Tuesday, August 25, 2026 | Trusted IoT intelligence since 2016
General IoT Hardware & Devices India IT & Telecom Industrial IoT Agriculture Defence Energy Healthcare Logistics Smart Cities Networks Platforms & Cloud Smart Home
2 min read

You Have Until September 11 to Fix This, or Your IoT Product Becomes Illegal in Europe

On September 11, 2026, the clock starts on the first hard deadline inside the EU’s Cyber Resilience Act — and most connected-device makers still believe they have until 2027 to comply. That assumption is about to get expensive. The CRA entered into force in December 2024, and its headline requirements — security-by-design, mandatory security updates, […]

On September 11, 2026, the clock starts on the first hard deadline inside the EU’s Cyber Resilience Act — and most connected-device makers still believe they have until 2027 to comply.

That assumption is about to get expensive.

The CRA entered into force in December 2024, and its headline requirements — security-by-design, mandatory security updates, CE marking for cybersecurity — don’t fully apply until December 11, 2027. But buried inside the regulation is Article 14, and it goes live thirteen months earlier than that. From September 11, 2026, any company selling a “product with digital elements” into the EU — sensors, gateways, smart appliances, industrial controllers, wearables, the entire IoT stack — must report actively exploited vulnerabilities and severe security incidents to ENISA and national cyber authorities within 24 hours of becoming aware of them. A fuller notification follows within 72 hours, and a final report is due within 14 days of a fix.

Two details make this deadline sharper than it first looks. First, scope isn’t limited to EU-headquartered companies — anyone placing a connected product on the EU market is covered, wherever they’re based. Second, the obligation is retroactive: Article 69(3) applies the reporting duty to products already sold and already in the field, not just new launches. A sensor shipped in 2019 that’s still running in a warehouse outside Rotterdam falls under the same 24-hour clock as a product launching next month.

That retroactivity is what actually catches teams off guard. To meet a 24-hour reporting window, a company has to already know — continuously, not after the fact — exactly which software components sit inside every product it has ever shipped into the EU. That means a maintained software bill of materials and live vulnerability tracking, running before September 11, not assembled in response to an incident. Teams that start building that process in October will have already missed the point of the deadline.

The penalty structure is built to be felt. Under Article 64, violations of the essential cybersecurity requirements and the Article 14 reporting duty carry fines of up to €15 million or 2.5% of global annual turnover, whichever is higher — for a billion-dollar IoT vendor, that ceiling works out closer to €25 million. Regulators can also pull non-compliant products from the EU market entirely, a consequence that for many manufacturers does more damage than the fine itself.

The real story here isn’t the euro figure. It’s that “we’ll be ready by 2027” is the wrong sentence to be saying out loud right now. The Cyber Resilience Act’s most operationally demanding obligation lands more than a year before the deadline most companies have on their roadmap, and it reaches back into hardware some teams stopped thinking about years ago.

nn

EU CRA Article 14 Reporting Duty infographic