Why Tight Deadlines Must Be Incorporated into Incident Response Processes, Supply Chains, and Product Portfolios
On September 11, 2026, the Cyber Resilience Act (CRA) will introduce mandatory reporting requirements for many companies. This will significantly impact industries like automotive, where a range of digital products—beyond just type-approved vehicle components—must comply.
1. Regulatory Framework and Effective Date
The CRA aims to harmonize cybersecurity requirements across products with digital elements, affecting hardware, software, and remote data processing solutions. Importers and distributors can also assume manufacturer obligations under specific conditions. It has a broad scope, affecting products like connected chargers and diagnostic devices, with substantive requirements effective December 11, 2027. However, reporting under Article 14 starts on September 11, 2026, necessitating existing products to be included in compliance processes.
2. Automotive: No Blanket Exemption
While the CRA offers sector-specific exemptions, it does not exempt the entire automotive industry. Software and products such as charging devices, aftermarket components, and cloud solutions may still fall under CRA regulations, emphasizing the need for a careful assessment of each product.
3. Product Analysis Prior to Risk Classification
Companies must evaluate their product portfolio to identify which products are subject to CRA requirements. A detailed product map should include current products available in the EU, the legally recognized manufacturer, and potential exemptions. Starting December 11, 2027, there will be cybersecurity requirements for design, risk assessment, and compliance.
4. Reporting Requirements and Challenges
The CRA mandates reporting on actively exploited vulnerabilities and serious incidents. The reporting timeline is strict, with a 24-hour deadline to report such vulnerabilities. There is a need for urgent assessments and rapid responses, with established processes to manage the reporting efficiently. Timely reporting is crucial to avoid penalties and ensure compliance.
5. User Notification Obligations
In tandem with reporting to authorities, manufacturers must inform affected users of vulnerabilities or incidents. Parameters for what constitutes a necessary notification will vary and depend on the potential risk to users.
6. Navigating Multiple Regulatory Frameworks
The CRA operates alongside other regulations, such as NIS 2 and GDPR, creating a complex web of compliance requirements. Companies must integrate various incident detection and reporting strategies in line with all applicable regulations.
7. Preparations Needed Before September 2026
By the deadline, companies should establish a reporting framework, clearly document their product portfolio, and define manufacturing responsibilities. Additionally, 24/7 escalation procedures and contractual obligations for suppliers should be put in place.
8. Conclusion
The upcoming deadlines present a significant challenge for automotive companies and others affected by the CRA. A proactive approach—thoroughly examining product portfolios, clarifying roles, and establishing effective reporting channels—will be essential for meeting compliance needs and mitigating risks in the event of cybersecurity incidents. Understanding these dynamics now will prove invaluable in navigating future challenges effectively.