---
title: "Cyber Resilience Act: The first obligations take effect in September 2026"
description: Starting in September 2026, the Cyber Resilience Act will require digital products sold in Europe to meet new cybersecurity requirements.
image: https://blog.pradeo.com/hubfs/Template%20article%20(26)-1.png
---

[![pradeo_logo_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Mobile Application Security](https://blog.pradeo.com/topic/mobile-application-security) [News](https://blog.pradeo.com/topic/news)

# Cyber Resilience Act: The first obligations take effect in September 2026

![Picture of Clara Campos](https://blog.pradeo.com/hubfs/1711636314862%20(1).jpg)

 By [Clara Campos](https://blog.pradeo.com/author/clara-campos) on May, 7 2026

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![](https://blog.pradeo.com/hubfs/Template%20article%20(26)-1.png)

###### The [Cyber Resilience Act (CRA), European regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng?eliuri=eli%3Areg%3A2024%3A2847%3Aoj&locale=en), was implemented on December 10th 2024. Its first binding requirements will come into effect on September 11th 2026, with full implementation scheduled for December 2027.

###### For the first time, the European Union is imposing mandatory cybersecurity requirements on all products containing digital components, both hardware and software, placed on the European market.

## A Regulation That Targets Digital Products

Unlike the [NIS2 directive](https://blog.pradeo.com/nis2-directive-what-obligations-apply-to-mobile-applications-and-usage), which focuses on the security of organisations, the CRA applies to the products themselves. Its scope is very broad: applications, connected devices, software, firmware, hardware components, any product integrating digital elements is covered, with the exception of pure cloud services (covered by NIS2), medical devices and vehicles, which are already governed by specific regulations.

The Cyber Resilience Act (CRA) classifies products into [three levels of severity](https://digital-strategy.ec.europa.eu/en/policies/cra-summary), which determine the applicable conformity assessment procedure: "default" products (self-assessment), "important" products of Class I and II (stricter assessment, potentially requiring a third party), and "critical" products (mandatory European certification).

Manufacturers, software publishers, application developers and hardware manufacturers [bear most of the obligations](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act). Importers and distributors are also affected, with conformity verification obligations before placing products on the market.

Penalties are aligned with those of the GDPR: up to €15 million or 2.5% of annual global turnover for non-compliance with essential cybersecurity requirements. Market surveillance authorities may also order the withdrawal of non-compliant products from the European market.

 

## Key Requirements and How Yagaan Addresses Them

[Annex I of the Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng?eliuri=eli%3Areg%3A2024%3A2847%3Aoj&locale=en) defines the requirements that products must meet. They must for instance be placed on the market without any known exploitable vulnerability and with a secure default configuration. Several of these requirements directly relate to application security, the core expertise of [Yagaan, powered by Pradeo.](https://pradeo.com/en/yagaan-application-security/)

 

###### Security by Design

> The CRA requires that cybersecurity be integrated from the design phase. A product must be placed on the market without any known exploitable vulnerability, with a secure default configuration, robust authentication mechanisms and a minimised attack surface. Security is no longer an add-on at the end of the cycle, it becomes a legal obligation from the very start of development.

Yagaan addresses this requirement with its [Static Application Security Testing (SAST)](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/) solution, which integrates directly into CI/CD pipelines to analyse source code at every iteration, identifying vulnerabilities before production. The tool uses machine learning to prioritise flaws by their real criticality and provide contextual remediation guidance.

 

###### Vulnerability Management and 24-Hour Reporting

> The CRA requires a structured process for detecting, correcting and communicating vulnerabilities throughout the entire product lifecycle, or for a minimum of five years after market placement. From 11 September 2026, manufacturers will be required to notify ENISA of any actively exploited vulnerability within 24 hours of discovery, provide a full report within 72 hours and a final report within 14 days.

Yagaan's [In-App Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/) directly addresses this requirement by detecting exploitation attempts on the deployed application in real time, enabling the identification and neutralization of attacks in production.

And before production, integrating [Yagaan Static Application Security Testing (SAST)](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/) into the development cycle enables the detection of vulnerabilities in the source code, in line with this obligation to maintain security. By identifying and fixing flaws during development rather than later, software vendors reduce the risk of having to report exploitable vulnerabilities after the product has been released. 

 

###### Software Component Traceability

> The CRA requires the production of an SBOM (Software Bill of Materials), a comprehensive inventory of all software components integrated into the product, including third-party libraries and open-source dependencies. This SBOM must be available to surveillance authorities on request.

For mobile applications, which are digital products within the meaning of the CRA, [Yagaan Mobile Application Security Testing (MAST)](https://pradeo.com/en/solutions/mobile-application-security/mobile-application-security-testing/)enables security audits from their binary code (Android and iOS), identifying integrated third-party components and their vulnerabilities. This covers both internally developed applications and those from suppliers, contributing to the traceability required by the regulation.

 

###### Protection Against Tampering and Attacks in Production

> The CRA requires that digital products minimise their attack surface and be protected against unauthorised access.

Yagaan contributes to these requirements with two complementary solutions. [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)protects the application code against reverse engineering, cloning and tampering, concretely reducing the attack surface exploitable by an attacker. [In-App Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/) ensures real-time application protection during execution, detecting and neutralising attacks directly on the device.

 

## Time to Prepare

The first binding Cyber Resilience Act deadline is just months away. For application developers, compliance requires integrating security into the development cycle and structured vulnerability management in their applications.

Yagaan, powered by Pradeo, supports organisations in this process by providing a complete application security suite, from development to execution.

###### About The Author

[More from this author](https://blog.pradeo.com/author/clara-campos)

![](https://blog.pradeo.com/hs-fs/hubfs/1711636314862%20(1).jpg?height=100&name=1711636314862%20(1).jpg)

###### Clara Campos

#### Recommended articles

[![Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/hubfs/Template%20article%20(32)-1.png)](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

###### [Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 - June 18, 2026

[![What is Application Shielding?](https://blog.pradeo.com/hubfs/Template%20article%20(6)-1.png)](https://blog.pradeo.com/what-is-application-shielding)

###### [What is Application Shielding?](https://blog.pradeo.com/what-is-application-shielding)

 - March 5, 2026

#### Recommended articles

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 - 7 May, 2026

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 - 7 May, 2026

[2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 - 7 May, 2026

[Signal: a phishing campaign targets users' backups](https://blog.pradeo.com/signal-a-phishing-campaign-targets-users-backups)

 - 7 May, 2026

[Morpheus Spyware: a fake Android application used for smartphone surveillance](https://blog.pradeo.com/morpheus-spyware-a-fake-android-application-used-for-smartphone-surveillance)

 - 7 May, 2026

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (25)](https://blog.pradeo.com/topic/news)
- [Partners (24)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Clara Campos"
  },
  "dateModified" : "May 7, 2026, 7:34:18 AM",
  "datePublished" : "2026-05-07 07:34:18",
  "description" : "Starting in September 2026, the Cyber Resilience Act will require digital products sold in Europe to meet new cybersecurity requirements.",
  "headline" : "Cyber Resilience Act: The first obligations take effect in September 2026",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Template%20article%20%2826%29-1.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```