453 days left
Cyber Resilience Act
The Cyber Resilience Act applies to anyone placing a product with digital elements on the EU market — hardware or software, sold or free. Its reporting obligations begin on 11 September 2026, and full compliance follows on 11 December 2027.
Who it catches
Manufacturers, importers and distributors of anything with a digital element. That is far wider than software houses: a machine builder shipping a controller, an appliance with a companion app, a sensor with firmware, a company that sells a device someone else manufactured under its own brand. Slovenia has a large manufacturing base and very little of it has begun preparing, largely because the obligation arrived as product-safety law rather than as cyber-security law and landed on the wrong desk.
THE DATES
Where this stands today
-
CRA enters into force
-
Reporting obligations begin, including for products already on the market
-
Full compliance required for products placed on the market
What it actually requires
- Security by design, and secure configuration out of the box rather than after setup
- Signed and authenticated updates, delivered for a defined support period
- A vulnerability-handling process, with a coordinated disclosure policy
- Reporting of actively exploited vulnerabilities and severe incidents to ENISA
- Technical documentation, conformity assessment and CE marking for cyber security
- A software bill of materials, so you know what is inside what you ship
What it costs to get wrong
Up to €15 million or 2.5% of global annual turnover for breaching the essential requirements. The more immediate consequence is simpler: a product that cannot carry the CE marking cannot be sold in the EU, and a distributor that discovers this late has an inventory it cannot move.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Penetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more VMVulnerability management
Continuous discovery, prioritised by what is actually reachable and actually exploited — not by a scanner dumping ten thousand findings on your team.
Read more IRIncident response
Containment, eradication and recovery, on site if it needs to be. The 24-hour clock in the law starts the moment you notice, not the moment you call.
Read moreNot sure whether Cyber Resilience Act applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.