Regulation (EU) 2024/2847 imposes cybersecurity requirements on anyone placing products with digital elements on the European market, a category that includes software distributed as a product and not only connected devices. The perimeter differs from NIS2, which targets essential and important entities: here the criterion is placing the product on the market, and this brings within scope many software houses and vendors that fall outside the NIS2 perimeter. The calendar is staggered: the regulation has been in force since 10 December 2024, Chapter IV on market surveillance authorities applies from 11 June 2026, the reporting obligations of Article 14 from 11 September 2026, and the essential requirements of Annex I from 11 December 2027.
The part already in force changes teams' daily work. Anyone who becomes aware of an actively exploited vulnerability must submit an initial alert within twenty-four hours, a full notification within seventy-two hours and a final report within fourteen days of a corrective measure becoming available; for a severe incident the initial sequence is identical and the final report is due within one month. The channel is the Single Reporting Platform managed by ENISA, with a single submission addressed to the CSIRT designated as coordinator, which in Italy operates within the National Cybersecurity Agency. The obligation also applies to products already made available on the market before 11 December 2027.
Full application of the CRA falls nine days after the AI Act obligations for the high-risk systems of Annex III. For those developing or integrating software with AI components intended for the European market, this is effectively a single preparation window, with evidence that overlaps substantially: system registers, risk management, version traceability, supplier requirements. In the rating this evidence is assessed once, without opening two parallel workstreams that ask the same documents of two different parts of the company.
On the proposal front, the cyber package presented by the Commission on 20 January 2026 would replace the 2019 Cybersecurity Act with a new regulation (COM(2026) 11) and would amend NIS2 in a targeted way (COM(2026) 13). The block that most directly affects technology buyers concerns the ICT supply chain: the Commission could designate third countries as raising cybersecurity concerns, classify vendors controlled by them as high risk and impose equipment phase-out periods. The text is under negotiation, and in the progress report of 22 May 2026 the Council asked for clarifications on the identification methodology, so it should be treated as a signal of direction rather than an imminent obligation. Supply decisions taken in the coming months will still play out within that framework.