European guidelines on the Cyber Resilience Act: what changes and the 11 September 2026 deadline

5 Sep , 2026 - News

European guidelines on the Cyber Resilience Act: what changes and the 11 September 2026 deadline

The European Commission and the Italian National Cybersecurity Agency (ACN) have published the official guidelines on the application of the Cyber Resilience Act, Regulation (EU) 2024/2847, which governs the cybersecurity of products with digital elements.

The document clarifies how the regulation should be read and offers practical guidance and real-world use cases for developers, manufacturers and businesses. It lands at a specific moment: the first operational obligations start on 11 September 2026.

Who the Cyber Resilience Act applies to

Scope first, because that is what everyone wants to know. The CRA addresses those who place products with digital elements on the European market: hardware, software, connected devices and components. It concerns whoever develops business software, manufactures IoT devices, sells software solutions or embeds firmware in their own products.

It does not concern a company that merely uses third-party software for its own operations. The distinction is clear-cut and worth checking early: many manufacturing SMEs find they are in scope because of the software embedded in the products they sell.

Cyber Resilience Act: the nine sections of the European guidelines and the 11 September 2026 deadline
The nine sections of the European guidelines on the Cyber Resilience Act.

The nine sections of the guidelines

The document is organised into nine practical sections covering the whole compliance journey:

  1. Scope of application — which products with digital elements fall under the obligations.
  2. Placing on the market — criteria and duties before commercialisation.
  3. Open source software — handling free code and developer responsibilities.
  4. Substantial modifications — when an update changes the product and triggers a new conformity assessment.
  5. Spare parts — operational rules for replacement components.
  6. Support period — how to define and communicate the security support lifecycle to users.
  7. Vulnerability handling — vulnerability management across the product lifecycle.
  8. Incident reporting — notification duties towards the national CSIRT and ENISA.
  9. Conformity assessment — compliance routes and market surveillance.

The 11 September 2026 deadline

From 11 September 2026 the obligations set out in Article 14 come into force. Manufacturers of products with digital elements active on the European market must report every actively exploited vulnerability and every severe security incident to the national CSIRT and to ENISA.

The timeline is tight and leaves no room for delay:

  • Within 24 hours — early warning, partial information allowed. Its purpose is to trigger the process, not to provide a full picture.
  • Within 72 hours — notification with the assessment of the vulnerability or incident and the corrective measures adopted.
  • Within 14 days — final report with a full description, root causes, impact and remediation applied.

Twenty-four hours are not many if nobody knows who decides that a vulnerability is being actively exploited, who signs the notification and through which channel it is sent. Those decisions belong before an incident, not during one.

11 September 2026 is only the first step: full application of the regulation is set for 11 December 2027, when the essential cybersecurity requirements and the conformity assessment obligations take effect.

What is at stake

The regulation sets penalties proportionate to the severity of the breach: failure to meet the essential cybersecurity requirements can reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. For other obligations, including reporting, the caps are lower but still material.

CRA Article 14: early warning within 24 hours, notification within 72 hours, final report within 14 days
Reporting timelines under Article 14 of the Cyber Resilience Act.

How FinGreenTech supports your compliance

Complying with the CRA takes two things at once: technical product security and documented procedures. FinGreenTech SRL Benefit Company works on both.

Vulnerability assessment and penetration testing

Analysis of products and infrastructure to find flaws before they are exploited, with a report that also serves as evidence of the vulnerability management process the regulation requires.

Incident response and reporting plans

Roles, activation thresholds and transmission channels defined in advance, so that the 24-hour early warning follows a written and tested procedure rather than improvisation.

Certified management systems

Guidance towards ISO/IEC 27001 for information security and ISO/IEC 42001 for artificial intelligence management systems: two frameworks that cover much of what the CRA asks you to document.

Secure cloud and infrastructure

Data centres in Italy and the ACN QC2 qualification as a certified cloud provider for the Italian Public Administration: your data stays within the national perimeter.

Funding and subsidies

Vouchers and non-repayable grants to cover the cost of technological upgrades and certification. Checking which incentives apply is part of the project, not a separate service.

FinGreenTech as Cyber Resilience Act compliance partner
The CRA compliance journey with FinGreenTech.

Check whether the CRA applies to your products

The first step is understanding whether your products or services fall within the scope of the regulation and which processes need to change. If you have doubts about scope, reporting duties or deadlines, get in touch: the initial assessment is free.

Source: Italian National Cybersecurity Agency (ACN), European guidelines on the application of the Cyber Resilience Act. For all application matters, the text of Regulation (EU) 2024/2847 and the official European Commission documentation prevail. Please note that the official guidance is available in Italian and in the EU official languages.


, , ,

Leave a Reply

Your email address will not be published. Required fields are marked *