REGULATORY WATCH BRIEFModerate 49📜 Final Regulationin effect
EU Cyber Resilience Act reporting obligations take effect for manufacturers
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
ADTP Regulatory Watch· September 11, 2026· European Commission
ImpactModerate 49
Type📜 Final Regulation
Statusin effectin force
JurisdictionEU
Effective11 September 2026
What happened
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related to their products.
Why it matters for trust and compliance
Its status is in effect. It is in force now.
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
Takes effect September 11, 2026.
It relates to CRA. The regulations library explains what that law requires.
Who is affected
technologymanufacturingmanufacturermanufacturers of products with digital elements
Recommended actions
Map the security requirements to existing controls and close gaps.
Check breach-notification procedures and timelines against the requirement.