Skip to content
Search our site  
    Ask a Nemko Expert

    Real Compliance Questions. Straight Answers From Nemko Experts.

    Pepijn Van Der Laan
    THIS WEEK'S QUESTION - SEPTEMBER 17, 2026

    The EU Cyber Resilience Act is now taking effect. What do I need to do now? 

    Answer from Pepijn Van Der Laan, Global Technical Director of Nemko Digital:

    The EU Cyber Resilience Act (CRA) introduces cybersecurity requirements for hardware and software products with digital elements sold in the EU.

    As of September 11, 2026, manufacturers must report certain actively exploited vulnerabilities and severe security incidents. Most remaining CRA requirements become mandatory on December 11, 2027.

    Manufacturers should start preparing now by reviewing product cybersecurity, vulnerability-management processes, technical documentation, SBOMs, and the security of third-party components and software in their supply chain. The CRA specifically requires manufacturers integrating third-party components to exercise cybersecurity due diligence.

    Need help understanding what the CRA means for your product?
    Explore Nemko’s CRA Compliance Implementation Roadmap:
    https://digital.nemko.com/cra-compliance-implementation 


    Your Question Could Be Our Next Expert Answer

    Every product, market, and compliance journey is different. That's why we're answering the questions manufacturers are asking.

    Have a compliance question?