The Cyber Resilience Act (CRA) is the EU's first horizontal cybersecurity regulation for all products with digital elements – and it affects online shops too. Regulation (EU) 2024/2847 has been in force since 10 December 2024 (EUR-Lex). From 11 September 2026 the vulnerability and incident reporting duty applies, with its tight 24-, 72- and 14-day deadlines; from 11 December 2027 the full manufacturer obligations follow, including CE marking, conformity assessment and a software bill of materials (SBOM) (European Commission). This guide explains which obligations 2026 brings for distributors, importers and manufacturers, who exactly the CRA affects in e-commerce, and how to organize patch management, security monitoring and clean technical documentation in your hosting.
What the Cyber Resilience Act Regulates
The CRA is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (EUR-Lex). As a regulation – unlike a directive – it applies directly in all 27 member states, without needing national implementation. Its scope is very broad: every hardware and software product that can establish a direct or indirect data connection to a device or network and that is made available on the EU market (European Commission). From the smart door lock and router firmware to a downloadable application, almost everything for which no more specific product rule exists falls under the CRA.
Around 90 percent of all products with digital elements fall into the default category, for which manufacturers self-assess the requirements, issue an EU declaration of conformity and provide technical documentation (European Commission). For important products (Annex III) and critical products (Annex IV) – such as password managers, firewalls or operating systems – stricter assessment routes apply, in some cases involving a notified body.
Behind the regulation lies a real economic problem: the global cost of cybercrime was already estimated at around EUR 5.5 trillion per year for 2021 (European Commission). The EU expects the CRA to reduce the cost of security incidents by EUR 180 to 290 billion annually (European Commission). In Germany, the Federal Office for Information Security (BSI) is the central body that informs manufacturers and retailers about the CRA and receives reports (BSI). For shop operators, the CRA is therefore not an abstract IT topic but part of IT security in e-commerce.
The term horizontal is decisive here: unlike sector-specific rules that only concern individual product groups, the CRA sets uniform cybersecurity requirements across all products with digital elements. For shop operators, this means the obligations are not limited to a niche but potentially cover the entire assortment of connected or software-based items. Also important is the demarcation from existing frameworks: products already subject to stricter, equivalent EU rules – such as certain medical devices or vehicles – are partly exempt, so that no double requirements arise (EUR-Lex).
Timeline: These CRA Deadlines Apply in 2026 and 2027
The CRA applies in stages. After entering into force on 10 December 2024, three dates follow that you should know (EUR-Lex):
| Date | What applies from this day | Who is affected |
|---|---|---|
| 11 June 2026 | Rules on the notification of conformity assessment bodies | Assessment bodies, notified bodies |
| 11 September 2026 | Reporting and vulnerability duty (24 h / 72 h / 14 days) | All manufacturers |
| 11 December 2027 | Full manufacturer obligations, CE marking, SBOM | Manufacturers, importers, distributors |
For everyday practice, two dates matter most: 11 September 2026 brings the duty to report actively exploited vulnerabilities and severe security incidents. 11 December 2027 makes CE marking, conformity assessment and technical documentation a precondition for offering products with digital elements on the EU market at all (European Commission).
Does the Cyber Resilience Act Affect My Online Shop?
The CRA distinguishes four roles of economic actors: manufacturer, authorized representative, importer and distributor – each with its own obligations (EUR-Lex). An online shop is rarely just one of these roles. Depending on what you sell and how you source it, you can be a distributor and an importer at the same time – or even become a manufacturer yourself.
As a distributor
You resell products with digital elements without altering them. Then you must verify that CE marking, declaration of conformity and contact details are present, and you may not offer non-compliant goods (European Commission).
As an importer
If you place goods from a non-EU manufacturer on the EU market for the first time, you face extended obligations: check the conformity assessment and technical documentation, add your own contact details, and inform the manufacturer of vulnerabilities (EUR-Lex).
As a manufacturer
If you sell own-brand devices, your own apps or self-developed software, you count as a manufacturer – with the full obligations from secure-by-design to SBOM. The same applies if you modify a product in a way that affects its security.
In concrete terms, many everyday assortments come into view: connected household appliances and smart-home tech, wearables and fitness trackers, routers and network accessories, USB gadgets with firmware, but also downloadable programs, mobile apps and software licenses. Anyone who carries such items should clarify per product group who the manufacturer is, where it is based and whether the conformity documents are available. This inventory is often the most laborious but also the most important first step – it decides which obligations apply to you at all and where action is needed.
The importer is the trickiest case in e-commerce. Anyone who sources smart devices, accessories with firmware or software directly from non-EU countries and resells them quickly becomes an importer in the sense of the CRA and must ensure that an economic actor in the EU is responsible for the obligations (European Commission). If the manufacturer is based outside the EU, it must also designate an authorized representative established in the EU (EUR-Lex). If that is missing, the product is not compliant – a pattern many shop operators already know from the GPSR product safety regulation.
Software as a service is generally not covered by the CRA, as long as it is not an integral part of a product with digital elements. In scope, however, are downloadable software, apps, firmware and connected hardware. So as soon as you offer your own applications for download or sell own-brand hardware, you should plan for the manufacturer obligations early – ideally already during programming and architecture.
Reporting and Vulnerability Duty from 11 September 2026
The first tangible CRA obligation starts on 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe security incidents (EUR-Lex). This duty applies regardless of company size or revenue, once a product with digital elements is on the EU market (BSI). Reports are filed via the central CRA Single Reporting Platform to the competent national CSIRT – in Germany the BSI or CERT-Bund – and in parallel to the EU agency ENISA (BSI).
Reporting happens in three stages with tight deadlines (BSI):
- Within 24 hours: an early warning to the CSIRT and ENISA as soon as a vulnerability is actively exploited or a severe incident occurs.
- Within 72 hours: a full report covering the type of vulnerability, the impact on the product and the corrective measures taken or planned.
- Within 14 days: a final report once a corrective or mitigating measure is available. For severe incidents, the final report is due no later than one month after the 72-hour report (EUR-Lex).
24 hours is short. Anyone who only thinks about who reports, which data is needed and who has access to the Single Reporting Platform during the first incident loses valuable time. A documented reporting and escalation process with responsibilities and templates makes sense – embedded in ongoing security monitoring. Micro and small enterprises are exempt from certain penalties for the 24-hour report, but not from the reporting duty itself (European Commission).
From 11 December 2027: Manufacturer Obligations, CE Marking and Conformity
With 11 December 2027 the CRA becomes fully applicable. From that day, products with digital elements may only reach the EU market if they meet the essential cybersecurity requirements, have undergone a conformity assessment, carry an EU declaration of conformity and bear the CE marking (European Commission). The CE marking thus signals cybersecurity for the first time, not only classic product safety.
The essential requirements include, among others, a secure default behaviour (secure by default), a design without known exploitable vulnerabilities, a managed approach to vulnerabilities across the entire support period and the provision of security updates (EUR-Lex). The manufacturer must also define and state how long it supplies a product with updates – the support period should reflect the expected usage time.
In practice, the full set of obligations demands above all robust documentation. The manufacturer must be able to demonstrate that a product meets the requirements, document how vulnerabilities are handled and provide users with understandable information for secure setup. This also includes actively communicating the support period, so that buyers know how long they can expect security updates. For own-brand and private-label offerings in the shop, this means clarifying these records with suppliers early and transferring them into your own processes – reconstructing missing documentation afterwards is only possible with considerable effort.
| Conformity route | For which products | Third-party involvement |
|---|---|---|
| Self-assessment (internal control) | Default products (around 90%) | None – manufacturer assesses itself |
| Third-party assessment by notified body | Important products (Annex III) | Notified body assesses |
| European certification | Critical products (Annex IV) | Certification scheme |
SBOM: The Software Bill of Materials Becomes Mandatory
One of the most important changes for development teams is the Software Bill of Materials (SBOM). The CRA requires manufacturers to identify and document the components of their products – among other things through a software bill of materials in a common, machine-readable format covering at least the top-level dependencies (EUR-Lex). This makes an SBOM legally binding for the first time, not just a recommendation. In practice, this means established formats such as CycloneDX or SPDX.
For shop operators who use their own extensions, this is directly relevant: a typical shop consists of dozens of dependencies – from the framework and libraries to individual plugins. Keeping an overview of these components lets you react quickly when a new vulnerability becomes known, instead of laboriously searching for where a vulnerable library is even used. This dependency management becomes a topic anyway when moving to Shopware 6.7 with Symfony and Vite – an SBOM is then not extra work but a by-product of clean IT security processes.
Fines and Market Surveillance
The CRA is backed by noticeable sanctions. Breaches of the essential requirements as well as the SBOM and vulnerability obligations can be penalized with fines of up to EUR 15 million or 2.5 percent of worldwide annual turnover – whichever is higher (EUR-Lex).
| Type of breach | Maximum fine |
|---|---|
| Essential requirements, SBOM, vulnerabilities | EUR 15 million or 2.5% of turnover |
| Other obligations (incl. importers/distributors) | EUR 10 million or 2% of turnover |
| Incorrect or misleading information to authorities | EUR 5 million or 1% of turnover |
The CRA is enforced by the national market surveillance authorities; in Germany the BSI plays a central role (BSI). They can have non-compliant products withdrawn from the market. Anyone implementing further EU requirements in parallel – such as the NIS2 cybersecurity requirements or the EU packaging regulation PPWR – can bundle compliance processes instead of treating them in isolation.
A vulnerability in a centrally used component rarely affects only one product. If reporting or update processes are missing, the effect spreads across the entire assortment. That is why a process set up cleanly once – monitoring, patch management, reporting – is more economical than patching up individual cases in an emergency.
Implementing the Cyber Resilience Act in E-Commerce
Technically, the CRA is manageable if security is understood as an ongoing operational process rather than a one-off project. For shop operators, implementation can be broken down into four building blocks that together cover both the 2026 reporting duty and the 2027 manufacturer obligations.
Patch and update management
Regular, documented installation of security updates across the entire support period – including orderly procedures such as those described in safe Shopware maintenance.
Security monitoring
Continuous monitoring for vulnerabilities and anomalies, so that an incident is detected early and the 24-hour deadline can be met – built on resilient managed hosting.
Technical documentation
Record the declaration of conformity, support period, vulnerability handling and SBOM in a structured way – as the basis for CE marking and conformity assessment.
Secure processes and automation
Define reporting and escalation paths and automate recurring checks, instead of doing every step manually.
The typical path in an existing shop: first we clarify your role – distributor, importer or manufacturer – and thereby the scope of obligations. Then we set up monitoring and update processes, build the technical documentation and define the reporting chain for an emergency. If a larger project is coming up anyway, such as a relaunch or migration, the CRA structure can be planned in directly. A professional shop combines both: a fast, modern front-end – for example with view transitions for smooth page changes – and resilient security processes in the background. In consulting we position the CRA within the rest of your compliance.
- Your role under the CRA determined: distributor, importer or manufacturer
- CE marking, declaration of conformity and contact details of the goods checked
- Authorized representative in the EU in place for non-EU manufacturers
- Reporting and escalation process for the 24/72/14 deadlines documented
- Patch and update management established across the support period
- SBOM of your own software maintained in a machine-readable format
- Access to the CRA Single Reporting Platform and responsibilities clarified
Set Up Your CRA Processes Now
The Cyber Resilience Act is applicable law, and the first hard deadline falls on 11 September 2026 (EUR-Lex). By then, reporting and vulnerability processes should be in place; by 11 December 2027, CE marking, conformity assessment and SBOM follow (European Commission). For online shops, it pays to see the CRA not as a burdensome duty but as a reason for resilient security processes – because the same processes the regulation demands also make a shop more robust in day-to-day operation. Anyone who clarifies roles early, sets up monitoring and structures the documentation is prepared for both dates. Talk to us if you want to assess your CRA exposure and set up the necessary processes – our team supports hosting, security operations and technical documentation.
This article draws on Regulation (EU) 2024/2847 (Cyber Resilience Act) in the official text at EUR-Lex, the summary and explanations of the European Commission (digital-strategy.ec.europa.eu) and the information from the Federal Office for Information Security (BSI) on the Cyber Resilience Act. The figures, deadlines and thresholds mentioned can change over time and depending on interpretation. This article does not replace legal advice. As of: July 2026.
The CRA (Regulation (EU) 2024/2847) has been in force since 10 December 2024 (EUR-Lex). The reporting and vulnerability duty applies from 11 September 2026, and the full manufacturer obligations with CE marking and SBOM from 11 December 2027 (European Commission). So the appropriate processes for products in your assortment should be prepared early.
As a rule yes, if you sell products with digital elements. As a distributor you typically have to verify that CE marking, declaration of conformity and contact details are present, and you may not offer non-compliant goods (European Commission). If you source goods directly from non-EU countries, you may additionally become an importer with extended obligations.
From that day, actively exploited vulnerabilities and severe security incidents are subject to reporting (EUR-Lex). Reporting is staged: an early warning within 24 hours, a full report within 72 hours and a final report within 14 days – via the CRA Single Reporting Platform to the BSI or CERT-Bund and to ENISA (BSI).
An SBOM (Software Bill of Materials) is a machine-readable list of a product's software components. The CRA requires it from manufacturers at least for the top-level dependencies (EUR-Lex). If you offer your own software, apps or own-brand hardware, an SBOM is, in our experience, not only mandatory but also practical: it makes reacting quickly to new vulnerabilities easier (project experience).
For breaches of the essential requirements as well as the SBOM and vulnerability obligations, fines of up to EUR 15 million or 2.5 percent of worldwide annual turnover are possible – whichever is higher (EUR-Lex). Lower maximum limits apply to other obligations and to incorrect information. The exact amount depends on the individual case and the market surveillance authority.
We help classify your role under the CRA, set up patch management and security monitoring in your hosting, and build the technical documentation. This typically lets you prepare the reporting processes for 2026 and the manufacturer obligations for 2027 in a structured way – embedded in an ongoing, documented security operation (project experience).