Follow us :
General

EU Cyber Resilience Act: What Starts on 11 September 2026

Close-up of a technician placing an electronic component onto a circuit board with tweezers — Xen Bilişim General

After 11 September 2026, the moment you learn that a vulnerability in a product you sell into Europe is actually being exploited, a clock starts: 24 hours for an early warning, 72 hours for a detailed notification. The upper administrative fine sits at EUR 15 million or 2.5% of global annual turnover, whichever is higher.

A common misreading is that this is cyber security legislation. It isn’t. The EU Cyber Resilience Act (Regulation (EU) 2024/2847, or CRA) is product legislation. The department that owns it is the team managing CE marking and the technical file, not the IT department. IT is a supplier to that process.

Which products fall in scope?

The definition is deliberately wide: any hardware or software that can connect, directly or indirectly, to a device or network. “Product with digital elements” reaches far past software companies — a textile machine with an electronic control board, a remotely monitored HVAC system, a smart meter, a payment terminal, even the companion mobile app shipped with a product.

Roughly 90% of products can be self-assessed by the manufacturer. For the categories listed in Annexes III and IV, the picture changes:

ClassExample productsConformity assessment
DefaultAll other connected products not listedManufacturer self-assessment
Important — Class IRouters, password managers, VPNs, browsers, identity management software, smart home assistantsThird party if harmonised standards are not applied
Important — Class IIFirewalls, intrusion detection and prevention systems, hypervisors, tamper-resistant microcontrollersThird-party assessment always required
CriticalSmart meter gateways, smart cards, hardware devices with security boxesEuropean cybersecurity certification may apply

If your product lands in Class II, you need a plan for working with an EU notified body before 2027. Türkiye’s standards institute (TSE) has stated an ambition to become a notified body for the CRA, but that depends on legislative alignment and designation by the EU. As things stand today, the counterparties are EU-based bodies.

What exactly begins in September?

The regulation entered into force on 10 December 2024, but obligations open in stages. Only the reporting duties start this September.

Reportable eventEarly warningNotificationFinal report
Actively exploited vulnerability24 hours72 hoursWithin 14 days of a corrective measure being available
Severe incident24 hours72 hoursOne month after the notification

The threshold is not “exploitable” but being exploited. A proof of concept or a research finding does not by itself trigger reporting; evidence of real-world attack does. And the clock runs from the moment the manufacturer becomes aware, not from the moment the flaw appeared.

Reporting happens once, through the Single Reporting Platform. The submission goes to the coordinating CSIRT (the national cyber incident response team) for the manufacturer’s main establishment and is made available to ENISA at the same time. Affected users must also be informed, along with any mitigating measures.

Where does a manufacturer in Türkiye report?

This is the part most often missed. For manufacturers not established in the Union, the regulation sets a cascade: first the Member State of the authorised representative covering the most products, then the Member State of the importer placing the most products on the market, then the distributor’s, and finally the Member State with the highest number of users.

Appointing an authorised representative is not mandatory under the CRA — Article 18 says a manufacturer “may” appoint one, unlike the medical device or radio equipment regimes. But if you don’t, your reporting address drifts to wherever your importer sits.

Practically, who tells whom within 24 hours is a contractual question. If your importer agreements don’t spell out the notification flow and the contact channel, the first real incident will burn its opening hours on phone calls.

What changes on 11 December 2027?

The heavier load arrives then. From that date the CE marking covers cybersecurity requirements, and the technical file must contain a risk assessment, a software bill of materials (SBOM) and evidence of security testing.

One item causes particular pain: the support period. Article 13 requires it to reflect the product’s expected lifetime and to be at least five years, dropping to the expected time in use only where that is shorter. Publishing security updates for five years also means the third-party components in your supply chain have to be supported for the same window. If you ship an end-of-life library inside your firmware, the problem starts the day that library loses support, not in 2027.

The view from Türkiye

The Ministry of Trade’s Directorate General for Product Safety and Inspection is running impact analysis and alignment work on the regulation. The Cyber Security Directorate, established under Cyber Security Law No. 7545 (Official Gazette, 19 March 2025), has a steering role on testing, certification and standards.

Waiting for domestic alignment doesn’t help: a manufacturer selling into the EU is already directly subject to the regulation as it stands.

A preparation framework

  1. Product inventory: which of the goods you ship to the EU carry digital elements, and which fall under Annex III? Get the classification wrong and every step after it starts from the wrong place.
  2. Vulnerability intelligence: who watches disclosed flaws in your components, and how often? The 24-hour window does not accept “we heard late” as a defence.
  3. Incident workflow: who decides, who files on the platform, who is reachable at the weekend? Without a written and rehearsed flow, 72 hours is short.
  4. Software bill of materials: is there a version-level list of the open source and third-party components in your firmware, and is it current?
  5. Contracts: have notification, update and support-period clauses been added to importer and supplier agreements?

Organisations that want to walk through these points against their own product line can request a 30-minute assessment call via the contact form.

Frequently asked questions

We only sell software, no hardware. Are we in scope? Yes. Standalone software is covered. The exemptions are narrow: bespoke software built and delivered to a single customer and not placed on the market, and non-commercial open source projects, are treated differently.

An importer sells our product in the EU — are we still the manufacturer? If the product carries your brand, you are. Vulnerability reporting and technical documentation cannot be transferred to the importer; Article 18 explicitly excludes the core manufacturer duties from an authorised representative’s mandate.

If we don’t report, how would anyone find out? Usually through the customer. Your EU buyer reports the incident under its own obligations and the chain follows. Market surveillance authorities also carry out product-level checks.

Is this the same as the 72-hour breach notification under KVKK? No, they are separate. KVKK — Türkiye’s data protection law, comparable in structure to the GDPR — covers personal data breaches; the CRA covers product vulnerabilities. If personal data was exposed too, both notifications run in parallel.

Our components come from Far East suppliers and we get no evidence from them. Now what? The responsibility stays with you. Writing update commitments and component-list disclosure into purchase agreements is one of the cheapest preparation steps available before 2027.

If you want to produce a component inventory for your firmware and put vulnerability tracking on a repeatable process, get in touch.

Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 13, 14, 18, 64 and Annexes III–IV; European Commission “CRA reporting obligations”; Cyber Security Law No. 7545 (Official Gazette 19.03.2025, No. 32846).

Share this post
Türkçe oku

Related Posts