
Cyber Resilience Act - September 2026
What does the Cyber Resilience Act mean for software development companies and, more importantly, for our customers? It brings its first obligations starting 11 September 2026.
If you are operating in EU markets, you might have heard about the Cyber Resilience Act (CRA) - Regulation (EU) 2024/2847.
Products with digital elements
The CRA eliminates the historical liability shield of software licensing, treating digital code with the exact same rigorous safety and conformity standards applied to physical products. So-called products with digital elements are software or hardware products (i.e., they do not have to be physical), including the remote data processing solutions required for that product to function (aka backend).
The regulation is built upon two immutable pillars: security by design, requiring products to be hardened before they reach the market, and security over time, mandating the continuous handling of vulnerabilities. The CRA fully applies from 11 December 2027.
Obligations from 11 September 2026
The reporting obligations concerning actively exploited vulnerabilities and severe incidents that impact the security of products with digital elements apply from 11 September 2026. Failure to comply could result in fines of up to €15 million or 2.5 percent of the offender's total worldwide annual turnover for the preceding financial year.
Where to report depends on your country. For Slovakia, you can find more information about the reporting procedure on the website of the Národný bezpečnostný úrad (National Security Authority).
For our customers
As a software development company, we are not directly liable from a CRA perspective (in most cases). However, because we also help our customers operate their systems, we strongly suggest establishing a reliable communication channel so that any (though unlikely ;-)) incidents are not lost in someone's email inbox. Unless the customer has its own ticketing system, the simplest solution is to use an email group where there is no single point of failure.
Hopefully, we won't have to handle such a situation in the future, but especially in the era of AI agents, one should always be prepared.