture, PCB options, antenna and debug ports, and sometimes the housing. Waiting until after enclosure freeze turns a documentation task into a redesign.

Soft brand note from LA NPDT: treat these as idea-to-functional-prototype decisions, the same way you would treat DFM for a critical interface.

See also regulatory-compliant design guidance and engineering for global markets.

What this is not

  • Not legal advice. Confirm scope and obligations for your product against the Regulation text and qualified counsel.
  • Not a claim that every connected product needs the same conformity assessment path. Important and critical product categories have additional rules in the Commission materials.
  • Not a substitute for reading the Official Journal text and the Commission guidance published 27 July 2026.

Sources

If you are still proving the connected concept, design identity, update trust, and component diligence into the functional prototype rather than around them later. If you are already quoting tooling, freeze the enclosure only after a security-minded design review. Book a consult with LA NPDT when you want an engineering-side walkthrough of prototype sequencing for EU-bound connected hardware. This article is not legal advice.

Frequently asked questions

When Do Cra Reporting Obligations Start?

Article 14 reporting obligations apply from 11 September 2026, according to the European Commission CRA summary.

When Does the Full Cra Product Regime Apply?

Main obligations apply from 11 December 2027. Chapter IV on notification of conformity assessment bodies applies earlier, from 11 June 2026.

Does reporting apply to products already on the EU market?

Yes. The Commission summary states reporting obligations apply to products already made available on the Union market, including those placed before 11 December 2027.

What must manufacturers notify, and how fast?

Actively exploited vulnerabilities and severe incidents affecting product security, via the CRA Single Reporting Platform to the relevant CSIRT and ENISA: early warning within 24 hours, main notification within 72 hours, then final reports on the Commission summary timelines.

What should founders put into the next prototype now?

Prioritize unique device identity, signed OTA, a vulnerability disclosure channel, SBOM/component diligence, and risk-assessment notes that travel with the design file. Those choices are hard to bolt on after enclosure freeze.

Related articles

All articles

Get in touch

Tell us what this is about

Share a few details about your question, partnership, or idea — a member of the LA NPDT team will reply within one business day.

Optional context

What are you looking to accomplish? (optional)

What do you already have? (optional — tick any)

Your information stays confidential and is never shared.