The Cyber Resilience Act: what it means for your business

The Cyber Resilience Act
By Stephen Cook

From 11th September 2026, a new EU regulation starts changing how connected products and software are built, sold and supported – and UK businesses trading into Europe are firmly in scope [1] [2]. Here is what the Cyber Resilience Act actually requires, why it matters beyond the compliance paperwork, and how Espria helps clients meet it. 

What is the Cyber Resilience Act? 

The Cyber Resilience Act (CRA) is an EU regulation – Regulation (EU) 2024/2847 – that sets mandatory cybersecurity requirements for “products with digital elements.” In practice, this covers hardware and software that can connect to a device or network: IoT devices, routers and connected industrial equipment, standalone software and firmware, and remote data processing services such as cloud applications, web services and mobile apps. [1] 

It applies to manufacturers, importers and distributors of these products, and it applies regardless of where the company is based. If your product or service is placed on the EU market, or put into service in the EU, the CRA applies – UK-based businesses are not exempt simply because the UK has left the EU. [1] [2] 

A small number of product categories are excluded because they are already regulated elsewhere, including medical devices, automotive components and marine equipment, along with non-commercial open-source software. [1] 

Why it matters now 

Two dates matter most: 

  • 11th September 2026 – vulnerability and incident reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents to their national Computer Security Incident Response Team (CSIRT) and to ENISA, on a strict three-stage timeline: an early warning within 24 hours, a detailed notification within 72 hours, and a final report. [1] [2]
  • 11th December 2027 – full compliance is required, covering secure-by-design and secure-by-default engineering, Software Bills of Materials (SBOMs), technical documentation and CE marking for any new product placed on the EU market. [1] [3] 

The reporting obligation reaches products already on the market today, so the infrastructure to detect and report vulnerabilities needs to be in place well before September 2026 – not built in response to the first incident. [1] [2]

The impact on Espria clients – especially those operating in Europe 

Many Espria clients develop or resell software, connected devices or cloud-based services, or embed them in the products and platforms they sell. If any part of that portfolio reaches EU customers – directly, through a distributor, or as an OEM component in someone else’s product – the CRA applies to your business, even though it is UK-based. [2] [5] 

This sits alongside, but is separate from, the UK’s own Cyber Security and Resilience Bill, which is progressing through Parliament and will extend similar duties to UK managed service providers and digital supply chain businesses domestically. The two regimes are not the same, and businesses trading in both markets should expect to meet both sets of obligations. [7] 

For clients selling into Europe, the practical impact includes: 

  • Products cannot legally carry the CE mark, and therefore cannot be placed on the EU market, without evidence of conformity with the CRA’s security requirements. [1]
  • Distributors and importers in the EU share legal responsibility for CRA compliance, so contracts and due diligence with EU partners need to reflect this. [1] 
  • Vulnerability disclosure and incident response processes need to be fast, documented and auditable – informal or ad hoc handling will not meet the 24- and 72-hour reporting windows. [2] [3] 

The cost of getting it wrong 

The CRA carries some of the toughest penalties in EU digital regulation. The most serious breaches carry fines of up to €15 million or 2.5% of global annual turnover, whichever is higher. Other breaches of market-access and documentation obligations can attract fines of up to €10 million or 2%, and providing false or misleading information to authorities can cost up to €5 million or 1% of global turnover. Beyond the fines, non-compliant products simply cannot be sold in the EU – a direct hit to revenue and market access, not just a regulatory risk.  [6]

What compliance actually delivers 

Treated only as a compliance exercise, the CRA is a cost. Treated properly, it delivers real business value: 

  • Fewer exploitable vulnerabilities, because secure-by-design principles are built into development rather than bolted on afterwards.  [1]
  • Full visibility of software supply chains through SBOMs – knowing exactly what is inside every product, which shortens the time to respond when a new vulnerability is disclosed elsewhere in the industry.  [3]
  • Faster, more structured incident response, because the reporting workflow already exists rather than being improvised under pressure. [2] [3] 
  • A genuine competitive advantage in EU procurement and enterprise tenders, where cybersecurity due diligence is increasingly a condition of doing business. [5]
  • Less duplicated effort where clients already hold Cyber Essentials or ISO 27001 – much of that existing control environment maps directly onto CRA requirements. 

What clients need to do 

  • Map the product and service portfolio to identify which items count as “products with digital elements” and confirm which are placed on the EU market, directly or indirectly. [1] [5] 
  • Stand up vulnerability handling and incident reporting processes now, ahead of the 11 September 2026 deadline, including a clear route to the relevant CSIRT and ENISA. [2] [3] 
  • Build and maintain SBOMs for software components, and embed secure-by-design and secure-by-default practices into the development lifecycle. [1] [3] 
  • Prepare technical documentation and the right conformity assessment route for CE marking ahead of the December 2027 deadline. [1] [5] 
  • Review contracts and due diligence arrangements with EU distributors and importers, who carry shared obligations under the CRA. [1] [4] [5]

How Espria helps 

Espria Remedi8, our closed-loop automated vulnerability remediation platform, is built for exactly this challenge. Continuous vulnerability scanning through Tenable identifies exposure across the estate; automated remediation and patching through NinjaOne closes it down; and the closed-loop process leaves a documented, auditable evidence trail – the same evidence base clients need for CSIRT and ENISA reporting under the CRA. 

Alongside this, our expertise across the Microsoft stack: Azure, Microsoft 365, Dynamics 365 and Business Central – helps clients harden the environments their products and services run on, while HaloPSA-tracked service delivery gives a clear, timestamped record of remediation activity that stands up to audit. 

The CRA deadlines are fixed, and the September 2026 reporting obligation is now close.  [1]

Espria clients who want to understand their exposure, or who need help building compliant vulnerability handling and reporting processes, should speak to their account manager or contact the Espria team directly. 

Or join us at our Cyber Intelligence Briefing on 24th September at Corpus Christi College, Cambridge, we’ll look at how AI is changing vulnerability discovery, why remediation is becoming harder, and what IT leaders should prioritise next.

Register for our Cyber Intelligence Briefing here.

Sources

What’s in this article

    You may be interested in

    The Hidden Costs of Printing: How Managed Print Services Reduce Business Waste

    Introduction For many organisations, printing is viewed as a routine operational expense. Printers are purchased, toner is replaced when needed, and documents continue to flow through the business without much scrutiny. However, the true cost of printing extends far beyond paper and ink. Unmanaged print environments often create hidden expenses through inefficient device usage, excessive energy consumption, IT support demands, security risks, and employee downtime. These costs can accumulate significantly over time, impacting productivity and profitability. This is particularly relevant as businesses seek to optimise operations, reduce waste, and improve sustainability while controlling expenditure. Whether…

    Read the article

    Can Your Business Actually Recover? The Operational Resilience Question Most SMEs Cannot Answer

    Operational resilience is not a technology problem. It is a business problem. And until boards and leadership teams own it, no amount of IT investment will be enough. The Gap Between Confidence and Reality Most organisations believe they are more resilient than they are. The backups are running. The antivirus is licensed. The IT team knows what they are doing. That confidence, in our experience, rarely survives first contact with an actual incident. The question is not whether your systems are protected. The question is whether your business can keep delivering its most important services…

    Read the article

    Integration of Sophos and Microsoft for enhanced threat intelligence

    Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations

    For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…

    Read the article

    Checklist marked passed next to cracked cyber shield over network, illustrating compliance vs cyber resilience.

    Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan

    Moving from box‑ticking compliance to real‑world cyber readiness  Written by Richard Puckey  Cyber security has a confidence problem  For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure.  The problem? Cyber threats don’t operate on an annual cycle.  The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…

    Read the article

    A person sitting in a comfortable, modern living space while speaking on the phone, representing a tenant reaching out to a housing association’s customer service team. The environment conveys everyday life and the importance of accessible, responsive communication.

    How Housing Associations Can Transform Tenant Experience with Modern OmniChannel CX

    Written by Russell Hallam, CX Consultant at Espria In today’s housing landscape, tenants expect fast, seamless and personal interactions, no matter which channel they use. Phone, digital, web chat, video, email, messaging: it all needs to feel connected, consistent and effortless. But for many teams, the reality is different. Disconnected systems slow down responses, important information is buried across platforms and frontline staff shoulder the burden of manual processes.  At Espria, we’ve helped housing associations modernise their customer experience with cloud-enabled omnichannel solutions designed for efficiency, visibility and compliance. Here’s what that looks like in action. 1. RealTime CRM Integration: Context at the Exact Moment You Need It  When a tenant calls,…

    Read the article

    Silhouette pointing to a digital padlock, indicating cyber security

    Elevating Human Risk Management: A Boardroom Must for Cyber Resilience in 2026

    Written by Richard Puckey As organisations move through 2026, cybersecurity has firmly established itself as a core business risk. Regulatory scrutiny is increasing, threat actors are more capable than ever and the operational and reputational impact of cyber incidents continues to escalate. In response, businesses have invested heavily in security technology such as advanced detection platforms, zero trust architectures, AI-driven analytics and automated response capabilities. These controls are considered essential and non-negotiable. However, are they sufficient? The reality facing security leaders today is clear, the majority of material cyber incidents still involve a human decision…

    Read the article