Abstract: This practical compliance handbook provides an 18-month execution roadmap for hardware and software manufacturers under Regulation (EU) 2024/2847 (Cyber Resilience Act). It clarifies the scope of Products with Digital Elements (PwDE), outlines the secure-by-design lifecycle obligations, and establishes compliance workflows for mandatory 24-hour early warning and 72-hour detailed incident reporting via ENISA's Single Reporting Platform starting September 11, 2026. The guide incorporates Romania-specific enforcement guidance through DNSC and CYBERFORT, Software Bill of Materials (SBOM) generation standards, and conformity assessment checklists.

What Every EU Company Needs to Know Before September 2026. Free Guide by Mararu & Mararu Lawyers • March 2026

Executive Summary

Many organisations still think the Cyber Resilience Act (Regulation (EU) 2024/2847) is a “2027 problem”. The reality is far more urgent.

From 11 September 2026 – only six months from now – every manufacturer of products with digital elements must report actively exploited vulnerabilities and severe security incidents through ENISA’s Single Reporting Platform. Deadlines are strict: 24-hour early warning + 72-hour detailed notification.

The CRA (Regulation (EU) 2024/2847) mandates secure-by-design, lifecycle vulnerability handling, CE marking, and full transparency.

This free guide from Mararu & Mararu Lawyers gives you exactly what you need right now: plain-language explanations, a practical checklist roadmap, Romania-specific guidance, and the most common pitfalls to avoid.

Take action before the September 2026 cliff

Book your free 15-minute CRA Compliance Quick Scan (in Romanian or English). We will review your product portfolio and flag your biggest exposure areas.

Book your free 15-minute scan →

CRA in Plain Language

The CRA (Regulation (EU) 2024/2847) is a Regulation – directly applicable in every Member State, including Romania, with fines up to €15 million or 2.5% of global turnover.

In scope: Products with digital elements (PwDE) Out of scope
  • IoT devices, smart cameras, wearables, routers
  • Industrial PLCs and control systems
  • Consumer software and apps sold commercially
  • Connected toys, smart home appliances
  • Legacy products already on the market
  • Medical devices (MDR/IVDR)
  • Motor vehicles
  • Radio Equipment Directive (RED) products with specific rules
  • High-risk AI systems (separate rules)
  • Purely offline products

Who bears the CRA obligations?

  • Non-EU manufacturers have direct obligations: reporting actively exploited vulnerabilities, maintaining SBOM (Software Bill of Materials), publishing a CVD (Coordinated Vulnerability Disclosure) policy, etc.
  • EU importers (the Romanian or European company that brought the products to market) are jointly and severally liable and must ensure the products comply with CRA (Articles 20–22 of the Regulation).

If the importer does nothing, they risk fines and product withdrawal from the market by ANPC.

This rule applies to all products already sold in Romania or the EU, including those from China, Turkey, USA, etc.

Quick decision tree – Is my product in scope?

  1. Is it placed on the EU market commercially? → Yes
  2. Does it contain software or firmware? → Yes
  3. Can it connect (directly or indirectly) to any network/device? → Yes
  4. → Almost certainly in scope.

The three core obligations

01 Secure by design & default (full from Dec 2027) – risk assessment, secure lifecycle, automatic updates.
02 Vulnerability handling – documented CVD policy, SBOM (even lite version), coordinated disclosure.
03 Transparency & reporting (starts 11 September 2026) – report to ENISA, inform users, CE marking.

Step-by-Step Implementation Roadmap (18-month practical checklist)

PHASE 1 – NOW TO 30 JUNE 2026 (PREPARATION FOR REPORTING)

  • ☐ Inventory all PwDE on the EU market (including legacy)
  • ☐ Appoint internal CRA responsible person
  • ☐ Draft and publish Coordinated Vulnerability Disclosure (CVD) policy
  • ☐ Start building SBOM-lite
  • ☐ Conduct initial cybersecurity risk assessment
  • ☐ Define 24h/72h incident response process
  • ☐ Train development and support teams

PHASE 2 – FROM 11 SEPTEMBER 2026 (REPORTING LIVE)

  • ☐ Register on ENISA Single Reporting Platform
  • ☐ Report actively exploited vulnerabilities within 24 hours
  • ☐ Report severe incidents within 72 hours
  • ☐ Provide users with clear mitigation instructions

PHASE 3 – FULL COMPLIANCE BY 11 DECEMBER 2027

  • ☐ Complete conformity assessment
  • ☐ Affix CE marking + issue Declaration of Conformity
  • ☐ Implement automatic security updates
  • ☐ Maintain technical documentation for 5 years

Romania-Specific Considerations

Romania is actively leading CRA implementation. The CRA EUROPE 2026 conference (Bucharest, March 2026) brought together 150+ European leaders.

Key Authorities

  • DNSC – main contact for reporting and market surveillance
  • ANPC – general market surveillance
  • ASF & BNR – for financial-sector clients (DORA overlap)

Free Support

CYBERFORT Project – free tools and training for SMEs

Common Pitfalls & How to Avoid Them

Pitfall Why it hurts How to avoid
Thinking you have time until 2027 Reporting obligation starts Sep 2026 for legacy products Build 24h/72h process NOW
No CVD policy published Fines + reputational damage Publish simple policy this month
Ignoring supply chain You remain liable for third-party components Require SBOM from all suppliers

How Mararu & Mararu Lawyers Can Help

Book your free 15-minute CRA Compliance Quick Scan.

Book your free 15-minute scan now →
Resources & Further Reading

Ready to turn CRA compliance into a competitive advantage?

Contact Mararu & Mararu Lawyers today

Author

Amala Mararu

Founder, Senior Partner

Amala Mararu, senior Romanian lawyer for foreign investors specializing in tech, space, and art law in Bucharest.
Amala Mararu
amala.mararu@mararu.com
+4 (031) 421 5150
Founder, Senior Partner
https://x.com/amala_mararu
https://www.linkedin.com/in/amalamararu/
Amala Mararu, senior Romanian lawyer for foreign investors specializing in tech, space, and art law in Bucharest.
Biography
Biography
Icon

Amala M. Mararu is a High Court-qualified Romanian attorney and strategic legal advisor with over 25 years of legal practice representing multinational corporations, major industry associations, and prominent industrial clients in complex cross-border transactions, high-stakes litigation, and with regulatory and policy reform.

Her core practice encompasses AI and data privacy, space technology and IP, cybersecurity, commercial disputes, cultural heritage assets, digital media, and environmental law.

She has directed landmark natural-resources infrastructure concessions valued at $266 million, orchestrated large-scale telecom restructurings involving hundreds of employees and sites, and secured precedent-setting victories before the High Court of Cassation and Justice. As legal advisor to Romania’s largest employers’ confederation on national Social Dialogue Committees, she helped shape foundational labor and insolvency policy legislation.

Amala is fluent in English – full business and legal proficiency, and Romanian (native).

Recent publications

View All
View All
Icon

Cultural Heritage in Orbit: Legal Status of Historic Space Objects, Artifacts, and the Emerging Framework for Protection Beyond Earth

Historic space objects already sit under jurisdiction, ownership and due regard. The task is to give operators predictable parameters for working near them, not to freeze exploration. This article maps OST Articles II, VIII and IX, Artemis Accords Section 9, national licensing practice, and the proposed EU Space Act, and sets out steps available now.

Ready for Enterprise Legal Support and Representation in Romania?

Partner with Mararu & Mararu SCA to secure and protect your brand, people, capital, assets and business operations. Contact us to discuss how we can assist with your specific requirements.

Get a Quote Now
Get a Quote Now
Icon