Stavenor

Guides

Does the CRA Apply to Products Already on the Market?

Updated 20 September 20262 min read

Short answer: mostly no — except for reporting, which applies already.

The Cyber Resilience Act runs on two separate axes, and reading only the first one creates a dangerous sense of safety.


Axis one: the product requirements

Article 69(2): products placed on the market before 11 December 2027 are subject to the Regulation's requirements only if, from that date, they undergo a substantial modification.

So a device you sold in 2025 does not need CE marking under the CRA, a CRA technical file or a CRA declaration of conformity — unless you substantially modify it after 11 December 2027.

What counts as a substantial modification? Recital 39: a security update that reduces cybersecurity risk without changing the intended purpose is not a substantial modification. A feature update that changes intended functions, type or performance generally is.


Axis two: reporting

Article 69(3) makes an express exception. By way of derogation from paragraph 2, the reporting obligations of Article 14 apply to all in-scope products placed on the market before 11 December 2027 — modified or not.

And Article 14 has applied since 11 September 2026.

Your installed base is in scope for reporting even where it is out of scope for everything else. If a vulnerability in a product you sold last year is actively exploited, and you become aware of it now, the 24-hour clock runs.


Reporting outlives support

The Commission's guidance on the application of the CRA (C(2026) 5252, paragraph 210) adds a point most summaries miss:

For products placed on the market before 11 December 2027, or whose support period has ended, the Annex I Part II vulnerability handling obligations do not apply — but reporting still does.

A device you stopped updating years ago remains reportable if someone exploits it.


No retroactive reporting — with one catch

Paragraph 217 of the same guidance: there is no obligation to report active exploitation you were already aware of before 11 September 2026.

The catch: if you knew about a vulnerability before that date, but become aware that it is being exploited after it, that exploitation is reportable.


What to do about your installed base

  1. List every product still available on the EU market — including older models and versions.
  2. Connect them to your vulnerability monitoring, even if you no longer ship updates for them.
  3. Make sure your reporting procedure covers them. Most procedures are written for current products only.

Sources

Position as at 20 September 2026. General information, not legal advice.