Cybersecurity requirements depend on product functions and the applicable regime. CRA reporting duties for manufacturers of in-scope products started on 11 September 2026; the main CRA obligations apply from 11 December 2027. RED Delegated Regulation (EU) 2022/30 remains relevant until its repeal takes effect on 11 December 2027. Its repeal does not remove the rest of the RED.
How we support this
We scope the requirements, coordinate firmware and documentation questions with the manufacturer and identify specialist assessment needs. Security testing is separately agreed where required.
A cybersecurity document checklist is not equivalent to penetration testing or technical security validation.
Reviewed: 17 September 2026. This page is reviewed manually. It does not track legal changes automatically.
