New mandatory requirements
For products with digital elements within its scope, the Cyber Resilience Act introduces cybersecurity and vulnerability-handling requirements. Reporting obligations have applied since 11 September 2026; the main obligations generally apply from 11 December 2027. Exemptions and specific roles require separate assessment.
Existing obligations
Existing contractual, data-protection and sector-specific obligations are not automatically replaced by the CRA. The requirements that applied previously depend on the product and its use.
An optional digital capability
A digital product dossier can connect the start and end of support, software and firmware versions, security updates, a security contact, known vulnerabilities and related records. Use of Roboterausweis is not prescribed by law.
New role and responsibility consequences
Manufacturers, importers and distributors have different obligations. Own brands or modifications can also affect the responsible role. The platform does not determine whether the CRA applies or which role a company has.
Manage evidence in a structured way
Cybersecurity risk assessment, vulnerability management and a Software Bill of Materials (SBOM) have their own document areas. Security updates are documented; the platform does not install updates on machinery.
Documentation status, not a statement of conformity
Recorded and not recorded describe only the dossier. A file in the SBOM area does not prove that every statutory requirement as to content, format or completeness has been met.
Official sources
Source status: 10 October 2026. General information; not a legal assessment of any individual case.
European Commission · Regulatory information (opens in a new window)EUR-Lex · Cyber Resilience Act (opens in a new window)