IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

Does the Cyber Resilience Act apply to what I sell?

The Cyber Resilience Act is a European law about products, not about companies. That is the part most people get wrong. It never asks how many staff you have. It asks what you sell. This guide walks you through the check in plain words, so you can answer yes or no today.

The two questions that decide it

Work through both. You only need a pen.

1. Does the thing you sell have digital elements?

Two things have to be true together. It is a software or hardware product, and its normal or expected use includes a data connection to a device or a network. A phone app counts. A machine with a controller that talks to other equipment counts. A doorbell with a wifi chip counts. A steel bracket with no electronics does not. Article 2(1) draws the line here.

2. Do you sell it under your own name or logo?

If your name or your logo is on the box, the law calls you the manufacturer. It does not matter who wrote the code or who built the case. Two articles do that job, so name the right one. Article 3(13) is the case where you had the product made for you. Article 21 is the case where you buy a finished product and resell it under your own name or logo, and it hands you the same manufacturer duties.

Two yes answers mean you are in scope. One no means you are not the manufacturer of that product. Do the check per product, not per company.

You bought it from someone else and put your name on it

This is the case people miss. You did not design it. You did not write a line of its code. You buy it, you print your logo on it, you sell it. Under this law that makes you the manufacturer. Here is the exact wording:

"manufacturer" means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge.

Regulation (EU) 2024/2847, Article 3(13), English text of the Official Journal.

The middle part is the one that catches you. Having a product made for you, and then selling it under your own name, puts you in the same box as the company that built it. The last part matters too. Giving it away free does not get you out. If instead you buy a finished product from a supplier and resell it with your own logo on it, Article 21 does the same job: an importer or a distributor that puts a product on the market under its own name or trademark is treated as the manufacturer and carries the Article 13 and Article 14 duties.

One trap worth naming

Some articles say own-branding is covered by Article 22. That is wrong. Article 22 is about somebody who substantially changes a product and then sells it. Putting your logo on a product you did not change is Article 3(13) if you had it made for you, and Article 21 if you bought it finished and resold it. Either way it is not Article 22. If a supplier or an adviser cites Article 22 at you for this, they have the wrong article.

Where it stops

The law has edges. These are the two that matter most:

  • You sell it under the maker's brand. Their name is on it, so the manufacturer duty is theirs. You may still have duties as an importer or a distributor, but you are not the manufacturer.
  • What you sell has no software and no connection. A hand tool, a bag of screws, a printed sign. There are no digital elements, so this law does not reach it.

The clocks

Three dates. Put them in the calendar now.

11 June 2026 Chapter IV (Articles 35 to 51) already applies. That chapter is about the bodies that assess conformity, so it is mostly not your problem. It is here so you can see the law switches on in stages.
11 September 2026 Article 14 starts. The reporting duty is live from this day.
11 December 2027 The rest of the law starts. Design rules, technical documentation, CE marking (the mark that says a product meets EU rules), security updates.

Once the duty is live, these deadlines run. The first two start when you become aware. The last two start later, and each row says from what.

Within 24 hours An early warning, counted from the moment you become aware. A short note that something is wrong. You are not expected to have the full story yet.
Within 72 hours The detailed notification, also counted from the moment you become aware. What it is, what you know so far, what you are doing about it.
Within 14 days The final report for a vulnerability, counted from the day a fix or a workaround is available.
Within one month The final report for a severe incident. This one is counted from the 72-hour notification, not from a fix.

Two things start the clock. A vulnerability in your product that somebody is actively exploiting, or a severe incident that affects the security of your product. A bug that nobody is attacking does not start it.

You file once, through the single reporting platform set up under the Regulation. Article 14(7) sends the report to the CSIRT that acts as coordinator for the country where your business has its main establishment in the EU, and to ENISA at the same time. A CSIRT is the national team that handles cyber incidents. ENISA is the EU cybersecurity agency. For a Belgian business the CSIRT is normally the CCB, the Centre for Cybersecurity Belgium. If the platform is not reachable when you need it, contact the CSIRT directly and note the time you made contact, because the clock does not stop for a tool that is not ready.

Old products count. Article 69(3) says the Article 14 reporting duty applies to products you put on the market before 11 December 2027 as well, not only to new ones. So the list you make this week has to include what you sold last year.

What happens if you miss it

Failing the Article 14 duty can cost up to 15 million euro, or 2.5 percent of worldwide yearly turnover, whichever is higher. That is Article 64(2).

There is one carve-out for the smallest companies, and it is narrower than it sounds. Article 64(10)(a) says a manufacturer that is a micro or small enterprise cannot be fined for missing the 24-hour deadline. Small here means under 50 staff, with turnover or balance sheet total at or under 10 million euro. Micro means under 10 staff and 2 million euro. Article 3(19) takes those figures from Recommendation 2003/361/EC. Read that twice. The fine for being late is gone. The duty to report is not. You still have to file, and every other part of Article 14 still applies to you in full. One detail worth knowing if you check this yourself. As first published, Article 64(10) said "by way of derogation from paragraphs 3 to 9", which left the Article 64(2) fine untouched. A corrigendum published on 2 July 2025 changed that to "paragraphs 2 to 9", and that is what makes the carve-out actually reach the fine above. Several free copies of the regulation online still show the uncorrected wording.

What to do this week

This takes an hour, and it is worth more than any policy document you could write instead.

  1. List every product you sell that has software in it, or that connects to anything. Include the ones you buy in and badge with your own name.
  2. For each line, answer question two. Is your name on it, or the maker's?
  3. Name one person who would send the report. Write their name and their phone number next to the list.
  4. Ask that person one question. If we found out at four o'clock on a Friday, what would you do in the next 24 hours? If there is no answer, you have found the gap.
  5. Ask your suppliers how they will tell you about a vulnerability in the part they sell you, and how fast. You cannot report in 24 hours what you hear about in three weeks.

A list, a name, and one honest answer. That is the whole job for this week.

If you build or assemble physical products, the production side is covered in cybersecurity for manufacturing, which also explains how NIS2 classifies you. NIS2 and this law are separate: check who must comply with NIS2 for that one.

FAQ

We only sell software, no hardware. Are we in scope?

Yes, if you sell it under your own name and it connects to a device or a network. Article 2(1) covers products with digital elements, and software on its own is one of them.

We give our app away for free. Does that change anything?

No. Article 3(13) ends with the words "whether for payment, monetisation or free of charge". Free does not take you out of scope.

We are five people. Are we too small for this?

No. Article 2 sets the scope by the product, and it holds no staff or turnover threshold at all. Size does change two things, but neither is an exemption. Article 33(5) lets a micro or small enterprise use a simplified format for the technical documentation, and Article 64(10)(a) protects it from a fine for missing the 24-hour deadline. That fine protection only works because a corrigendum of 2 July 2025 corrected Article 64(10); free copies of the law still show the old wording, under which the fine stood. The duty to report stays either way.

Does this replace NIS2?

No. They are two separate laws. NIS2 is about how your organisation is run and it does have size thresholds. The Cyber Resilience Act is about the products you put on the market. You can be caught by both, by one, or by neither.

We stopped selling that product two years ago. Does it still count?

For reporting, yes. Article 69(3) applies the Article 14 duty to products placed on the market before 11 December 2027 too. The other duties in the law only come back to an old product if you substantially change it after that date, under Article 69(2).

Our supplier says Article 22 covers our own-brand products. Is that right?

No. Article 22 is about a person who carries out a substantial modification of a product and then makes it available. Selling an unchanged product under your own name or trademark is Article 3(13) if you had it made for you, or Article 21 if you are the importer or distributor. It is a common mix-up and it points you at the wrong obligations.

Related reading

Not sure which of your products are in scope?

Easy Cyber Protection helps small businesses and their IT partners get the boring parts of compliance in order, in Dutch, French and English.

See how it works

Sources

  1. Primary source: Regulation (EU) 2024/2847 (Cyber Resilience Act), full text in the Official Journal. This is the authoritative text for every article cited on this page: 2, 3(13), 13, 14, 21, 22, 33(5), 64, 69 and 71.
  2. Corrigendum to Regulation (EU) 2024/2847, published 2 July 2025, which changed Article 64(10) from "paragraphs 3 to 9" to "paragraphs 2 to 9". That correction is what makes the micro and small enterprise carve-out reach the Article 64(2) fine.
  3. European Commission, SME definition (Recommendation 2003/361/EC), for the micro and small enterprise figures. Article 3(19) of the Regulation points to this Recommendation for those definitions.
  4. Secondary source, the reading copy those articles were actually read in on 10 September 2026: cyberresilienceact.eu, text of Regulation (EU) 2024/2847. EUR-Lex was not reachable that day, so we used this article-by-article copy instead. Note that this copy still shows Article 64(10) as it read before the corrigendum, which is why the corrigendum is cited above on its own.