Dublin: From the smart doorbell on a suburban porch to the industrial sensors humming inside a factory, almost every connected product sold in Europe is about to come with new legal strings attached. The Cyber Resilience Act, the bloc’s sweeping attempt to make hardware and software secure by design, is moving from abstract ambition into concrete obligation, and the next set of deadlines arrives this year.
The law rests on a simple premise that has taken a remarkably long time to become rule: products with digital elements should not ship riddled with avoidable holes, and when serious flaws emerge, someone should have to say so. For years manufacturers faced no consistent duty to patch the gadgets they sold or to disclose when those gadgets were being actively exploited by attackers. The Act changes that across the single market, covering everything from consumer electronics to the software libraries woven invisibly into countless other systems.
The immediate milestone falls in the autumn. From the middle of September, makers of connected products must report serious incidents and actively exploited vulnerabilities through a single European platform, with an early warning due within twenty-four hours and a fuller account within seventy-two. For vulnerabilities that are being exploited in the wild, a final report follows within fourteen days of a fix becoming available. The compressed timetable is meant to give defenders across the continent a fighting chance to react before a flaw spreads.
Ahead of that, from the middle of June, the machinery for certifying compliance begins to take shape, as rules on appointing and notifying the bodies that will assess products come into effect. Authorities are racing to ensure enough of these assessment bodies exist by the end of the year, conscious that a shortage could clog the pipeline and leave manufacturers unable to get products to market once the full requirements bite.
That full weight lands at the end of 2027, when products will need to carry the familiar conformity marking backed by genuine security assessment. Between now and then companies face a steep climb: cataloguing the software inside their devices, building processes to handle vulnerability disclosures, and committing to provide security updates for a defined support period rather than abandoning products the moment the next model ships.
The open-source world has watched the law’s evolution with particular anxiety. Much of modern software is built atop freely shared components maintained by volunteers, and early drafts raised fears that unpaid contributors might be saddled with corporate-style liability. Later revisions carved out protections for non-commercial development, but the broader question of how responsibility flows along a supply chain of reused code remains a live one for developers in Dublin’s tech cluster and far beyond.
For manufacturers the message is that security is no longer optional or purely reputational; it is a condition of selling into the world’s largest single market. Whether the Act ultimately hardens Europe’s digital ecosystem or simply adds paperwork will depend on how rigorously the reporting duties are enforced once the platform goes live, and on whether smaller firms can shoulder the compliance burden without being squeezed out.




