Key data
| Regulation | Amendment to Regulation (EU) 2024/2690 — Cyber Resilience Act (CELEX:32024R2690R(03)) |
|---|---|
| Publication | August 7, 2026 |
| Entry into force | Not specified in the amendment |
| Affected parties | Manufacturers, importers and distributors of products with digital elements marketed in the EU |
| Maximum penalty | €15,000,000 or 2.5% of annual global turnover (whichever is higher) |
| Category | European Regulation |
If you sell hardware, software or any connected device in the European Union, Regulation (EU) 2024/2690, known as the Cyber Resilience Act, is already in force and this amendment published on August 7, 2026 corrects errors in the original text to ensure its proper application. It is not a future standard: it is the legal framework that defines what you must comply with today to avoid risking million-euro sanctions.
What does this regulation establish?
The Cyber Resilience Act establishes mandatory cybersecurity requirements for all products with digital elements marketed in the EU. This amendment (CELEX:32024R2690R(03)) corrects technical errors in the original text of Regulation (EU) 2024/2690, without altering its substantive content.
The main obligations covered by the regulation are:
- Security by design: Products must comply with cybersecurity standards from the development phase, not as an afterthought.
- Full lifecycle: Security responsibility extends throughout the entire product lifecycle, including updates and support.
- Vulnerability and incident notification: Manufacturers are required to notify actively exploited vulnerabilities and security incidents to competent authorities.
- Supply chain responsibilities: Not only manufacturers are responsible. Importers and distributors also assume specific obligations.
- SME provisions: There are specific measures to facilitate compliance for small and medium-sized enterprises, although they do not exempt them from essential obligations.
| Obligation | Who assumes it | Scope |
|---|---|---|
| Security by design | Manufacturers | From development to commercialization |
| Security maintenance | Manufacturers | Throughout the entire product lifecycle |
| Vulnerability and incident notification | Manufacturers | To EU competent authorities |
| Supply chain responsibility | Importers and distributors | Verification of manufacturer compliance |
Economic and operational impact
The economic impact of the Cyber Resilience Act materializes on two levels: the cost of adaptation to comply and the cost of non-compliance.
As for the penalty risk, the regulation sets the highest threshold between two options: €15 million or 2.5% of annual global turnover. For a company with €100 million in global turnover, the potential fine would reach €2.5 million. For a company with €800 million in turnover, it would exceed €15 million.
As for the cost of operational adaptation, companies must plan investments in:
- Review and redesign of product development processes to incorporate security from the outset.
- Implementation of vulnerability monitoring and management systems throughout the lifecycle.
- Creation or strengthening of internal procedures for notifying authorities in case of incidents.
- Audit of suppliers and partners in the supply chain to verify their compliance.
SMEs have specific provisions that can reduce administrative burden, although essential security requirements are equally applicable.
Who does it affect?
- Hardware manufacturers with digital components or connectivity (IoT devices, consumer electronics, connected industrial equipment, etc.).
- Software developers and manufacturers commercialized as a product in the EU.
- Importers who introduce digital products manufactured outside the Union into the EU market.
- Distributors who make available on the EU market products with digital elements.
- Technology SMEs that develop or sell any product with a digital component, although with some specific facilities.
Products already covered by specific sectoral cybersecurity regulations (such as certain medical devices or aviation equipment) are outside the scope of this regulation, although it is advisable to verify on a case-by-case basis.
Practical example
Imagine a medium-sized Spanish company that manufactures smart locks connected via Bluetooth and WiFi and distributes them in several EU countries, with annual global turnover of €40 million.
Under the Cyber Resilience Act, this company must:
- Redesign its development process to incorporate security testing before launching each model to market.
- Maintain an active firmware update channel throughout the entire product lifecycle, not just in the first months after launch.
- Establish an internal procedure to detect and notify vulnerabilities to competent authorities within the timeframes set by the regulation.
- Review contracts with its electronic component suppliers to ensure they also comply with required standards.
If this company fails to meet its obligations and is sanctioned, the fine could reach 2.5% of its €40 million global turnover, that is, up to €1 million in a single enforcement proceeding.
What should companies do now?
- Identify if your product falls within the scope of the regulation: Review whether you manufacture, import or distribute any product with digital elements in the EU. If in doubt, consult with a product regulation specialist.
- Audit your current development process: Assess whether your development cycle already incorporates security requirements from design or if you need to adapt it.
- Establish a vulnerability management system: Create or strengthen procedures to detect, manage and notify vulnerabilities and incidents to competent authorities.
- Review your supply chain: If you are an importer or distributor, verify that the manufacturers you work with comply with the regulation's requirements. Your responsibility is also at stake.
- Consult specific SME provisions: If you are a small or medium-sized enterprise, identify what specific facilities the regulation applies to you to plan your adaptation efficiently.
- Document compliance: The regulation requires you to be able to demonstrate compliance to authorities. Generate and retain the necessary technical and process documentation.
The risk of not acting is clear: fines of up to €15 million or 2.5% of annual global turnover, plus possible blocking of product commercialization in the EU.
Frequently asked questions
How much can the fine be for violating the Cyber Resilience Act?
Regulation (EU) 2024/2690 sets penalties of up to €15 million or 2.5% of annual global turnover, applying whichever figure is higher. For a company with €200 million in global turnover, that equals €5 million in maximum potential fine.
Does the Cyber Resilience Act only affect large technology companies?
No. It affects any manufacturer, importer or distributor of products with digital elements operating in the EU market, regardless of size. SMEs have some specific provisions to facilitate compliance, but are not exempt from essential cybersecurity obligations.
What obligations do importers and distributors have, not just manufacturers?
The regulation extends responsibilities throughout the supply chain. Importers must verify that products they introduce into the EU comply with the regulation's requirements. Distributors also assume obligations when making products available to the market. It is not enough for the manufacturer to comply: importers and distributors are equally responsible.
What must be notified to authorities and within what timeframe?
The Cyber Resilience Act requires manufacturers to notify competent authorities of actively exploited vulnerabilities and security incidents affecting their products. The specific notification timeframes are set out in the text of Regulation (EU) 2024/2690, which you can consult in the official source linked at the end of this article.
What exactly is a "product with digital elements" according to this regulation?
This refers to any hardware or software product that includes digital components, especially those with connectivity capability (to the internet, local networks, Bluetooth, etc.). This covers everything from IoT devices and smart appliances to commercial software, connected industrial equipment and consumer electronics. If your product can connect or has firmware, it is very likely to fall within the scope of the regulation.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32024R2690R(03)