Cyber Resilience Act
Cybersecurity requirements for products with digital elements under Regulation (EU) 2024/2847 — scope, the deemed manufacturer rule, SBOMs and vulnerability reporting.
Article 21 — why the CRA treats private-label sellers as manufacturers
If your brand is on a connected product, the Cyber Resilience Act makes you its manufacturer. How the rule works, the GPSR Article 8(1) parallel, substantial modification, and what to ask your factory.
CRA vulnerability reporting — the 24-hour obligation that's already live
Since 11 September 2026, manufacturers of connected products must report actively exploited vulnerabilities within 24 hours. The three deadlines, how to report, penalties, and how to set up the process.
The Cyber Resilience Act — what it means for product sellers
The EU's first cybersecurity law for everyday connected products. Which products are in scope, why own-brand sellers are the manufacturer, the key obligations, and the 2026 and 2027 deadlines.