CRA: Connected Products, Security Updates and Reporting Scenarios
Cyber Resilience Act assessment considers digital functions, manufacturer roles and the product lifecycle. Reporting duties starting in 2026 must be distinguished from the main requirements applying in 2027.
Questions for your situation
Can all CRA work wait until 2027?
The main requirements apply from 11 December 2027, but relevant manufacturer reporting duties began on 11 September 2026. Review processes for actively exploited vulnerabilities and severe product-security incidents separately. Define scope, responsible teams and classification now; the general transition date does not postpone those reporting duties.
Is a commercial device excluded because it contains open-source components?
Open-source components do not remove every obligation from the commercial finished product. Assess manufacturer, contributor and open-source steward roles separately. Connect component inventories, versions and vulnerability tracking to maintenance. Do not assign all projects the same legal role or every commercial product an automatic exemption.
What should be reviewed when another company operates the product's cloud function?
Determine the remote processing function's relationship to the product and CRA scope; independent cloud services do not all receive the same treatment. Explain dependencies for authentication, updates, incidents and service termination. Contracts should support necessary security controls and change notifications.
Does one penetration test complete CRA preparation?
Testing provides evidence for a defined version and scope. Secure design, dependencies, vulnerability handling and update delivery require continuing arrangements. Connect risk assessment to tests and track remediation. A favourable report does not establish conformity of future versions or the entire lifecycle automatically.
Can reporting of active exploitation wait until a patch is ready?
Record when the issue became known and assess reporting scope first. Early warning and notification are not one step deferred until patch completion; review relevant 24- and 72-hour stages. Coordinate remediation, official reporting and user information. Final-report conditions for vulnerabilities and severe incidents differ and require separate review.
Can adding a connection feature later affect the file?
Assess changes to attack surface, authorisation, data flows and classification. Existing risk analysis and tests may not represent the new function. Update necessary documentation, assessment and user information. A software-only change is not automatically insignificant for conformity.
Share the subject, organisation or product, target market, current evidence and target date. The team can then separate consultancy, official fees, independent evaluation and realistic timing.