Tallinn: The Cyber Resilience Act enters its main compliance phase in December, when manufacturers placing connected products on the Union market must ensure that their devices meet essential cybersecurity requirements throughout their expected lifetime. Estimates from the Commission’s Joint Research Centre put the number of connected devices in scope at seventeen billion across the Union by the deadline, encompassing everything from smart thermostats and door locks to industrial control systems.
Regulation (EU) 2024/2847 was the bloc’s response to a fragmented landscape in which connected devices were often shipped with default passwords, abandoned without security updates after a year or two, and traded across borders with no consistent product liability for cyber failures. The regulation imposes essential cybersecurity requirements during the design and manufacturing phase, vulnerability handling obligations through the support period, and reporting duties when incidents and actively exploited vulnerabilities are discovered.
The Estonian Information System Authority has been one of the most active national supervisors in the preparation phase. Its work on a baseline taxonomy of products and risk classes has fed into the harmonised standards still being developed under the mandate to CEN and CENELEC. The first three standards are expected to be cited in the Official Journal in October, just two months before the application date, a timeline that has caused open frustration among manufacturers.
Three compliance pathways have emerged. The first applies to default-class products, which represent the majority of connected goods. Manufacturers self-assess against harmonised standards or follow a conformity assessment procedure based on internal production control. The second pathway covers important products, including network management software, password managers and identity management systems, which require either a self-assessment against harmonised standards or a third-party module. The third pathway, for critical products, mandates third-party assessment by notified bodies, with the relevant list including hardware-based security tokens, smart card readers and certain industrial automation systems.
The vulnerability handling regime is the operational core of the regulation. Manufacturers must operate a coordinated vulnerability disclosure policy, address vulnerabilities discovered during the support period, and report actively exploited vulnerabilities to the European Union Agency for Cybersecurity within twenty-four hours of awareness, with a full notification within seventy-two hours. The Agency has spent the past year building the single reporting platform that will serve as the entry point for the Union, with national CSIRTs receiving forwarded notifications.
Two policy issues are still in flux. The first concerns open-source software. The regulation contains a specific exemption for non-commercial development, but the boundary with commercial stewardship is unclear. A guidance document from the Commission, due in September, is expected to clarify the position of foundation-led projects that receive corporate sponsorship. The second issue concerns the interaction with the NIS2 incident reporting duties, which apply to operators of essential and important services. A joint reporting interface is being prepared to avoid duplicative notification burdens for entities subject to both regimes.
For manufacturers, the December deadline is approaching at the moment when the harmonised standards landscape remains in flux. For supervisors, the early months of 2027 will determine whether the regulation succeeds in raising the security floor for connected products or merely adds a layer of paperwork to a market that finds workarounds. The next six months will set the tone.




