What the CRA requires
The Cyber Resilience Act, Regulation EU 2024/2847, applies to products with digital elements placed on the EU market. Manufacturers must handle vulnerabilities across the product lifecycle, run a coordinated disclosure process, meet the Annex I security requirements, and back it all with a risk assessment that leads to an EU Declaration of Conformity. The regulation itself is the demand driver. Nobody is buying compliance because it is nice to have.
The two deadlines
Two dates create the buying pressure. From 11 September 2026 the Article 14 reporting duty applies, so a manufacturer must report actively exploited vulnerabilities and severe incidents to ENISA on a 24 hour, 72 hour, and 14 day clock. By 11 December 2027 full conformity applies, covering the complete path from classification through Annex I to the Declaration of Conformity. The first deadline is close, and the process behind it takes months to stand up.
Article 14 reporting starts 11 September 2026. Full conformity is due 11 December 2027. Both dates are fixed and neither moves for unprepared manufacturers.
Penalties and scope
Non-compliance with the essential requirements can reach fines of 15 million euro or 2.5 percent of global annual turnover, whichever is higher. Scope is broad, so if a product has digital elements and reaches the EU market it is likely in scope, whether the manufacturer sits in the EU or not. That combination of broad scope, severe penalties, and a near deadline is the case you make to a prospect.