Summary
The EU Cyber Resilience Act sets minimum security rules for software, from mobile apps to desktop tools. Software makers must already report serious security problems within 24 hours, and from 11 December 2027 their products need a CE mark. Fines reach €15 million or 2.5% of global turnover. This guide explains who is covered, what secure by design means and the ten steps to take now.
The Cyber Resilience Act: the clock is already ticking
If you sell software in Europe, the Cyber Resilience Act (CRA) applies to you. And it is not coming. It is here.
Since 11 September 2026, software makers must report serious security problems within 24 hours. That covers apps, desktop software and downloadable tools. It also covers products you launched years ago.
The big date is 11 December 2027. From then, your software needs to meet the full security rules and carry a CE mark.
Get it wrong and the fines are steep. The top penalty is €15 million or 2.5% of global turnover, whichever is higher. Regulators can also pull your product off the market.
Here is what you need to know.
Does the CRA cover your software?
Probably. The CRA is an EU law that sets minimum security rules for hardware and software. Think of it as product safety law, but for code.
The test is simple. If you build software and sell it under your name, you are in scope. Paid, free or freemium makes no difference. Apps, desktop clients and firmware all count.
What about the cloud? Pure cloud services follow other rules, such as NIS2. But if your app needs a cloud feature to work, that feature counts as part of the product.
Small firms are not off the hook either. The one concession is that micro and small companies will not be fined for missing the 24 hour warning.
The European Commission published guidance in July 2026 to clear up the grey areas. It is helpful, but it is not law. So keep a record of your reasoning whenever you decide not to report something.
CE marking for software: yes, really
You know the CE mark on your kettle or your child’s toys. From December 2027, it will appear on software too.
To earn it, you need four things. Your software must meet the core security rules. You need technical documents that prove it. You sign a declaration saying it complies. Then you add the CE mark.
The good news? Most software, including mobile apps, can be self-assessed. Only higher-risk products, such as some security and network tools, need an outside body to check them.
The CE mark is a promise to your customers. Make sure you can back it up.
What does secure by design actually mean?
It means you build security in from day one. You do not bolt it on after launch. The CRA wants software that is secure when you design it, secure when it ships and secure for its whole life.
In practice, that comes down to a few habits:
- Lock the doors. Use strong logins and ship with safe settings switched on.
- Fix what breaks. Have a clear way for people to report flaws, and patch them quickly.
- Know your ingredients. Keep a software bill of materials (SBOM). This is simply a list of every component inside your product. Only 32% of manufacturers have one for every product they ship.
- Stick around. Support your software for at least five years, unless people will use it for less.
One catch. If a flaw comes from someone else’s code inside your product, it is still your problem.
What it means in Ireland
The CRA applies in Ireland right now. It does not need an Irish law to switch it on.
If something goes wrong, you report it through an EU online portal run by ENISA, the EU cybersecurity agency. For Irish firms, the report lands with CSIRT-IE, the incident team inside the National Cyber Security Centre (NCSC). The NCSC has published guidance and runs a CRA helpdesk. But it will not tell you whether your product is in scope. That call is yours.
The reporting deadlines are tight:
- 24 hours to send an early warning.
- 72 hours to send a full report.
- 14 days after a fix is ready to send a final report on a flaw, or one month for a serious incident.
And no, the clock does not stop for the weekend.
Why the CRA makes sense
“For years, customers have carried the risk of insecure software. They buy it, trust it, then find the holes after an attack. The CRA puts that responsibility back on the people who build and sell it. We expect a car to pass safety checks before it leaves the garage. Software runs our hospitals, our banks and our homes, so why should it be any different? For Irish software firms, this is a chance to stand out. A CE mark and a proven incident plan will win customers.”
David McNamara, CEO and Founder, CommSec
Your CRA checklist: ten things to do now
- List your products. Write down every piece of software you sell under your name. Note which ones the CRA covers, and why.
- Check the risk level. Find out if any product needs an outside assessment.
- Pick a decision maker. Name one person who can approve a report at any hour.
- Practise the 24 hour deadline. Run a drill, ideally on a Friday evening.
- Assess the risks. Look at security at the design stage and write down what you decide.
- Build your SBOM. List every component in every product.
- Open the door to reports. Publish a simple way for people to flag security flaws.
- Set safe defaults. No default passwords, strong logins, security switched on.
- Commit to support. Set a support period of at least five years and plan your updates.
- Check your suppliers. Make sure their contracts back up your CRA duties.
With these in place, you are ready to prepare your CE mark paperwork before December 2027.
Find your weak spots before attackers do
At its heart, the CRA is about risk. Your software must ship without known exploitable vulnerabilities, and you must keep testing it for as long as you support it. You cannot fix what you cannot see. That is where CommSec comes in. Our penetration testing puts experts in the attacker’s seat to find the flaws that matter before release. CheckScan+ managed vulnerability scanning keeps watch between tests, so new weaknesses are caught early. And our new Perimeter external exposure scan gives you a fast view of what your organisation exposes to the internet. Together, they give you early warning, ongoing assurance and the evidence regulators will ask for.
Need a hand? That is what we are here for
The CRA needs legal know-how and technical skill. Most software firms do not have both on the payroll. Writing a policy is the easy part. The hard part is knowing exactly what to do when an incident hits at 2am on a Saturday.
It starts with leadership. CISO as a Service gives you a senior security leader, without the cost of a full-time hire. Your CISO checks your products against the CRA and owns your reporting process.
Next comes planning. Our ISO 27001 specialists build the incident response plan, policies and documentation that prove you are in control. We then run tabletop exercises, so your team rehearses the 24 hour deadline before it counts.
Finally, there is response. An Incident Response Retainer puts our responders on call. If something goes wrong, experts are on hand to contain it and help you report on time.
Do not wait for your first incident to find the gaps. Talk to us about your requirements, and we will help you put a clear roadmap together, so you are ready well before the December 2027 deadline.
Not sure where you stand? Book a CRA readiness review with CommSec. Contact CommSec
Cyber Resilience Act FAQs
When does the CRA apply? Reporting rules started on 11 September 2026. Everything else, including CE marking, starts on 11 December 2027.
How big are the fines? Up to €15 million or 2.5% of global turnover, whichever is higher.
Does the CRA cover mobile apps? Yes. Any software you sell under your own name is covered, even if it is free.
Does the CRA cover SaaS? Pure cloud services follow other rules. But cloud features your product needs to work are covered.
Who do I report to in Ireland? CSIRT-IE at the NCSC, through ENISA’s online reporting portal.
How long must I support my software? At least five years, unless people will use it for less time.
Are small companies exempt? No. Small firms must comply, but they will not be fined for missing the 24 hour warning.
