If your organisation develops, commissions or owns an app or other software product that is available in the EU, the Cyber Resilience Act is something you should now be thinking about.
The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for hardware and software products made available on the EU market.
The Act has been in force since December 2024, but its requirements are being introduced in stages. The next significant date is 11 September 2026, when vulnerability and security incident reporting obligations start to apply. The wider requirements of the Act then apply from 11 December 2027.
For businesses planning digital products today, particularly products expected to remain in use for several years, that makes the CRA increasingly relevant during the development process.
What is the Cyber Resilience Act?
The principle behind the CRA is fairly simple.
Digital products should be designed with appropriate cybersecurity measures, maintained securely and supported when vulnerabilities are discovered.
The legislation applies to what it calls "products with digital elements". This includes hardware and software products whose intended or reasonably foreseeable use involves a direct or indirect connection to a device or network.
That can include:
Mobile applications
Desktop software
Connected devices
Software components
Operating systems
Smart products
Certain server or cloud functionality required for a product to operate
That does not mean every website or online service automatically falls under the CRA.
The key question is whether the software forms part of a product with digital elements that is made available on the EU market. Remote processing can also form part of that product where the product depends on it to perform its intended function.
Whether a particular application, platform or service falls within scope therefore depends on how it works and how it is supplied.
What changes on 11 September 2026?
This is the first date likely to have a direct operational impact on many organisations.
From 11 September 2026, manufacturers of products covered by the CRA must report certain actively exploited vulnerabilities and severe security incidents.
The reporting timescales are relatively short. An early warning may need to be submitted within 24 hours of becoming aware of the issue, followed by a more detailed notification within 72 hours.
That creates a practical question for organisations operating digital products:
If a serious vulnerability was discovered in your application tomorrow, would you know who was responsible for identifying it, assessing it, escalating it and reporting it?
For organisations working with external development partners, that answer is not always obvious.
What changes in December 2027?
The wider requirements of the Cyber Resilience Act become applicable on 11 December 2027.
At that point, cybersecurity becomes a more formal part of the complete product lifecycle.
Manufacturers will need to consider cybersecurity risks during design and development, maintain appropriate technical documentation and complete the required conformity assessment before placing a product on the market.
Requirements can include areas such as:
Secure configuration
Access control
Protection of data
Vulnerability management
Security updates
Technical documentation
A defined support period
Manufacturers will also be expected to manage vulnerabilities throughout the stated support period for the product.
For many common software products, including mobile applications, this does not necessarily mean an expensive external certification process. Manufacturer self-assessment can be sufficient for many products, while higher-risk categories can have stricter assessment requirements.
Who is actually responsible?
This is one of the most relevant parts of the CRA for organisations commissioning software.
It would be easy to assume that if an external development company builds your application, they automatically carry the regulatory responsibility.
That is not necessarily the case.
Under the CRA, a manufacturer can include an organisation that develops a product itself, but also one that has the product designed or developed and markets it under its own name or trademark.
Consider a typical project.
A business commissions an agency to design and build a digital product. The finished application is then released to customers under the client's brand.
Depending on the circumstances, the client may be considered the manufacturer for the purposes of the CRA, even though another company actually developed the software.
That makes the responsibilities between client and development partner worth defining clearly.
Who monitors vulnerabilities?
Who maintains third-party libraries and dependencies?
Who provides security updates?
Who investigates a reported vulnerability?
Who handles incident reporting?
Who maintains the documentation needed to demonstrate compliance?
These questions increasingly need to be answered during product planning rather than after launch.
What about existing digital products?
Products placed on the EU market before 11 December 2027 will not automatically need to meet every wider CRA requirement.
However, the position can change if the product undergoes a substantial modification after that date.
The September 2026 reporting obligations can also apply to products already available on the EU market before the wider requirements take effect.
So organisations operating existing products should not simply assume that the CRA is only relevant to software launched after 2027.
Does this matter to UK businesses?
Potentially, yes.
The CRA is an EU regulation, but the key question is whether an in-scope product is being made available on the EU market.
A UK company that develops, commissions or supplies digital products for customers or users in the EU may therefore need to consider the Act.
For businesses with users or customers across Europe, it is worth establishing this early.
What should businesses developing digital products do now?
There is still time before the wider requirements apply, but products being commissioned today may easily remain operational beyond December 2027.
A few questions are worth addressing during project planning:
Security should be part of the product conversation
For organisations commissioning digital products, one of the biggest effects of the Cyber Resilience Act is likely to be how the lifetime of a product is considered.
Launching the application is not the end of the conversation.
Who maintains it, how vulnerabilities are handled, how long security updates are provided and where responsibility sits all need to be understood.
At Harmony, we already consider security, technology choices, ongoing support and maintainability when planning digital projects with our clients. As the Cyber Resilience Act starts to take effect, those conversations will become increasingly relevant for products intended for the European market.
If you are planning a new application or digital product and are unsure how the CRA could affect the way it should be designed, developed or supported, speak to us about your project.
This article provides general information about the Cyber Resilience Act and should not be considered legal or regulatory advice.
-
Kieran Sawyer has over 15 years of experience helping clients shape innovative digital and immersive solutions. He leads on strategy, combining commercial insight with creative technology to deliver impactful experiences.
Profile -
Date
Sep 1, 2026
-
Reading time
8 min read
-
Services
Augmented Reality Development
Virtual Reality Development
Web systems
Immersive Technologies
WebXR
Max 500 characters (0/500)