Wire · regulatory
The EU Cyber Resilience Act: Preparing for the New Reporting Obligations for “Products ...
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 22 September 2026 · Fusion42 review
The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements and a new three-stage reporting process for actively exploited vulnerabilities and severe incidents for all digital products sold in the EU, effective from 11 September 2026. The CRA applies globally to manufacturers, importers, and distributors of in-scope hardware and software products with digital elements connecting to networks, excluding pure SaaS unless essential to product function.
This Wire brief sits within Fusion42's coverage of Enterprise Software, and 8 sources have reported it between 4 Sep 2026 and 23 Sep 2026.
◆ ◆ The Wire takeaway
Your product compliance now requires mandatory vulnerability and incident reporting to EU authorities starting this month. If you sell connected hardware or software in Europe, you must align your security processes fast or face market exclusion.
◆ Coverage
8 sources · first reported 4 Sep 2026 · latest 23 Sep 2026
◆ Related on Wire
◆ Topics