8. 7. 2026 | Jiří Hradský
Cyber Resilience Act (CRA): obligations for software and hardware manufacturers
Do you develop software or manufacture devices that connect to the internet?
Then the Cyber Resilience Act (CRA) very likely applies to you – Regulation
(EU) 2024/2847 on horizontal cybersecurity requirements for products with
digital elements. The first hard obligation kicks in as early as 11 September
2026: reporting of actively exploited vulnerabilities. And watch out – it
also covers products that are already on the market. Breaches carry fines of up
to EUR 15,000,000 or 2.5 % of worldwide turnover. In this article we summarise
who the CRA applies to, what obligations it introduces, what the Czech
adaptation act addresses, and how to prepare.