Published on September 1, 2026 · The mitza.es team

Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), entered into force on December 10, 2024, with a 36-month transition period before most of its obligations become fully applicable. That transition period doesn't mean nothing happens until the end: it activates specific obligations in phases, and the next phase lands on September 11, 2026, when notification of vulnerabilities and security incidents becomes mandatory.
What exactly happens on September 11, 2026
From that date, manufacturers of products with digital elements are required to report to the competent authorities any actively exploited vulnerability and any severe incident affecting their products. This obligation isn't limited to products launched after September — it also applies to products already on the market. It's the date that confirms the CRA is no longer a "some day" regulation, but an active operational obligation.
It's the second relevant milestone on the regulation's timeline. The first, June 11, 2026, activated the obligations for conformity assessment bodies. The next major date, December 11, 2027, will be full compliance: from then on, no product with digital elements can be marketed in the EU without CE marking under the CRA.
Who's actually affected (and why it's not just "the big players")
The regulation targets manufacturers, importers and distributors of products with digital elements that connect, directly or indirectly, to another device or a network. That includes IoT devices, applications and software products, and connected industrial systems. It's easy to read "manufacturer" and picture a hardware multinational, but the real scope is much broader: any company that develops or distributes an app, a SaaS service, a connected device, or a system with software components falls under the regulation — including plenty of SMEs that have never thought of themselves as "technology manufacturers".
If your company develops software that's sold or distributed, or manufactures or sells connected hardware (anything from an IP camera to a management system for a specific industry), now is the time to check where you sit in that chain and which obligations apply to your role.
The notification deadline: 24 hours, then 72 hours
The CRA sets out a tiered notification scheme with very tight deadlines:
- Initial notification within 24 hours of the manufacturer becoming aware of an actively exploited vulnerability or a severe incident affecting its product.
- Complete notification within 72 hours, including a detailed description of the incident or vulnerability, the exploitation method, corrective measures already taken, and recommendations for affected users.
Meeting these deadlines requires having an internal detection and escalation process already in place before the incident happens. Improvising a notification protocol during the first 24 hours of an active vulnerability is the worst possible time to start defining one.
The CRA's underlying obligations, beyond September
Incident notification is just one piece. The regulation requires, on an ongoing basis throughout the product's lifecycle:
- Security by design, from the development phase through product withdrawal.
- Vulnerability management across the entire product lifecycle, not just at launch.
- Documented risk assessment, retained for a minimum of 10 years.
- Deployment of security updates when vulnerabilities are detected.
- Meeting the 24-hour and 72-hour notification deadlines described above.
CRA and NIS2: complementary regulations, not the same thing
It's easy to confuse the CRA with NIS2, but they regulate different, complementary things. NIS2 requires organizations to manage the cybersecurity risk of their own systems and processes: risk analysis, incident management, business continuity. The CRA, on the other hand, regulates the security of the product itself: the software or device being manufactured, sold or distributed has to meet minimum security requirements, and its manufacturer has to manage vulnerabilities that appear after the sale. A company can be subject to both at once: as an organization (NIS2) and as a manufacturer or distributor of a connected product (CRA).
Just as with NIS2, the CRA is a directly applicable EU regulation: it doesn't need a specific Spanish law transposing it for the obligations to exist and become enforceable on the dates set out in the regulation itself.
Where to start if you're not sure it applies to you
- Identify whether your company develops, manufactures, imports or distributes any connected product: software, an app, a SaaS service, an IoT device or a connected system.
- Check whether you already have an internal channel and process to detect and escalate vulnerabilities in your products.
- Assess whether you could meet the 24-hour initial notification deadline if an active vulnerability were detected today.
- Start documenting the risk assessment of your products, keeping in mind the obligation to retain it for 10 years.
- If you also manage data and internal processes subject to NIS2, review both frameworks together — they share much of the same risk-management logic.
Reducing risk while you get up to speed
Complying with the CRA isn't just a paperwork exercise: it requires real detection and response processes that also protect you against incidents like ransomware, which is becoming more frequent against companies of every size in Spain. If you also want to cover the financial impact of an incident while you finish adapting your processes, it may be worth checking how much a cyber insurance policy for SMEs costs today. And if you're not sure where to start assessing your products and processes, a tailored audit gives you a clear starting point before notification deadlines become a real problem.