Cyber Resilience Act mandates long-term security planning for connected devices

New European legislation requires manufacturers to embed cybersecurity into the entire lifecycle of internet-connected products, addressing the risks of long service lives and ensuring safety long after sale.

Internet-connected products are increasingly being designed for very long service lives, from household devices to industrial equipment. That creates a basic but often overlooked problem: security cannot end when the sale does. As the Computerworld column argues, the Cyber Resilience Act forces manufacturers to treat cybersecurity as a lifecycle obligation, not a launch-day feature.

The European Commission says the regulation is intended to raise the security of products with digital elements across their entire life cycle, including hardware, software and components placed on the EU market. It entered into force on 10 December 2024, with the main obligations applying from 11 December 2027. The Commission also says the law makes manufacturers responsible for providing security support and software updates to address vulnerabilities.

That matters because many connected devices remain in service for a decade or more. The article points out that smart metres, sensors and industrial machines may still be operating long after the software, suppliers and even the original development teams have changed. In practice, this means producers need to decide early how they will identify devices in the field, deliver updates, and respond if a component or supplier disappears. The Commission’s FAQs say the framework applies to products with digital elements made available on the Union market, including final products and separately placed components.

The timing is already relevant. The article says reporting duties for actively exploited vulnerabilities and certain serious security incidents begin on 11 September 2026, well before the rest of the regime takes full effect. The Commission’s implementation material confirms that the main obligations follow in December 2027. It also published guidance on 27 July 2026 to clarify scope, support periods and reporting duties.

For manufacturers, the practical message is simple: a product’s technical life and its security life must be planned together. The column argues that if a device is meant to last 15 years, the company behind it should know from the outset how it will remain safe on the internet in year 15. The Commission has warned that non-compliance can attract substantial penalties, including fines of up to €15 million or 2.5 per cent of global turnover, whichever is higher.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.