What is the state of implementation of the Cyber Resilience Act in the EU? 27 July 26 Visiola Pula

Cullen International's latest Benchmark analyses how 19 EU countries are preparing to implement the Cyber Resilience Act (CRA). It tracks national laws, designated authorities, incident notification bodies and penalties ahead of the regulation’s application dates.

Key findings

Implementation remains at an early stage in most surveyed countries: Finland and Slovakia are the only countries that have adopted implementing legislation, while draft laws have been proposed in the Czech Republic, France, Germany, the Netherlands, Spain and Sweden.

Member states are taking different approaches to market surveillance: most countries that have proposed implementing legislation designate a single market surveillance authority, while the Czech Republic proposes 12 sectoral authorities.

Manufacturers will need to comply with incident and vulnerability notification requirements from 11 September 2026, before the CRA enters into full application on 11 December 2027.

Why it matters

The CRA will introduce EU-wide cybersecurity requirements for products with digital elements, but national implementation will determine which authorities enforce the rules and how penalties are applied. This is relevant for manufacturers, importers, distributors, cybersecurity authorities and conformity assessment bodies.

What the content covers

The Benchmark tracks proposed and adopted national laws implementing the CRA in 19 EU countries, including designated market surveillance authorities, notifying authorities, CSIRTs and national penalties regimes.

Background

The Cyber Resilience Act establishes baseline cybersecurity requirements for hardware and software products with digital elements, from the design phase through expected use. As an EU regulation, it will apply directly across EU member states without national transposition, but member states must still designate enforcement authorities, incident notification bodies and penalty regimes. The full regulation will apply from 11 December 2027, while rules on notification of actively exploited vulnerabilities and severe incidents will apply from 11 September 2026.

Scope

Region: Europe
Countries covered: 19 EU countries (including Finland, Slovakia, the Czech Republic, France, Germany, the Netherlands, Spain, Sweden, Italy and Austria)
Policy area: Cybersecurity and product regulation
Source type: Benchmark
Published: 16 July 2026