Skip to main content

Compliance Knowledge

Product Cybersecurity, RED and the CRA

CRA reporting and main obligation dates, the role of RED Delegated Regulation (EU) 2022/30 and the limits of a document checklist.

Request a Project Quote

Services are offered exclusively to business customers.

Cybersecurity requirements depend on product functions and the applicable regime. CRA reporting duties for manufacturers of in-scope products started on 11 September 2026; the main CRA obligations apply from 11 December 2027. RED Delegated Regulation (EU) 2022/30 remains relevant until its repeal takes effect on 11 December 2027. Its repeal does not remove the rest of the RED.

How we support this

We scope the requirements, coordinate firmware and documentation questions with the manufacturer and identify specialist assessment needs. Security testing is separately agreed where required.

A cybersecurity document checklist is not equivalent to penetration testing or technical security validation.

General information only. Applicability depends on the product, intended use, economic-operator role, destination market and relevant dates. A guide does not replace a product-specific assessment.

Reviewed: 17 September 2026. This page is reviewed manually. It does not track legal changes automatically.

Back to Compliance Knowledge

Request a Product Assessment

Services are offered exclusively to business customers.

Request a Project Quote

Services are offered exclusively to business customers.

Request a Project Quote