Jump directly to content

Are Companies Ready? First CRA Requirements Take Effect in September

09 September 2026, 06:01

The first requirements of the EU Cyber Resilience Act (CRA) will take effect on 11 September 2026. The regulation applies to most products with digital functionality and affects tens of thousands of companies in Sweden. Companies that fail to comply risk administrative penalties, market restrictions, and exclusion from supply chains. Despite this, many organizations still underestimate the scope of the legislation, according to RISE cybersecurity expert Ted Strandberg.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe cybersecurity incidents to the European Union Agency for Cybersecurity (ENISA). An initial notification must be submitted within 24 hours of becoming aware of an incident, followed by a more detailed report within 72 hours. Once the incident has been resolved, a final report must also be submitted.

The CRA covers virtually all products with digital elements, including connected consumer products, smart home solutions, industrial systems, machinery, and software. As a result, large corporations, smaller development companies, and suppliers throughout the value chain will be affected.

“Many organizations still view the CRA as something that lies further ahead. However, the first obligations take effect already this September. At the same time, many do not realize how broadly the regulation applies. Industrial companies, product developers, manufacturers of connected products, businesses in the energy and real estate sectors, and their suppliers may all be affected by the new requirements,” says Ted Strandberg, Cybersecurity Expert at RISE.

Ted Strandberg, cybersecurity expert at RISE.

The major shift is that cybersecurity can no longer be treated as an afterthought. Companies must demonstrate that security is built into products from the earliest stages of development and managed throughout the entire product lifecycle.

“It is no longer sufficient to address security issues once a product has reached the market. Companies need to work systematically with cybersecurity, from design and development to maintenance, security updates, and clear information on how long the product will be supported,” says Ted Strandberg.

The remaining provisions of the Cyber Resilience Act will become applicable on 11 December 2027. These include requirements related to secure development, vulnerability management, CE marking, and documentation demonstrating compliance with the regulation.

According to Ted Strandberg, the consequences may be particularly significant for suppliers.

“Companies that cannot demonstrate that their products or components meet cybersecurity requirements risk being excluded from supply chains, facing substantial penalties, or being prohibited from placing products on the market. For many organizations, the transition will take several years. If preparations have not yet begun, now is the time to act,” says Ted Strandberg.

RISE participates in several European standardization and harmonization initiatives related to the Cyber Resilience Act. Ted Strandberg leads Sweden's national standardization working group for product cybersecurity and is available to comment on both the implications of the regulation and how its requirements can be implemented in practice.

 

Contact

Ted Strandberg
Cybersecurity Expert, RISE
Chair, Sweden's National Standardization Working Group for Product Cybersecurity

Email: ted.strandberg@ri.se
Phone: +46 10 516 60 93
Mobile: +46 72 454 60 93