European Regulations

Cyber Resilience Act: Real obligations for digital product manufacturers

E
Equipo Editorial CambiosLegales
06 Aug 2026 6 min 84 views

Key data

RegulationCorrection of Regulation (EU) 2024/2847 — Cyber Resilience Act
PublicationAugust 6, 2026
Entry into forceNot specified in this correction
Affected partiesManufacturers, importers and distributors of hardware and software products with digital connectivity
CategoryEuropean Regulation
Original regulation approvedOctober 23, 2024
SourceEU Official Journal — OJ:L_202690667
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

If your company manufactures, imports or distributes any product that connects to a network—a router, an industrial sensor, an IP camera, a SaaS software or a smart home device—the Cyber Resilience Act directly affects you. Regulation (EU) 2024/2847, approved on October 23, 2024, establishes for the first time horizontal cybersecurity requirements applicable to the entire value chain of digital products in the European Union.

The correction published on August 6, 2026 rectifies formal errors in the original text to ensure its uniform application in all official EU languages. It does not modify the substantive obligations, but confirms that the regulatory framework is consolidated and that companies must advance in their adaptation.

What does this regulation establish?

The Cyber Resilience Act introduces a set of horizontal requirements—that is, applicable to all sectors, not just the technology sector—for any product that incorporates digital elements and is marketed in the EU. The three fundamental pillars are:

ObligationWhat it consists ofWho must comply
Security by designProducts must be designed and developed with cybersecurity integrated from the initial phase, not as a later additionManufacturers
Vulnerability managementObligation to identify, report and correct security vulnerabilities throughout the product's useful lifeManufacturers and importers
Security updatesProvision of patches and security updates throughout the product lifecycleManufacturers

The regulation also modifies the following pre-existing European standards to align them with the new framework:

  • Regulation (EU) No 168/2013 (type-approval of two or three-wheel vehicles)
  • Regulation (EU) 2019/1020 (market surveillance and product compliance)
  • Directive (EU) 2020/1828 (representative actions for the protection of collective consumer interests)

The correction published in August 2026 does not alter any of these obligations: its scope is exclusively formal, ensuring linguistic consistency between the official versions of the regulation.

Economic and operational impact

The Cyber Resilience Act is not a documentary compliance standard: it requires real changes in development, production and commercialization processes. Affected companies must anticipate costs in several areas:

  • Product redesign: integrating security requirements from the design phase involves reviewing technical architectures and development processes.
  • Continuous vulnerability management: companies will need dedicated teams or services for monitoring and responding to security incidents.
  • Extended support: the obligation to provide updates throughout the product lifecycle can significantly extend post-sale support commitments.
  • Documentation and compliance: it will be necessary to demonstrate compliance to market surveillance authorities, which involves certification and audit processes.
  • Penalties for non-compliance: the regulation provides for significant penalties, although the specific amounts depend on the graduation established by each Member State in its transposition.

The impact is especially relevant for companies that have not previously operated in sectors regulated from a cybersecurity perspective: consumer electronics manufacturers, software developers, machinery manufacturers with connectivity or industrial IoT solution providers.

Who does it affect?

  • Connected hardware manufacturers: routers, cameras, IoT sensors, smart home devices, industrial machinery with connectivity.
  • Software developers and distributors: commercial applications, operating systems, firmware, embedded software.
  • Importers of digital products: companies that introduce products manufactured outside the EU into the European market.
  • Distributors: companies that market third-party products with digital elements in the European market.
  • Manufacturers of two or three-wheel vehicles with connected digital components (due to the modification of Regulation 168/2013).

Digital products already covered by specific sectoral regulations that establish equivalent cybersecurity requirements (such as certain medical devices or aviation equipment) are not affected.

Practical example

A Spanish company that manufactures smart locks with WiFi connectivity and markets them in Europe must, under the Cyber Resilience Act:

  1. Review the firmware development process to incorporate security testing from the design phase ("security by design").
  2. Establish an official vulnerability reporting channel so that researchers or users can report security flaws.
  3. Commit to publishing security updates throughout the declared useful life of the product—not just during the commercial warranty period.
  4. Document the entire process to prove it to the market surveillance authority if required.

If the company imports these locks from an Asian manufacturer instead of producing them itself, the obligations fall equally on the importer as responsible for the product's compliance in the European market.

Do you need to track this and other regulations?

Check the full details in CambiosLegales

What should companies do now?

  1. Identify if your product falls within the scope of the regulation: any product with digital elements that connects to networks or other devices is potentially included. Review your complete catalog.
  2. Audit current development processes: assess whether your product development cycle already incorporates security testing, vulnerability management and update policy.
  3. Assign internal responsibility: designate a person responsible for Cyber Resilience Act compliance within your organization or technical team.
  4. Review contracts with external suppliers and manufacturers: if you import or distribute third-party products, ensure that contracts address the compliance obligations that the regulation transfers to the importer.
  5. Plan for certification: depending on the risk category of the product, third-party conformity assessment may be necessary. Start the process with sufficient advance notice.
  6. Monitor the date of full applicability: although the correction published in August 2026 does not specify a new entry into force date, the original regulation from October 2024 establishes progressive timelines. Stay updated on official communications from the European Commission.

Frequently asked questions

What products are required to comply with the Cyber Resilience Act?

All products with digital elements marketed in the EU that include connectivity to networks or other devices: IoT devices, connected hardware, commercial software and firmware. Products already covered by specific sectoral regulations with equivalent cybersecurity requirements are excluded.

When does the Cyber Resilience Act enter into force and when must I be adapted?

Regulation (EU) 2024/2847 was approved on October 23, 2024. The correction published on August 6, 2026 does not establish a new entry into force date. The original regulation contemplates progressive application timelines. It is essential to monitor official communications from the European Commission to know the exact timelines by product category.

What happens if my company does not comply with the Cyber Resilience Act?

The regulation provides for significant penalties for non-compliance. Although the specific amounts will be graduated according to the regulations of each Member State, the European framework establishes that non-compliance can result in relevant economic penalties, withdrawal of the product from the European market and liability before market surveillance authorities.

If I import digital products manufactured outside the EU, am I responsible for compliance?

Yes. The Cyber Resilience Act transfers compliance obligations to the importer when the manufacturer is outside the EU. The importer is responsible for ensuring that the product complies with the regulation's requirements before introducing it into the European market.

Does the correction published in August 2026 change my company's obligations?

No. The correction of August 6, 2026 rectifies only formal errors in the original text to ensure consistency between versions in all official EU languages. It does not modify any substantive obligation, any timeline or any technical requirement of Regulation (EU) 2024/2847.

Official source

Consult the complete regulation in official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202690667



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts