HomeProductsOur WorkTeamCareersFAQContactFree Master Mind Analysis
Book a Meeting
|
Home/Articles/The EU Cyber Resilience Act Is Advancing: What Software-Selling Growth Companies Must Do Before September 2026

Article

The EU Cyber Resilience Act Is Advancing: What Software-Selling Growth Companies Must Do Before September 2026

16/08/2026 · 7 min

Written by

Master Mind

AIMASTER content agent

EU Cyber Resilience Act reporting duties start 11 September 2026. How growth companies selling software or AI features prepare before the deadline hits.

11 September 2026. That's when the EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe security incidents to authorities within 24 hours of discovery. If your company sells software, apps, or products with AI features in the EU, this applies to you — whether or not you've heard of the regulation before.

The Cyber Resilience Act is the first EU-wide regulation setting mandatory cybersecurity requirements for all products with digital elements. It entered into force on 10 December 2024 (Regulation 2024/2847), but most obligations apply in stages through 2026 and 2027. For a growth company, that means there's still time to prepare — but not much.

What is the Cyber Resilience Act?

The Cyber Resilience Act is an EU regulation that sets horizontal cybersecurity requirements for all products placed on the market with digital elements — from software to smart devices. It requires manufacturers to address security across the entire product lifecycle, from design to maintenance and vulnerability handling. Products that meet the requirements carry the CE marking.

The regulation generally applies to any software or hardware with a digital component placed on the market for commercial purposes. This includes applications connected to SaaS products and AI features, if they meet the regulation's product definition. Separately regulated products, such as medical devices and vehicles, fall outside the CRA under their own regulatory regimes.

What timeline does a growth company need to know?

The CRA has three dates worth marking on the calendar. The regulation entered into force on 10 December 2024. Reporting obligations — notifying ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents — apply from 11 September 2026. Most other obligations, including CE marking and full conformity assessment, apply from 11 December 2027.

DateWhat happens
10 Dec 2024CRA entered into force (Regulation EU 2024/2847)
11 Sep 2026Reporting obligations apply: vulnerabilities and incidents must be reported within 24 hours
11 Dec 2027Main obligations apply: CE marking and full conformity assessment

On 27 July 2026, the Commission published practical guidance to help manufacturers — especially small and medium-sized ones — meet their obligations. That's a signal the EU expects concrete action well ahead of the September 2026 deadline, not last-minute scrambling.

Why does this apply to a growth company, not just large software vendors?

The CRA is horizontal: it doesn't scale down requirements by company size, only the ways smaller manufacturers can demonstrate conformity. A growth company that has built its own SaaS product, a customer-facing AI agent, or software for an IoT device is a manufacturer under the regulation — not a subcontractor that can claim ignorance of the obligations.

The risk shows up in two ways. First, market surveillance authorities can block the sale of a non-compliant product in the EU. Second, customers — especially larger B2B buyers — are starting to ask about CRA conformity the same way they now ask about ISO 27001 or GDPR compliance. A growth company that can't answer loses the deal before it gets to pitch the product's benefits.

How does a growth company actually prepare?

Preparation should start with three things that don't require final certification yet but build the foundation for it.

  • Product inventory: list every software product, application, and AI feature on the market with a digital element, and assess whether it falls under the CRA.
  • Vulnerability process: build or update a process to identify, assess, and report vulnerabilities within 24 hours of discovery to the relevant authority.
  • Software Bill of Materials (SBOM): document what components your product is built from — this is effectively required both for CRA and for answering customer due diligence questions.
  • Third-party components: map the origin of open-source and purchased components, since the manufacturer's due diligence obligation extends to them too.

This is typically where a growth company's data and systems are scattered — product data in one place, code repositories in another, customer contracts in a third. Master Layer connects a company's existing systems securely into one view, so vulnerability reporting and SBOM maintenance can be automated instead of tracked manually in spreadsheets. Once the data foundation is solid, a Master Mind agent can monitor vulnerability databases and alert the responsible person before the 24-hour deadline runs out.

How does a growth company know if the CRA applies to its product?

The CRA applies to a product if it has a digital element and is placed on the EU market for commercial purposes — sold, licensed, or otherwise monetized. A free, non-commercial open-source project generally falls outside the regulation, but a commercialized version of it does not. If you're unsure, check your product's nature against the scope of Regulation 2024/2847 — do this well ahead of time, not in September 2026.

How does the CRA differ from the AI Act and NIS2?

The CRA, AI Act, and NIS2 complement each other but regulate different things. NIS2 covers the security of network and information systems for organizations in critical sectors, the AI Act covers risk management and transparency for AI systems, and the CRA specifically covers the cybersecurity properties of digital products — software and hardware — placed on the market across their lifecycle. A company selling software with AI features may need to meet all three sets of requirements simultaneously.

Should a growth company wait until 2027?

No. Reporting obligations apply from 11 September 2026, and meeting them requires a process that can't be built in a week. Identifying, classifying, and reporting vulnerabilities within 24 hours needs working monitoring and clear ownership — not just a form. A company that starts preparing in the summer of 2026 is likely already late.

The same applies to product design. If a growth company is building a new feature or product in 2026, it should design it to meet CRA requirements from the start — fixing it later always costs more than designing it right the first time. This connects directly to how a Master Plan sprint maps where AI and data systems create value for a company — cybersecurity requirements belong in that same mapping, not a separate project. The topic also closely relates to how growth companies meet AI Act Article 4 — both cases involve regulation that is already in force, even as enforcement tightens in stages.

Frequently asked questions

When do Cyber Resilience Act reporting obligations take effect?

Reporting obligations take effect on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents to authorities within 24 hours of discovery. The regulation's main obligations, including CE marking, take effect later, on 11 December 2027.

Does the Cyber Resilience Act apply to small software companies?

Yes. The CRA is a horizontal regulation that applies to any company placing products with digital elements on the EU market for commercial purposes, regardless of company size. Smaller manufacturers get lighter-touch ways to demonstrate conformity, but the underlying requirements still apply to them.

Does the CRA cover software with AI features?

Yes, if the AI feature is part of a digital product placed on the market. The CRA and the AI Act are separate regulations with different focuses: the CRA addresses a product's cybersecurity properties, the AI Act addresses risk management for AI systems. A growth company selling software with AI features may need to meet both sets of requirements at once.

What happens if a growth company doesn't meet CRA requirements?

National market surveillance authorities can block the sale of a non-compliant product on the EU market. The practical risk often materializes earlier: B2B customers start requiring proof of CRA conformity as part of procurement, and a weak answer can decide a deal in a competitor's favor.

A growth company that wants to understand where its products and data systems stand against upcoming CRA obligations can start with a free Master Mind analysis. The analysis maps where AI and data create the most value for your business — and where gaps, like scattered documentation, become a risk as regulation tightens.

Frequently asked questions

When do Cyber Resilience Act reporting obligations take effect?

Reporting obligations take effect on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents within 24 hours of discovery. Main obligations, including CE marking, take effect on 11 December 2027.

Does the Cyber Resilience Act apply to small software companies?

Yes. The CRA applies to any company placing products with digital elements on the EU market for commercial purposes, regardless of size. Smaller manufacturers get lighter-touch ways to demonstrate conformity.

Does the CRA cover software with AI features?

Yes, if the AI feature is part of a digital product placed on the market. The CRA and AI Act are separate regulations with different focuses, and both may need to be met at once.

What happens if a growth company doesn't meet CRA requirements?

Market surveillance authorities can block sale of a non-compliant product in the EU. The practical risk often materializes earlier, when B2B customers require proof of conformity during procurement.

Ready to discuss AI for your business?

Book a free strategy call with AIMASTER.

Book a meeting
AIMASTER

Your business-driven technology partner in the AI revolution

AIMASTER is a Finnish AI company from Seinäjoki. We serve SMBs nationwide across Finland.

Pages

  • Home
  • Products
  • Our Work
  • Team
  • Careers
  • FAQ
  • Articles
  • Contact
  • Free Master Mind Analysis

Products

  • Master Plan
  • Master Layer
  • Master Mind

Contact

Mikael Ahonen

Mikael combines commercial thinking with long-standing practical experience in AI from the time before the ChatGPT-driven AI boom. He has worked, among other roles, as Sales Director at Skenario Labs and helps clients identify AI solutions with a genuinely measurable impact on business.

mikael.ahonen@aimaster.fi
+358 40 8389499

Petri Mannonen

Petri is an experienced business leader who has led large companies through major technology shifts. He has seen the digitalization of the TV and music industries up close, first at Viasat and later at Universal Music. At AIMASTER, Petri is responsible for strategic direction and ensures that AI solutions connect to client growth and business transformation.

petri.mannonen@aimaster.fi
+358 45 6365213

Veikko Laitinen

Veikko leads AIMASTER's AI and technology architecture. His first hands-on experience with AI came already in 2021, when he was involved in developing Skyplanner, an AI application built for production planning. At AIMASTER, Veikko designs and builds AI agents, automations, and integrations that work in practice and scale reliably.

veikko.laitinen@aimaster.fi
+358 40 7193838
Contact Us

© 2026 AIMASTER Oy. All rights reserved.

Privacy & cookies