0
Your cart


TOTAL excl.
TOTAL incl.
Pay

Wednesday, August 5, 2026

Cyber Resilience Act: Are your connected devices ready for the September 2026 deadline?

Cyber Resilience Act: Are your connected devices ready for the September 2026 deadline?


CERTILIENCE – BOOTH E149


With the Cyber Resilience Act, Europe is imposing cybersecurity requirements directly on connected products, rather than just organizations, for the first time. From September 11, 2026, all manufacturers, importers, and distributors will be required to report active vulnerabilities in their products, including those already on the market. Certilience supports manufacturers in achieving this compliance, from security audits of their connected devices to securing their IoT/IIoT fleets in production with CSLC.

Three deadlines to remember

December 10, 2024 — Effective date

The regulation becomes binding in all Member States and launches the transition periods.

September 11, 2026 Key Deadline

Obligation to report any actively exploited vulnerability within 24 hours, any serious incident within 72 hours, including for products already on the market.

December 11, 2027 — Full and complete implementation

All essential requirements become mandatory: CE marking, technical documentation, conformity assessment.

Who is affected?

The CRA affects the entire chain: manufacturers, importersAnd distributors of products containing digital elements sold in the EU. In concrete terms, this goes well beyond just software publishers

The level of requirement then depends on the cybersecurity risk of the product:

By default : the majority of products, with self-assessment by the manufacturer.

Important Firewall, VPN, password managers, antivirus: enhanced control.

Critical Identity management, HSM, hypervisors: mandatory certification by a notified body.

There are some sectoral exceptions (medical devices, automotive, aeronautics), which are already covered by their own regulations.

What changes in concrete terms?

Risk analysis before any development. SBOMgenerated for each version, listing open source components and dependencies. Coordinated Vulnerability Disclosure Policy with a single point of contact. Guaranteed fixes at least 5 years. And from 2027, a CE marking which incorporates cybersecurity for the first time.

Penalties of up to €15M or 2.5% of global turnover are planned for failure to comply with essential requirements and up to €10M or 2% for other obligations.

Our role at Certilience

Two of our areas of expertise directly address the challenges faced by the CRA regarding connected objects:

The IoT auditTo measure the actual security level of a connected device, we conduct penetration tests on the embedded API, analyze the protocols and information communicated by the device, perform penetration tests via its connectivity ports, and test its web interface, if one exists. Each assessment concludes with a summary of vulnerabilities (configuration errors, data leaks, etc.), prioritized recommendations, and concrete suggestions. This is precisely the "security by design" approach required by regulations.

CertiLink Secure Cloud (CLSC)Our sovereign, secure interconnection solution for IoT/IIoT systems offers: a complete separation between IT and OT to prevent intrusions on the office network from spreading to automated devices; end-to-end encryption; high availability (>99.9%); and a business continuity and disaster recovery plan (BCP/DRP), all hosted and operated from France. This directly addresses the need to maintain the security of connected products throughout their entire lifecycle, once deployed in the field.

The September 2026 deadline is here, and this also applies to your existing fleet. It's better to plan your strategy now than to discover it in a crisis.

Don't wait until the last minute and book an appointment with our experts at the show:



Ce site utilise des cookies pour optimiser le fonctionnement de la plateforme et, mesurer et cibler nos campagnes publicitaires.