progress_activityThe EU Cyber Resilience Act makes your connected product, the cloud it depends on, and its companion app your legal responsibility. Reporting obligations start 11 September 2026.
Scope your product with usThree questions. If the answer to the first one is yes, and to either of the others, Regulation (EU) 2024/2847 applies to you.
If you sell or distribute your product in the EU under your own name or trademark — directly, through a distributor, or as a component for some other company, you are directly affected.
If your product uses a direct or indirect network connectivity, your device qualifies.
If your product requires a web or cloud backend and/or a mobile or desktop app to operate, they all qualify as separate products.
The CRA defines the manufacturer as whoever places the product on the market under their own name or trademark — expressly including a party that had it designed or developed by someone else.
Who wrote the code is irrelevant to the statutory role. If your logo is on the box, the obligations are yours.
This is the trap in white-label and ODM sourcing: buying a finished module does not buy compliance with it. The evidence you need — the bill of materials, the conformity statement, the notification chain — has to be contracted for, because by default nobody upstream is obliged to give it to you.
| 10 December 2024 | CRA entered into force The clock started. Nothing was required of you yet. |
| 11 September 2026 | Reporting obligations go live Actively exploited vulnerabilities and severe incidents must be reported. You need a disclosure policy, an incident runbook, and a contractual notification chain with your suppliers before this date. |
| 11 December 2027 | Full regime and CE marking Declaration of conformity, complete Annex I coverage, technical documentation, and a declared support period. |
From 11 September 2026, actively exploited vulnerabilities and severe incidents are reported through the ENISA Single Reporting Platform — filed once, routed onward to the relevant national CSIRT.
| Early warning | 24 hours from becoming aware |
| Full notification | 72 hours |
| Final report | 14 days after a fix is available (vulnerability) — 1 month (severe incident) |
Note where the clock starts: when you become aware. Twenty-four hours is generous for filing a form and short for noticing in the first place — which makes detection, not paperwork, the binding constraint. If somebody else operates the cloud your product runs on, they will see it before you do, and your deadline depends on how fast they tell you.
Meeting that clock reliably means monitoring, alerting and triage already running across firmware, cloud and app on the day something happens. None of it can be assembled after the fact, and most of it is invisible until the first incident proves it missing. It is engineering work rather than paperwork — the kind we build and run.
forum
What you build, which markets you sell into, and how many units. We will tell you whether the CRA applies to you and what the next steps should be. This part costs you nothing.
contract
Once the NDA is signed you give us access to your infrastructure and your code.
inventory_2
Together we assemble a Software Bill of Materials for every product and every version that you still support.
troubleshoot
With the inventory in hand we can say what you are exposed to, what is already fixed upstream, and what needs work — across firmware, cloud and app.
Two areas of work that overlap, and we can help with either or both.
Once the initial SBOMs and vulnerabilities are mapped out, you will have the necessary coverage for the CRA vulnerabilities and incidents reporting.
The obligations run for as long as you support the product, not until the first filing. We build and operate pipelines that will automate vulnerability discovery, reporting and mitigation procedures.
It is, simply put. Our expertise and our AI-accelerated workflow can compress work that would normally take months into weeks.
mail office@nibblesmarthome.com
home_pin Petra Kočića 14b, 11080 Belgrade, Serbia