The Cyber Resilience Act in Romania: what product makers must do now
The CRA's first hard deadline arrives on 11 September 2026, when manufacturers must start reporting actively exploited vulnerabilities within 24 hours. The staged timeline, who is in scope, and what to do before full application in December 2027.
The third pillar of the EU’s cybersecurity legislation wave regulates neither critical-sector organizations (NIS2) nor financial entities (DORA) — it regulates products. The Cyber Resilience Act, Regulation (EU) 2024/2847, attaches cybersecurity obligations to hardware and software placed on the EU market, and its first hard deadline is close: from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours. Full application follows on 11 December 2027 — but for anyone who builds or ships digital products, the preparation window is now.
This overview covers the staged timeline, who is in scope, what the obligations require, how enforcement works in Romania, and where to focus first.
The CRA in brief
The Cyber Resilience Act sets horizontal cybersecurity requirements for “products with digital elements” — hardware and software, including their remote data processing where integral to the product. Its logic mirrors classic EU product law: essential requirements, conformity assessment, CE marking, and market surveillance — applied for the first time to cybersecurity. A product that does not meet the requirements will, from December 2027, simply not be lawfully placed on the EU market.
Timeline: three deadlines, not one
- 10 December 2024 – the CRA enters into force.
- 11 June 2026 – the provisions on conformity assessment bodies apply, so the certification infrastructure can stand up.
- 11 September 2026 – the reporting obligations apply: manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products.
- 11 December 2027 – the main obligations apply in full: essential cybersecurity requirements, vulnerability handling, technical documentation, conformity assessment, and CE marking.
The sequencing matters – the reporting duty arrives fifteen months before full application, and it applies to products already on the market, not only to new ones.
Who is in scope
The primary addressee is the manufacturer — whoever develops or has developed a product with digital elements and places it on the EU market under their name, wherever they are established. Importers and distributors carry verification duties. Open-source software has a deliberately lighter regime, with a “steward” category for foundations and similar bodies supporting open-source development. Pure services — SaaS as such — fall outside the CRA (NIS2 territory instead), except where remote processing is integral to a product’s function.
Products are tiered by risk: the default category — the large majority — can self-assess conformity; important products (classes I and II, e.g. password managers, firewalls, operating systems) face stricter assessment routes; critical products (e.g. smart cards, smart-meter gateways) may require European certification. Where your product lands determines your conformity path, so classifying early is worth the effort.
What the obligations require
- Security by design and by default – the essential requirements of Annex I: no known exploitable vulnerabilities at release, secure default configuration, attack-surface minimization, protection of data confidentiality and integrity, and more — evidenced through a documented cybersecurity risk assessment.
- Vulnerability handling across a support period – a coordinated vulnerability disclosure policy, a process for handling reports, a software bill of materials (SBOM) maintained internally, and security updates provided free of charge for the support period — in principle at least five years.
- Reporting from 11 September 2026 – staged notifications through ENISA’s single reporting platform, with the national CSIRT in the loop:
| Reporting stage | Deadline |
|---|---|
| Early warning of an actively exploited vulnerability or severe incident | No later than 24 hours after awareness |
| Vulnerability or incident notification | No later than 72 hours after awareness |
| Final report — actively exploited vulnerability | Within 14 days after a corrective or mitigating measure is available |
| Final report — severe incident | Within one month after the incident notification |
- Conformity assessment, technical documentation, and CE marking – from December 2027, the product carries the CE marking for cybersecurity like any other regulated product characteristic, backed by technical documentation that market surveillance can demand.
Enforcement in Romania
The DNSC acts as Romania’s market surveillance authority and national contact point under the CRA framework — the same authority Romanian organizations already know from NIS2, which concentrates cybersecurity supervision expertise in one place. Penalties reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential requirements or the reporting obligations, with lower tiers for other violations. Non-compliant products can also be withdrawn or recalled from the market — for a product business, often the sharper consequence than the fine.
CRA, NIS2, DORA: one map
The three regimes are complementary, not overlapping: NIS2 (GEO 155/2024 in Romania) regulates organizations in critical sectors; DORA regulates financial entities; the CRA regulates the products everyone buys and builds. A Romanian software company can face two regimes simultaneously — the CRA as a manufacturer and NIS2 as a digital provider — and entities regulated under NIS2 or DORA gain leverage from the CRA, because the security they must demand from suppliers increasingly arrives as a legal obligation on those suppliers.
What product makers should do now
- Inventory and classify. List every product with digital elements you place on the EU market and determine its CRA category — default, important, or critical — since that sets your conformity route and effort.
- Stand up reporting readiness first. The 11 September 2026 deadline requires detecting exploitation, deciding severity, and filing within 24 hours — escalation paths, decision authority, and platform access need to exist before the obligation starts.
- Assess against Annex I. A gap assessment of the essential requirements and the vulnerability-handling requirements, product by product — including whether you can actually sustain a five-year update commitment.
- Build the SBOM and disclosure machinery. Both take engineering time and both anchor everything else: you cannot handle vulnerabilities in components you have not inventoried.
- Plan the conformity file early. Technical documentation and the risk assessment accumulate naturally if started now — and painfully if reconstructed in late 2027.
Where Avencyx can help
Avencyx supports Romanian and EU product makers across the CRA lifecycle: product inventory and classification, gap assessments against the essential requirements, secure development and security architecture validation — including penetration testing of products before and after release — vulnerability-handling and disclosure processes, 24-hour reporting readiness backed by detection and response and incident response capability, and the technical documentation and evidence that conformity assessment demands. The work is anchored in Avencyx GRC. If your products will carry the CE marking for cybersecurity, talk to us — we will tell you honestly how far you are from it.
Legal disclaimer
This article is a general overview, not legal advice. Obligations depend on your products’ classification and your role in the supply chain, and implementing acts continue to be adopted — verify current requirements against the official texts, the DNSC, and qualified counsel.
Frequently asked questions
Does the CRA apply to my company?
If you manufacture hardware or software 'products with digital elements' placed on the EU market — from IoT devices to commercial software applications — yes, regardless of where you are established. Importers and distributors carry lighter obligations. Pure services (SaaS) are generally outside the CRA except for remote data processing that is integral to a product, and open-source software has a tailored, lighter regime.
What is the CRA compliance deadline?
There are three: 11 June 2026 for conformity assessment body provisions, 11 September 2026 for the reporting obligations (actively exploited vulnerabilities and severe incidents), and 11 December 2027 for the full obligations, including essential requirements and CE marking. The reporting deadline is the one that catches manufacturers unprepared — it arrives more than a year before full application.
Who enforces the CRA in Romania?
The DNSC acts as Romania's market surveillance authority and national reporting contact under the CRA framework, with reporting flowing through ENISA's single reporting platform. Penalties for breaching the essential requirements or the reporting obligations reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
How does the CRA relate to NIS2 and DORA?
They regulate different things: NIS2 and DORA regulate organizations (critical-sector entities and financial entities respectively), while the CRA regulates products. A Romanian software company can easily face two regimes at once — the CRA as a manufacturer, NIS2 as a digital provider — and NIS2/DORA entities benefit indirectly, since the products they procure will carry CRA obligations.