Uncategorized

EU Cyber Resilience Act for Dropshipping Smart Products: What Starts on September 11, 2026

Cyber Resilience Act reporting starts September 11, 2026. Learn the role map, 24/72-hour deadlines and supplier controls dropshippers need for smart products.

Quick answer: The EU Cyber Resilience Act’s incident-reporting obligations start on September 11, 2026 for manufacturers of products with digital elements. Manufacturers must send an early warning about an actively exploited vulnerability or severe security incident within 24 hours of becoming aware and a fuller notification within 72 hours through the EU’s Single Reporting Platform. Most broader product requirements apply from December 11, 2027, but dropshippers selling smart devices should act now: determine whether they are a manufacturer, importer or distributor, identify the responsible manufacturer, and create a supplier-to-store escalation path that can work inside the 24-hour window.

Updated: September 1, 2026

Cyber Resilience Act: key takeaways for smart-product sellers

  • Article 14 reporting obligations apply from September 11, 2026.
  • The 24-hour and 72-hour duties are primarily manufacturer obligations.
  • Reporting covers actively exploited vulnerabilities and severe incidents affecting product security.
  • The reporting duties cover products already made available in the EU, including products placed on the market before the main rules apply in 2027.
  • A private-label seller can be the manufacturer when a product is marketed under its name or trademark.
  • An EU business placing a non-EU manufacturer’s product on the EU market can be the importer.
  • Distributors and importers have their own verification, stop-sale, notification and cooperation duties under the broader regime.
  • A product feed is not enough; sellers need model identifiers, manufacturer contacts, vulnerability routes and support-period evidence.

What starts in 2026 and what waits until 2027?

The Cyber Resilience Act—Regulation (EU) 2024/2847—entered into force on December 10, 2024. Its timeline has three important milestones:

Date What applies
June 11, 2026 Chapter IV rules on notification of conformity-assessment bodies.
September 11, 2026 Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents.
December 11, 2027 Most of the CRA’s main product and economic-operator obligations.

The European Commission confirms this sequence in its official CRA summary.

The distinction matters. A seller should not claim that every CE-marking or distributor duty began in September 2026. At the same time, it would be a mistake to postpone all work until late 2027 because the reporting clock begins now and depends on data the supply chain must already be able to exchange.

Which products are covered?

A product with digital elements is hardware or software whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Remote data-processing solutions necessary for a product function can also form part of the product.

Examples potentially relevant to dropshipping include:

  • Wi-Fi or Bluetooth cameras;
  • smart plugs, bulbs and switches;
  • connected doorbells and locks;
  • fitness trackers and connected wearables;
  • app-controlled toys;
  • networked pet feeders;
  • smart irrigation controllers;
  • routers, repeaters and network devices;
  • USB devices with embedded software;
  • commercial software and companion apps.

Certain products covered by other sector-specific EU rules are excluded or treated differently. Medical devices, vehicles and aviation products can require separate analysis. Do not classify an item from its marketing name alone; examine connectivity, software, remote services and intended use.

Manufacturer, importer or distributor?

Your legal role does not necessarily match the word used in a supplier dashboard.

Role Practical CRA meaning Dropshipping example
Manufacturer Develops or manufactures a product, has it designed or manufactured, and markets it under its name or trademark. A merchant applies its own brand to a supplier’s smart camera.
Importer An EU-established person places on the market a product bearing the name or trademark of a non-EU manufacturer. An EU company first brings a Chinese-brand connected device to the EU market.
Distributor A supply-chain actor other than the manufacturer or importer makes the product available in the EU without changing its properties. A retailer resells an already imported, unchanged branded smart plug.

Private label can make the merchant the manufacturer

Changing the logo is not merely a marketing decision. If the item is sold under the merchant’s name or trademark, the merchant may carry manufacturer obligations, including the reporting duty and later cybersecurity, documentation and support obligations.

Do not assume the supplier is the EU importer

Direct shipment from a non-EU factory to an EU consumer can produce a more complicated chain than the store’s product page suggests. Map who first places the exact product on the EU market, which company is established in the EU and whose name appears on the device and documents.

The 24-hour and 72-hour reporting sequence

From September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The Commission’s official reporting guidance sets out the sequence:

  1. Within 24 hours: submit an early warning after becoming aware.
  2. Within 72 hours: submit the main notification with fuller information.
  3. Actively exploited vulnerability: submit a final report no later than 14 days after a corrective or mitigating measure becomes available.
  4. Severe incident: submit a final report within one month after the 72-hour notification.

Manufacturers report through the CRA Single Reporting Platform. The initial notification goes to the Computer Security Incident Response Team for the Member State of the manufacturer’s main establishment and is generally made available to ENISA.

What does “becoming aware” mean operationally?

A customer ticket, supplier email, app-store report, researcher message or unusual return pattern can be the first signal. The legal assessment belongs to the responsible manufacturer, but a slow retailer inbox can consume most of the reporting window. Every participant needs a route that escalates a possible security issue immediately.

What an ecommerce seller should do after a security alert

  1. Preserve the report. Record the original message, timestamp, order, product identifier, firmware/app version and evidence.
  2. Protect personal data. Restrict access to exploit details and customer information.
  3. Escalate to the responsible manufacturer. Use the pre-agreed security contact, not a general sales representative.
  4. Identify affected listings and inventory. Map the report to exact models, batches and supplier SKUs.
  5. Consider a temporary stop-sale. Do not keep promoting a product when there is reason to believe it presents a cybersecurity risk.
  6. Coordinate customer communication. Use accurate update, mitigation or recall instructions from the responsible operator.
  7. Track corrective action. Firmware, app, credential reset, product replacement or withdrawal from sale must reach the relevant customers.
  8. Document decisions. Keep the chronology and owners for later cooperation with market-surveillance authorities.

A cybersecurity incident can also become a product-safety, privacy, refund and liability issue. Review the broader allocation of risk in our guide, Can You Be Sued for a Dropshipping Product?

Supplier onboarding for smart products

A generic supplier checklist is not enough for connected devices. Add a cybersecurity annex before listing a product.

Identity and role

  • legal manufacturer name and address;
  • EU importer or authorized-representative details where applicable;
  • the exact brand and trademark shown on the item;
  • model, type, batch and serial-number logic;
  • confirmation of who owns Article 14 reporting.

Vulnerability operations

  • a monitored security-reporting address;
  • 24/7 escalation for actively exploited vulnerabilities and severe incidents;
  • the supplier’s vulnerability-disclosure policy;
  • how firmware and app updates are delivered;
  • how the supplier identifies affected batches and customers;
  • how language-specific security instructions are provided.

Evidence package

  • EU declaration of conformity and technical-document references when applicable;
  • CE-marking evidence;
  • user instructions and secure-configuration guidance;
  • support-period end date;
  • software bill-of-materials availability where relevant;
  • independent test reports and remediation status.

Use the broader operational checks in our 15-point supplier guide, then add this product-specific layer.

Product-page and support-period data

The Commission’s CRA summary explains that manufacturers will need to provide identification and contact information, user instructions and the end date of the support period. Distributors will need to verify CE marking and specified manufacturer/importer information and instructions under the broader rules.

A dropshipping catalog should therefore prepare structured fields for:

  • manufacturer and importer identity;
  • model and version;
  • required connectivity and companion app;
  • minimum operating-system versions;
  • security-update method;
  • support-period end month and year;
  • secure setup and password instructions;
  • vulnerability-reporting route;
  • current advisories or discontinued status.

Do not turn technical evidence into unsupported claims such as “unhackable” or “military-grade security.” The product page should be factual and bounded, following the same evidence discipline described in our high-converting product-page guide.

Existing inventory and old models

The reporting obligation is unusually important for legacy products. The Commission states that Article 14 reporting applies to all products with digital elements made available on the EU market, including products placed on the market before December 11, 2027.

By contrast, products placed on the market before December 11, 2027 are generally subject to the main CRA product obligations only if they undergo a substantial modification from that date. This is why sellers must distinguish the early reporting rule from the later full regime.

Create a legacy-device register

  • store SKU and supplier SKU;
  • manufacturer and importer;
  • hardware revision;
  • firmware and companion-app versions;
  • sale dates and destination countries;
  • support status;
  • security contact;
  • known advisories and fixes;
  • customer-notification capability.

If the supplier cannot identify versions or receive vulnerability reports, treat that as a product-selection risk—not merely a missing spreadsheet field. Our product research system can be extended with a “connected-device evidence” gate.

A 30-day CRA readiness plan for ecommerce sellers

Days 1–5: inventory

  • Export every connected or software-enabled product.
  • Group variants by manufacturer model and hardware revision.
  • Identify EU sales and inventory locations.

Days 6–10: role mapping

  • Classify manufacturer, importer and distributor for each line.
  • Flag private-label items.
  • Obtain the name of the operator responsible for reporting.

Days 11–15: escalation

  • Create a security-report intake form and monitored address.
  • Set a one-hour internal escalation target.
  • Test the supplier’s emergency contact.

Days 16–20: evidence

  • Collect identifiers, declarations, CE evidence, instructions and support dates.
  • Record missing or contradictory documents.
  • Pause new listings with no responsible operator.

Days 21–25: response playbook

  • Define stop-sale, customer-notice, update, return and recall decisions.
  • Assign legal, security, customer-support and fulfilment owners.
  • Prepare message templates without pre-judging an incident.

Days 26–30: simulation

  • Run a tabletop exercise for an actively exploited smart-camera vulnerability.
  • Measure time from customer ticket to manufacturer escalation.
  • Confirm the exact affected customers can be identified.
  • Fix every handoff that cannot meet the 24-hour window.

Frequently asked questions

When do CRA reporting obligations start?

Article 14 reporting obligations apply from September 11, 2026. Most main CRA obligations apply from December 11, 2027.

Who must make the 24-hour report?

The mandatory reporting duty is directed primarily at manufacturers. A seller may itself be the manufacturer when it markets the product under its name or trademark.

Do ordinary distributors have no responsibility?

Distributors have their own duties under the broader CRA regime, including verification, stop-sale, vulnerability escalation and cooperation obligations. They also need an operational route to get incident information to the responsible manufacturer now.

Are products sold before December 2027 excluded?

No. The Commission states that the early reporting obligations cover products with digital elements already made available in the EU, including products placed on the market before the main rules apply.

Does CE marking prove the product is secure?

No single mark proves that a product can never be compromised. CE marking is part of the conformity framework; sellers still need correct documentation, support information and a working vulnerability-response process.

Does the CRA cover a simple non-connected product?

The regulation targets products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect connection to a device or network. Purely non-digital goods may fall outside this scope but can be covered by other product rules.

What should I do if the supplier has no security contact?

Escalate the gap before listing or continuing to sell the item. A general sales inbox is not a credible route for a time-critical vulnerability report.

Is this only an EU-manufacturer issue?

No. Non-EU products sold into the EU create importer and distributor questions, and a private-label EU seller can become the manufacturer.

Practical next step: Choose the five connected products with the most EU sales. For each one, write down the legal manufacturer, EU importer, exact model, support end date and monitored security contact. Send a simulated high-priority vulnerability message and time how long it takes to reach a person who can act. If any row is blank or the route takes most of a day, pause scaling that product until the gap is fixed.

Editorial disclaimer: Dropshipper Lab is an independent educational website and is not affiliated with or endorsed by the European Commission, ENISA or any market-surveillance authority. This article summarizes public EU guidance reviewed on September 1, 2026. It is general educational information, not legal or cybersecurity advice. Scope, role classification, sector exclusions, enforcement and technical response should be assessed for the exact product and supply chain.

Disclosure: This article may contain affiliate links. If you make a purchase through one of these links, the author may earn a commission at no additional cost to you. This does not influence the content or our evaluation of the products and services discussed.

Disclosure: This article may contain affiliate links. If you make a purchase through one of these links, the author may earn a commission at no additional cost to you. This does not influence the content or our evaluation of the products and services discussed.

admin

Author of practical guides to dropshipping, ecommerce, automation, and growing an online business.