The EU Cyber Resilience Act Is Now a Live Business Issue
The first operational obligations under the EU Cyber Resilience Act are now in effect.
Reporting requirements have applied since 11 September 2026, while the Act’s broader product-security obligations will apply from 11 December 2027.
That later deadline should not encourage affected businesses to postpone preparation. Cybersecurity processes, technical documentation and product-support arrangements cannot always be assembled retrospectively.
What types of business could be affected?
The Cyber Resilience Act covers products with digital elements placed on the EU market.
Depending on the product and the business’s role, this can include:
- Connected equipment and sensors
- Network and security devices
- Smart consumer products
- Commercial software
- Mobile and desktop applications
- Software supplied with physical machinery
- Remote processing supporting a connected product
- Products incorporating open-source components
The exact legal position depends on the product and whether the business is acting as a manufacturer, developer, importer or distributor.
It is about the complete product lifecycle
The Act is not simply a requirement to run a vulnerability scan before launch.
Affected businesses may need processes covering:
- Product cybersecurity risk assessment
- Secure design and development
- Vulnerability monitoring
- Security updates
- Support periods
- Incident and vulnerability reporting
- Technical documentation
- Open-source component management
- Changes made after release
- Communication with customers and authorities
The European Commission’s guidance also discusses what constitutes a substantial product modification and how remote services can fall within scope.
Why SMEs should begin with a scope assessment
Many smaller businesses do not describe themselves as software manufacturers.
They may nevertheless commission an app, sell equipment containing connected components or provide software that forms part of a customer’s operational system.
The first useful step is therefore to establish:
- What digital products the business supplies
- Where those products are sold
- Who designed and maintains the software
- Which third-party components are included
- How vulnerabilities are currently reported
- How long security support is promised
- Who is responsible when an incident occurs
This creates a factual foundation for technical and legal advice.
Cyber Resilience Act Readiness Assessment
Joe Hunter IT provides practical IT, cybersecurity and software consultancy for businesses in Ireland and the UK.
A technical readiness assessment can help identify:
- Products and services that require closer examination
- Existing security and support processes
- Missing asset and software-component records
- Vulnerability-reporting responsibilities
- Technical documentation gaps
- Update and support arrangements
- Actions requiring specialist legal or compliance advice
The assessment does not replace formal legal interpretation. It helps the business understand its technology, responsibilities and practical gaps before seeking that interpretation.
Do not wait until 2027
Businesses that develop, import or sell products containing software should determine whether the Cyber Resilience Act applies before the main deadline becomes urgent.
Contact Joe Hunter IT at joe@joehunterit.com or visit joehunterit.com to arrange a Cyber Resilience Act technical readiness review.
