From 11 September 2026, manufacturers selling connected products into Europe must report actively exploited vulnerabilities and severe security incidents under the Cyber Resilience Act. According to Make UK data, nearly a third of British manufacturers have already experienced a cyberattack or supply chain breach — and fewer than half have a response plan.
The September milestone is the CRA's second major compliance trigger, following the initial phased rollout. It specifically targets manufacturers: the obligation to report vulnerabilities and incidents affecting products with digital elements is now a legal condition, not a voluntary practice. IoT manufacturers face particular scrutiny because connected devices sit outside traditional IT perimeters and have become the most frequently targeted attack surface in the UK.
The CRA's essential requirements extend through the full product lifecycle — secure development, vulnerability handling, and mandatory security updates for the product's expected lifetime. That scope means manufacturers cannot treat compliance as a one-time certification exercise. Building in secure-by-default configuration, maintaining a software bill of materials, and committing to post-sale patching are now preconditions for CE marking.
"As the IoT grows in the manufacturing industry, and studies like Make UK's remind us of the growing threats, regulators and businesses must remember that the IoT is not fully resilient if it is not secure. The huge quantities of valuable data IoT devices collect and transport — combined with the fact that many devices sit outside traditional IT perimeters — can make them a vulnerable target worth going after," said Iain Davidson, Head of Product Marketing at Wireless Logic.
"Resilience has always been vital to the IoT, but under the CRA it becomes a strategic imperative, as security will become a legal condition for selling a connected product in Europe. The CRA will officially move cyber security from an afterthought to a design requirement, from the drawing board through to end of support. Manufacturers must now build in secure-by-default configuration, vulnerability handling processes and a software bill of materials before a product ever reaches CE marking — and they must keep supporting it, not just ship and move on," Davidson added.
For manufacturers operating across the UK and EU, the reporting obligation now runs in parallel with existing UK PSTI requirements. The administrative and technical demands of dual reporting are expected to accelerate consolidation around vendors offering integrated compliance tooling.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter