Abstract: This practical compliance handbook provides an 18-month execution roadmap for hardware and software manufacturers under Regulation (EU) 2024/2847 (Cyber Resilience Act). It clarifies the scope of Products with Digital Elements (PwDE), outlines the secure-by-design lifecycle obligations, and establishes compliance workflows for mandatory 24-hour early warning and 72-hour detailed incident reporting via ENISA's Single Reporting Platform starting September 11, 2026. The guide incorporates Romania-specific enforcement guidance through DNSC and CYBERFORT, Software Bill of Materials (SBOM) generation standards, and conformity assessment checklists.
What Every EU Company Needs to Know Before September 2026. Free Guide by Mararu & Mararu Lawyers • March 2026
Executive Summary
Many organisations still think the Cyber Resilience Act (Regulation (EU) 2024/2847) is a “2027 problem”. The reality is far more urgent.
From 11 September 2026 – only six months from now – every manufacturer of products with digital elements must report actively exploited vulnerabilities and severe security incidents through ENISA’s Single Reporting Platform. Deadlines are strict: 24-hour early warning + 72-hour detailed notification.
The CRA (Regulation (EU) 2024/2847) mandates secure-by-design, lifecycle vulnerability handling, CE marking, and full transparency.
This free guide from Mararu & Mararu Lawyers gives you exactly what you need right now: plain-language explanations, a practical checklist roadmap, Romania-specific guidance, and the most common pitfalls to avoid.
Take action before the September 2026 cliff
Book your free 15-minute CRA Compliance Quick Scan (in Romanian or English). We will review your product portfolio and flag your biggest exposure areas.
Book your free 15-minute scan →
CRA in Plain Language
The CRA (Regulation (EU) 2024/2847) is a Regulation – directly applicable in every Member State, including Romania, with fines up to €15 million or 2.5% of global turnover.
| In scope: Products with digital elements (PwDE) |
Out of scope |
- IoT devices, smart cameras, wearables, routers
- Industrial PLCs and control systems
- Consumer software and apps sold commercially
- Connected toys, smart home appliances
- Legacy products already on the market
|
- Medical devices (MDR/IVDR)
- Motor vehicles
- Radio Equipment Directive (RED) products with specific rules
- High-risk AI systems (separate rules)
- Purely offline products
|
Who bears the CRA obligations?
- Non-EU manufacturers have direct obligations: reporting actively exploited vulnerabilities, maintaining SBOM (Software Bill of Materials), publishing a CVD (Coordinated Vulnerability Disclosure) policy, etc.
- EU importers (the Romanian or European company that brought the products to market) are jointly and severally liable and must ensure the products comply with CRA (Articles 20–22 of the Regulation).
If the importer does nothing, they risk fines and product withdrawal from the market by ANPC.
This rule applies to all products already sold in Romania or the EU, including those from China, Turkey, USA, etc.
Quick decision tree – Is my product in scope?
- Is it placed on the EU market commercially? → Yes
- Does it contain software or firmware? → Yes
- Can it connect (directly or indirectly) to any network/device? → Yes
- → Almost certainly in scope.
The three core obligations
| 01 |
Secure by design & default (full from Dec 2027) – risk assessment, secure lifecycle, automatic updates. |
| 02 |
Vulnerability handling – documented CVD policy, SBOM (even lite version), coordinated disclosure. |
| 03 |
Transparency & reporting (starts 11 September 2026) – report to ENISA, inform users, CE marking. |
Step-by-Step Implementation Roadmap (18-month practical checklist)
PHASE 1 – NOW TO 30 JUNE 2026 (PREPARATION FOR REPORTING)
- ☐ Inventory all PwDE on the EU market (including legacy)
- ☐ Appoint internal CRA responsible person
- ☐ Draft and publish Coordinated Vulnerability Disclosure (CVD) policy
- ☐ Start building SBOM-lite
- ☐ Conduct initial cybersecurity risk assessment
- ☐ Define 24h/72h incident response process
- ☐ Train development and support teams
PHASE 2 – FROM 11 SEPTEMBER 2026 (REPORTING LIVE)
- ☐ Register on ENISA Single Reporting Platform
- ☐ Report actively exploited vulnerabilities within 24 hours
- ☐ Report severe incidents within 72 hours
- ☐ Provide users with clear mitigation instructions
PHASE 3 – FULL COMPLIANCE BY 11 DECEMBER 2027
- ☐ Complete conformity assessment
- ☐ Affix CE marking + issue Declaration of Conformity
- ☐ Implement automatic security updates
- ☐ Maintain technical documentation for 5 years
Romania-Specific Considerations
Romania is actively leading CRA implementation. The CRA EUROPE 2026 conference (Bucharest, March 2026) brought together 150+ European leaders.
Key Authorities
- DNSC – main contact for reporting and market surveillance
- ANPC – general market surveillance
- ASF & BNR – for financial-sector clients (DORA overlap)
Free Support
CYBERFORT Project – free tools and training for SMEs
Common Pitfalls & How to Avoid Them
| Pitfall |
Why it hurts |
How to avoid |
| Thinking you have time until 2027 |
Reporting obligation starts Sep 2026 for legacy products |
Build 24h/72h process NOW |
| No CVD policy published |
Fines + reputational damage |
Publish simple policy this month |
| Ignoring supply chain |
You remain liable for third-party components |
Require SBOM from all suppliers |
How Mararu & Mararu Lawyers Can Help
Resources & Further Reading