Attention, UK tech founders reading headlines about Cyber Resilience Act: UK is in scope. It applies to any manufacturer placing a product with digital elements on the EU market, regardless of where that manufacturer is established. Brexit removed the UK from the EU regulatory framework. It did not remove UK products from EU market rules.

The first enforceable obligation binds on 11 September 2026, roughly two weeks from now, and it applies to products already on the EU market rather than only to new releases. Full application follows on 11 December 2027.

The UK has no domestic equivalent. The Cyber Security and Resilience Bill, introduced in November 2025, updates the UK’s NIS Regulations for operators of essential services. It does not create product cybersecurity obligations comparable to the CRA. UK manufacturers selling into the EU therefore face a substantial EU regime with no domestic framework to benchmark against.

This guide explains what the CRA is, exactly how it reaches UK companies, what the obligations are, what the deadlines are, and what UK manufacturers should do now.

Key Definitions

TermDefinition
CRACyber Resilience Act, Regulation (EU) 2024/2847. In force since 10 December 2024
Product with digital elementsAny software or hardware product, and its remote data processing solutions, placed on the EU market whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network
ManufacturerAny person that develops or manufactures a product with digital elements, or has it designed or developed, and markets it under their own name or trademark
ImporterAn EU-established person placing on the EU market a product bearing the name or trademark of a person established outside the EU
Authorised representativeAn EU-established person mandated in writing by a manufacturer to perform specified tasks on their behalf
SBOMSoftware bill of materials. A machine-readable inventory of product components
CE markingThe conformity marking required before a product may be placed on the EU market
ENISAEuropean Union Agency for Cybersecurity. Operates the CRA Single Reporting Platform
CSIRTComputer Security Incident Response Team. The national coordinator for CRA reporting

What Is the Cyber Resilience Act

The Cyber Resilience Act is Regulation (EU) 2024/2847. It entered into force on 10 December 2024 and introduces mandatory cybersecurity requirements for products with digital elements sold in the EU, covering the full product lifecycle from design through to end of support.

Before the CRA, EU product cybersecurity requirements were fragmented across sector-specific instruments: the Radio Equipment Directive for wireless devices, the Medical Devices Regulation for medical software, the Machinery Regulation for industrial equipment. Software sold as a standalone product was largely unregulated on security grounds.

The CRA closes that gap with a horizontal regime. It applies to essentially any product that connects to a device or network, which in practice means most software and most modern hardware.

The core obligations are secure design and development, no known exploitable vulnerabilities at the point of market placement, secure default configuration, a documented vulnerability handling process running for the support period, security updates, a software bill of materials, technical documentation, CE marking, and mandatory reporting of actively exploited vulnerabilities and severe incidents.

Does the Cyber Resilience Act Apply to UK Companies

Yes, in three distinct circumstances.

1. UK Companies Placing Products on the EU Market

The CRA applies to manufacturers placing products with digital elements on the EU market. Territorial scope follows market placement, not establishment.

A UK software company licensing its product to customers in Germany is placing a product on the EU market. A UK hardware manufacturer selling connected devices into France is placing a product on the EU market. A UK SaaS provider offering a service to EU customers where that service involves remote data processing integral to the product is within scope.

The manufacturer’s location, the location of its development team, and the location of its servers are all irrelevant to the scope determination. What matters is whether the product is made available on the EU market in the course of a commercial activity.

2. UK Companies as Component Suppliers

A UK company supplying software components, libraries, or modules that are integrated into products placed on the EU market by others is not itself the manufacturer of the final product. It is, however, subject to contractual pressure that operates like regulation.

EU manufacturers must document all components in their SBOM and must report actively exploited vulnerabilities in third-party components as their own. They will therefore require SBOMs, patching commitments, vulnerability notification obligations, and support period guarantees from their suppliers. UK component suppliers that cannot provide these will be replaced by ones that can.

3. UK Companies with EU Group Entities

Where a UK company sells into the EU through an EU subsidiary that places products on the market under its own name, the EU entity is the manufacturer and carries the obligations directly. Where the EU entity distributes products under the UK parent’s brand, the UK parent is the manufacturer and the EU entity is likely an importer with its own verification obligations.

The corporate structure determines who holds which obligations. It does not determine whether the obligations exist.

ScenarioCRA appliesWho is the manufacturer
UK company sells software directly to EU customersYesUK company
UK company sells through EU distributor under UK brandYesUK company; distributor has separate obligations
UK company sells through EU subsidiary under subsidiary’s brandYesEU subsidiary
UK company supplies components to EU manufacturersNot directlyEU manufacturer; contractual obligations flow to UK supplier
UK company sells only to UK and US customersNoNot applicable
UK company offers free open source outside commercial activityNoNot applicable

Does the UK Have Its Own Cyber Resilience Act? Or Anything Similar?

No. The UK has not enacted a domestic equivalent to the CRA, and the legislation currently before Parliament does not create one.

The Cyber Security and Resilience Bill, introduced in November 2025, updates the UK’s Network and Information Systems Regulations 2018. It expands the scope of regulated entities, strengthens incident reporting duties, and brings managed service providers into the regime. Its focus is organisational cybersecurity for operators of essential and digital services.

That is the NIS2 analogue, not the CRA analogue. It regulates organisations, not products.

The UK’s existing product security legislation is the Product Security and Telecommunications Infrastructure Act 2022, in force since April 2024. The PSTI regime imposes baseline security requirements on consumer connectable products: no universal default passwords, a vulnerability disclosure policy, and transparency about security update periods.

FeatureEU CRAUK PSTI
ScopeAll products with digital elements, consumer and businessConsumer connectable products only
Security requirementsComprehensive, Annex I essential requirementsThree baseline requirements
SBOMRequiredNot required
Vulnerability reporting to authoritiesRequired, 24/72 hour clocksNot required
Conformity assessmentRequired, with notified body routes for higher classesSelf-declaration of conformity
Technical documentationRequiredStatement of compliance only
Support period obligationsMinimum five years as a ruleTransparency about update period, no minimum
Maximum penalty€15 million or 2.5% worldwide turnover£10 million or 4% worldwide turnover

The practical consequence is that a UK manufacturer compliant with PSTI is nowhere near CRA compliant. PSTI addresses three specific issues. The CRA addresses secure development, vulnerability management, component transparency, and lifecycle support.

When Does the Cyber Resilience Act Take Effect?

The CRA phases in over three years. The dates are frequently conflated, and the ordering is counterintuitive.

DateWhat applies
10 December 2024CRA enters into force
11 June 2026Chapter IV applies. Member states designate notifying authorities and notified bodies
11 September 2026Article 14 reporting obligations bind. Actively exploited vulnerabilities and severe incidents must be reported
11 December 2027Full application. Essential requirements, Annex I, SBOM, technical documentation, CE marking, conformity assessment, support period

The reporting obligation arrives fifteen months before the substantive product requirements. Article 71(2) brings it forward deliberately, so the reporting channel is operating before the product rules land.

This creates the sequencing problem that most manufacturers have not addressed. From 11 September 2026, a manufacturer must report an actively exploited vulnerability within 24 hours of becoming aware of it. Determining whether a newly published vulnerability affects your product requires knowing what is inside your product. The SBOM obligation is not legally enforceable until December 2027, but it is operationally necessary from September 2026.

The September 2026 reporting obligations apply to products already on the EU market. There is no grandfathering for existing products.

The Reporting Obligation: What Happens on 11 September 2026

Two events trigger a report: a vulnerability in the product being actively exploited, and a severe incident affecting the product’s security. We have a handy documentation pack to speed up CRA vulnerability reporting.

Reports go simultaneously to the CSIRT designated as coordinator, being that of the member state where the manufacturer has its main establishment, and to ENISA through the Single Reporting Platform.

For UK manufacturers, the coordinating CSIRT question requires attention. A manufacturer with no EU establishment does not have an obvious member state coordinator. Where an authorised representative or importer is in place, that entity’s location typically determines the coordinating CSIRT. UK manufacturers should resolve this before an incident occurs rather than during one.

StageDeadlineContent
Early warning24 hours from awarenessThat the vulnerability or incident exists and, if known, the affected member states
Vulnerability notification72 hours from awarenessGeneral information on the affected product, the nature of the issue, corrective or mitigating measures available
Final report14 days after a corrective measure is availableFull description, severity, impact, corrective measure deployed

The clocks run in elapsed hours. A vulnerability disclosed on a Friday evening does not wait for Monday.

Registration on the Single Reporting Platform cannot be completed retroactively. Manufacturers should register before the obligation binds.

CRA Product Classification

Classification determines the conformity assessment route from December 2027. It does not affect the substantive requirements, which apply uniformly.

ClassExamplesConformity assessment
Default (approximately 90% of the market)Most software and connected hardwareManufacturer self-assessment and EU declaration of conformity
Important, class IBrowsers, VPNs, password managers, network management systems, identity management systemsHarmonised standards or third-party assessment
Important, class IIFirewalls, intrusion detection and prevention systems, hypervisors, tamper-resistant microprocessorsNotified body assessment mandatory
CriticalHardware security modules, smart meter gateways, smartcardsEuropean cybersecurity certification

UK manufacturers of class II products should begin engaging notified bodies well ahead of December 2027. Notified body capacity across the EU is finite and demand will concentrate in 2027.

Do UK Manufacturers Need an EU Authorised Representative for CRA?

The CRA permits, but does not universally mandate, appointment of an authorised representative. Article 17 provides that a manufacturer may appoint an authorised representative by written mandate.

The practical position for UK manufacturers is that some form of EU presence in the compliance chain is difficult to avoid. Where a UK manufacturer has no EU establishment, the importer takes on verification obligations under Article 19, including confirming that the manufacturer has completed conformity assessment, drawn up technical documentation, and affixed CE marking. An importer that cannot verify these cannot lawfully place the product on the market.

For a UK software company selling directly to EU customers without an importer in the chain, appointing an authorised representative is the cleanest route to a functioning compliance and reporting relationship with EU authorities.

This is a distinct requirement from the EU AI Act’s authorised representative obligation under Articles 22 and 54, which is mandatory for non-EU providers of high-risk AI systems and GPAI models. A UK company subject to both regulations may need to address both, and the same entity can hold both mandates if appropriately structured.

What UK Manufacturers Should Do Now

Before 11 September 2026

Determine whether your products are placed on the EU market and confirm your role as manufacturer, importer, or distributor. Identify your coordinating CSIRT and register on the ENISA Single Reporting Platform. Establish a named point of contact and an on-call rota capable of meeting a 24-hour clock. Draft submission templates for the 24-hour, 72-hour, and 14-day stages. Define the internal decision procedure for determining whether a vulnerability is actively exploited. Rehearse the process.

Between September 2026 and December 2027

Generate SBOMs automatically in your build pipeline in SPDX or CycloneDX format. Connect SBOM data to continuous vulnerability monitoring. Run a gap analysis against Annex I essential requirements. Classify your products and determine your conformity assessment route. Engage a notified body if you produce class II products. Define support periods by product family, minimum five years as a rule, and make the end date visible at the point of purchase. Push CRA requirements into supplier contracts covering SBOM provision, patching commitments, and vulnerability notification. Prepare technical documentation and the EU declaration of conformity.

Ongoing

Maintain the SBOM as products change. Monitor for end-of-life dependencies that cannot be patched within your declared support period. Track harmonised standards as they are published, since compliance with a harmonised standard creates a presumption of conformity.

FAQ

What is the Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847, an EU law introducing mandatory cybersecurity requirements for products with digital elements placed on the EU market. It covers secure design, vulnerability handling, security updates, software bills of materials, technical documentation, and mandatory incident reporting. It entered into force on 10 December 2024 and applies fully from 11 December 2027.

Does the Cyber Resilience Act apply to UK companies?

Yes, where a UK company places a product with digital elements on the EU market. Territorial scope follows market placement, not establishment. Brexit does not remove UK products from EU market rules. UK companies selling software or connected hardware to EU customers are manufacturers under the CRA.

When will the Cyber Resilience Act be implemented?

It is already in force. Article 14 reporting obligations bind from 11 September 2026. The full set of essential requirements, technical documentation, CE marking, conformity assessment, and SBOM obligations apply from 11 December 2027.

What does CRA stand for in cybersecurity?

CRA stands for Cyber Resilience Act, Regulation (EU) 2024/2847. It should not be confused with other uses of the abbreviation, including the Community Reinvestment Act in US banking or Cost of Revenue Analysis in finance.

Is there a UK Cyber Resilience Act?

No. The UK has not enacted a domestic equivalent. The Cyber Security and Resilience Bill, introduced in November 2025, updates the UK NIS Regulations for operators of essential services and is the analogue to NIS2, not the CRA. The UK’s product security regime is the PSTI Act 2022, which covers consumer connectable products with three baseline requirements and is significantly narrower than the CRA.

Does PSTI compliance mean we are CRA compliant?

No. PSTI requires no universal default passwords, a vulnerability disclosure policy, and transparency about update periods, and applies only to consumer connectable products. The CRA imposes comprehensive requirements across secure development, vulnerability management, SBOM, technical documentation, conformity assessment, and support periods, across all products with digital elements. PSTI compliance is a small subset of CRA compliance.

What products does the Cyber Resilience Act cover?

Any product with digital elements placed on the EU market, meaning any software or hardware product whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. This covers desktop and mobile applications, operating systems, connected devices, industrial control systems, and remote data processing solutions integral to a product. Certain sectors with existing regimes are excluded, including medical devices, motor vehicles, and civil aviation products.

Does the CRA apply to open source software?

Open source developed and supplied outside the course of a commercial activity is outside scope. Open source monetised, supported commercially, or integrated into a commercial product is within scope, and the manufacturer of the final product is responsible for the open source components it ships. The CRA also creates a lighter-touch open source software steward category for foundations sustaining open source development without direct monetisation.

What are the penalties for CRA non-compliance?

Up to €15 million or 2.5% of worldwide annual turnover for breach of the Annex I essential requirements, up to €10 million or 2% for other manufacturer obligations, and up to €5 million or 1% for supplying incorrect or misleading information to authorities. Market surveillance authorities can also require withdrawal or recall of products from the EU market.

Do we need to comply with both the CRA and the EU AI Act?

Where a product with digital elements incorporates an AI system, both may apply. The AI Act’s Article 15 requires high-risk AI systems to achieve appropriate accuracy, robustness, and cybersecurity. The CRA imposes horizontal cybersecurity requirements on the product as a whole. The two operate at different layers and both must be satisfied. The CRA’s SBOM obligation covers AI components alongside all other components.

Does the CRA apply to SaaS?

It applies to remote data processing solutions where the data processing is integral to the product and its absence would prevent the product from performing its functions. Pure cloud services without a connected product element are generally addressed by NIS2 rather than the CRA. The boundary requires case-by-case assessment based on how the service is delivered and whether it forms part of a product with digital elements.

Yuliia Habriiel

Founder, CLO LLB, IAPP AIGP
Fact Checked & Editorial Guidelines
Reviewed by: Subject Matter Experts