NowCRA incident reporting applies
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements through the Single Reporting Platform. The early warning can be due within 24 hours.
European Commission · CRA reporting11 Dec 2027CRA main obligations apply
Connected-product teams need product-security requirements, vulnerability handling and lifecycle support in the roadmap well before the application date. Reporting duties have already started earlier.
European Commission · Cyber Resilience Act20 Jan 2027Machinery Regulation becomes mandatory
Machinery placed on the market before that date remains under the current Directive; new launch plans crossing the date should map the Regulation, including software, cyber-safety and digital documentation implications.
European Commission · MachineryGuidanceGPSR business guidance is available
The Commission guidance explains manufacturer, importer, distributor, responsible-person and marketplace roles, including distance-sale information and corrective-action duties. Use it to audit role assumptions and product pages.
EUR-Lex · GPSR business guidelines