Guidelines for firms on cyber-resilience rules
(Pic: Shutterstock)

11 Sept 2026 technology Print

Guidelines for firms on cyber-resilience rules

The National Cyber Security Centre (NCSC) has published guidelines for businesses as new rules on products with a digital element come into effect across the EU today (11 September). 

From today, manufacturers must report significant vulnerabilities and incidents that affect the security of their products through the EU's Cyber Resilience Act (CRA) reporting framework. 

The Department of Justice says that the National Cyber Resilience Act Guidelines provide practical support for manufacturers covered by the regulations.

The guidelines contain information on reporting thresholds, timelines, notification procedures, and the information required when submitting reports. 

‘Milestone’ 

Dr Richard Browne (director general of the NCSC) said that today marked “a significant milestone” in European cyber-security regulation.  

“The commencement of the Cyber Resilience Act's reporting obligations will improve visibility of vulnerabilities and incidents affecting connected products and strengthen our collective ability to respond to emerging cyber threats,” he stated. 

Under the rules, manufacturers who become aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements must report that information through the CRA platform. 

Initial notifications are required within 24 hours of becoming aware of a reportable event. 

The CRA establishes a common framework for improving the cyber-security of products with digital elements throughout their lifecycle. It will apply in full from 11 December 2027. 

Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland

Copyright © 2026 Law Society Gazette. The Law Society is not responsible for the content of external sites – see our Privacy Policy.