Your company manufactures products with digital elements, i.e. connected devices or software, or it imports or distributes them. The Cyber Resilience Act sets new obligations for this.
What matters now
- Since 11 September 2026, reporting obligations apply to actively exploited vulnerabilities and severe security incidents; from 11 December 2027, all requirements apply.
- First clarify which products are covered and which role your company has: manufacturer, importer or distributor.
- Manufacturers need, among other things, a risk assessment, vulnerability handling, security updates over the support period and technical documentation.
- Contracts with suppliers and open source components belong in the review.
- The topic also touches product liability, which expressly covers software from December 2026.
Documents I need
- a list of products and their digital components
- existing security and update processes
- contracts with suppliers and customers
- responsibilities within the company
Next steps
Send me the documents by email to kanzlei@bauer.legal or use the appointment request, and mention any deadline that is running. I usually reply within one working day and let you know how things can proceed. You can write to me in English or German. How we work together and how fees are charged is explained under How we work together.
More: IT law, Deadlines for businesses.
This page gives a general overview of German law and does not replace advice on the individual case.