> Cyber Resilience Act and your company’s devices
> Source: https://developit.fi/en/articles/cyber-resilience-act-and-your-companys-devices/
> Full site in machine-readable form: https://developit.fi/llms-full.txt

Information security and audits 

# The Cyber Resilience Act is here: what does it mean for your company’s devices?
7 September 2026 · 5 min read

 In short: The EU Cyber Resilience Act (CRA) sets security requirements for all networked devices and software. Manufacturers report exploited vulnerabilities to authorities starting 11 September 2026, and new products need to meet the requirements and carry CE marking starting 11 December 2027. A company buying devices gets no duties, only rights: a stated support period and free security updates throughout it.

A router, a security camera, a printer, a meeting-room display and an accounting application are all products that contain software and are connected to a network. Until now their security has depended on the manufacturer’s goodwill: some publish updates for years, some quietly stop. The Cyber Resilience Act changes this. This article walks through what the act requires from manufacturers, what it means for a company as a buyer and what is worth doing already now.

## What is the Cyber Resilience Act and when does it apply?

The Cyber Resilience Act is EU Regulation (EU) 2024/2847, which entered into force on 10 December 2024. In Finland it is complemented by the Act on the Cyber Resilience of Certain Products and on Cybersecurity Certification, in force since 1 June 2026. The authority tasks are centralised at Traficom’s National Cyber Security Centre.

The regulation applies in stages. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe security incidents to the National Cyber Security Centre and to the EU cybersecurity agency ENISA, with a first notification within 24 hours of becoming aware. From 11 December 2027 products must meet the regulation’s essential cybersecurity requirements before they can be placed on the market.

Date

What happens

10 December 2024

The regulation entered into force

1 June 2026

Finland’s complementary act entered into force

11 September 2026

Manufacturers’ duty to report exploited vulnerabilities begins

11 December 2027

New products: requirements mandatory, CE marking from now on also covers security

## Which products does it cover?

The regulation covers products with digital elements, meaning devices and software that can be connected directly or indirectly to a network. In practice that is almost everything a company buys: network equipment, cameras, smart devices, operating systems, browsers and applications, and IoT devices in industry and the office. Exceptions are products that already have their own security legislation, such as medical devices and vehicles.

Products are divided into classes by risk. Most fall into the default class, where the manufacturer assesses conformity itself. Products classified as more important, such as password managers, network management products, firewalls and operating systems, require a stricter assessment.

## What does a manufacturer have to do?

A manufacturer must design the product to be secure from the start, assess its risks, manage vulnerabilities throughout the product’s lifecycle and provide security updates free of charge for a defined support period. The support period must reflect the product’s expected lifetime, and the regulation’s starting point is at least five years unless the lifetime is clearly shorter. The end date of the support period must be told to the buyer at the time of purchase.

In addition the manufacturer must report exploited vulnerabilities and severe incidents to the authorities and inform users about them and about corrective measures. When the requirements are met, the product receives the CE marking, which from now on also speaks to security. Importers and distributors have their own duties to make sure the products they sell comply.

## What does it mean for a company that buys and uses devices?

For a company as a buyer the regulation imposes no obligations. It provides tools.

- The support period can be asked for and compared. When two routers cost the same, the one with the longer support period is the better purchase.

- Updates are free and on time. Leaving a device unpatched becomes the company’s own choice rather than the manufacturer’s neglect.

- Vulnerabilities are disclosed. The knowledge that a device is a risk arrives sooner.

The flip side is that devices acquired before 11 December 2027 are not covered by the regulation’s requirements. An old fleet that no longer receives updates remains the company’s own risk.

If a company itself manufactures or commissions software or devices that it sells to customers, it is a manufacturer in the sense of the regulation, and then the obligations apply to it. That is a separate question worth going through in good time.

## What is worth doing now?

Three things that require no new purchases.

- Bring the device register up to date. Which networked devices and software does the company have, who manufactures them and do they still receive updates.

- Get updates under control. Device management and automatic updates take care of it so that nobody has to remember.

- A procurement practice. From now on every device and software purchase includes asking for the support period and recording it in the register.

This way the company is ready when new devices start arriving with the CE marking, and it recognises the old devices that are worth replacing before they become a problem.

Test whether you can spot a scam message: the scam quiz shows with eight messages which signs you notice and which slip past.

Want to know how your company’s devices stand from a security point of view? See how our security services work, or tell us about your situation and we’ll go through the devices and updates together.

## Sources
- Traficom: New Cyber Resilience Act enters into force on 1 June, vulnerabilities to be reported to Traficom from autumn (in Finnish) https://traficom.fi/fi/uutiset/uusi-kyberkestavyyslaki-voimaan-16-haavoittuvuuksista-ilmoitettava-traficomille-syksysta-alkaen
- Finnish National Cyber Security Centre: Cyber Resilience Act (CRA) (in Finnish) https://kyberturvallisuuskeskus.fi/fi/toimintamme/saantely-ja-valvonta/kyberkestavyyssaados-cyber-resilience-act-cra
- European Commission: The Cyber Resilience Act, summary of the legislative text https://digital-strategy.ec.europa.eu/en/policies/cra-summary
- Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex https://eur-lex.europa.eu/eli/reg/2024/2847/oj

Facts checked against primary sources on 7 September 2026.

 Information security and audits

 Explore the service 

## Read next
 Information security and audits NIS2 is now law in Finland: does it apply to your company, and what does the supervisor expect? Read the article Hardware and lifecycle services Leasing or buying: how should a company acquire its computers? Read the article Websites and graphic design Accessibility requirements for business websites: does the European Accessibility Act apply to you? Read the article
