SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
SDV WikiUpdated August 7, 2026

EU Cyber Resilience Act

The EU regulation on cybersecurity for products with digital elements — vulnerability reporting duties start September 11, 2026, and type-approved vehicles are outside its scope.

The Cyber Resilience Act, Regulation (EU) 2024/2847, is the European Union’s horizontal cybersecurity regulation for “products with digital elements” — any hardware or software product made available on the Union market, including components placed separately on the market. It obliges manufacturers to build products securely, to handle vulnerabilities across a defined support period, and to report actively exploited vulnerabilities and severe incidents to national authorities. It is not a vehicle regulation, and the single most useful thing to know about it in an automotive context is where it stops: type-approved vehicles and their components are excluded, and the duties land on the software layers around the vehicle instead.

The act entered into force on December 10, 2024. Its main obligations apply from December 11, 2027, but two parts arrive earlier: the rules on notifying conformity assessment bodies from June 11, 2026, and the reporting obligations in Article 14 from September 11, 2026.

The automotive boundary

Article 2 of the act provides that it does not apply to products with digital elements covered by Regulation (EU) 2019/2144, the EU General Safety Regulation — the instrument through which the EU makes UN R155 and UN R156 binding. A vehicle placed on the EU market under type approval, together with the systems and components approved with it, therefore answers to the R155 cybersecurity management system and the R156 software update management system, not to the Cyber Resilience Act.

That exclusion is narrower than it first appears, because a modern vehicle program ships a great deal of software that is not itself type-approved:

  • Backend and cloud services that are not the remote data processing a type-approved function depends on
  • Engineering, diagnostic and workshop tooling sold as products
  • Aftermarket and dealer-fitted electronics — accessories bolted into a vehicle after approval, which sit outside the R156 update discipline governing the vehicle they are attached to
  • Charging equipment, telematics boxes, fleet hardware and the mobile applications sold with them

The result is a compliance seam rather than a clean line. The same organization can be an approval holder under R155 for the car and a manufacturer under the Cyber Resilience Act for the tool that services it, with different reporting addresses and different clocks.

What Article 14 requires from September 11, 2026

A manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting that product’s security, must notify the Computer Security Incident Response Team (CSIRT) of the member state where it has its main establishment, and the EU Agency for Cybersecurity, ENISA. The deadlines are short and staged:

StepDeadline
Early warning notification24 hours from becoming aware
Main notification72 hours
Final report, actively exploited vulnerabilityno later than 14 days after a corrective or mitigating measure is available
Final report, severe incidentwithin one month of the 72-hour submission

Notifications are filed once, through the CRA Single Reporting Platform that ENISA is required to establish under Article 16 and which the Commission expects to be operational on the date the duties begin. The receiving CSIRT passes the notification to the CSIRTs of other member states where the product has been made available; a delegated act adopted on December 11, 2025 sets out the narrow cybersecurity grounds on which that onward sharing may be delayed. Anyone, not only manufacturers, may report vulnerabilities, threats, incidents and near misses voluntarily through the same platform.

The reach is wider than the 2027 obligations. The reporting duties apply to products with digital elements already made available on the Union market, including those placed on the market before December 11, 2027. A supplier whose tool has been in the field for years acquires a 24-hour reporting clock in September 2026 without shipping anything new.

How it sits against R155 and ISO/SAE 21434

R155 asks whether a manufacturer runs a certified cybersecurity management system and can show, per vehicle type, that risks were assessed and mitigated; its incident duties run toward type-approval authorities and are framed around the approved vehicle. The Cyber Resilience Act asks whether a product on the market is secure by design, supported for a declared period, and reported on within hours when something is being exploited; its duties run toward CSIRTs and ENISA. ISO/SAE 21434 sits underneath both as the engineering reference, which is why organizations that built a real 21434 practice for R155 generally find the act’s technical requirements familiar and its reporting timetable the unfamiliar part.

For a supplier the practical question is not which regime is stricter but which of its products falls where, and whether anyone has drawn that map. Two duty holders, two clocks and two recipients for what may be one vulnerability in one shared codebase is an organizational problem before it is a technical one.

September 2026 and the Data Act

The Commission’s compliance calendar for August and September 2026 recorded the Cyber Resilience Act reporting date of September 11 alongside partial application of the EU Data Act, Regulation (EU) 2023/2854, on September 12 — the calendar noted the milestone without specifying which provisions it covers. The two land a day apart and pull in different directions on the same vehicle data: the Data Act widens who may obtain data generated by a connected product, while the Cyber Resilience Act tightens what must be disclosed, to whom, and how quickly when that product is attacked. Our reporting on the calendar is in EU calendar sets Cyber Resilience Act vulnerability reporting to start September 11.

What to watch

Whether the Single Reporting Platform is genuinely ready on September 11 is the near-term question; the Commission said in mid-2026 that functional and security testing was still under way. Beyond that, the interesting boundary is the one the exclusion creates. Nothing in the act obliges a type-approval authority and a CSIRT to reconcile their views of the same vulnerability, and nothing obliges an approval holder to tell a CSIRT about a flaw in an approved component that is also present in an unapproved product. How that seam is policed — and whether the aftermarket layer that sits inside vehicles but outside type approval attracts enforcement attention — will determine how much the act actually changes about automotive cybersecurity practice.

Primary sources: European Commission, summary of the legal text of the Cyber Resilience Act and Cyber Resilience Act — Reporting obligations.

Related: EU Data Act (vehicle data) · ISO/SAE 21434 · OTA update · Type approval / homologation · UNECE R155 · UNECE R156