Cullen International's latest Benchmark analyses how 19 EU countries are preparing to implement the Cyber Resilience Act (CRA). It tracks national laws, designated authorities, incident notification bodies and penalties ahead of the regulation’s application dates.
Key findings
Implementation remains at an early stage in most surveyed countries: Finland and Slovakia are the only countries that have adopted implementing legislation, while draft laws have been proposed in the Czech Republic, France, Germany, the Netherlands, Spain and Sweden.
Member states are taking different approaches to market surveillance: most countries that have proposed implementing legislation designate a single market surveillance authority, while the Czech Republic proposes 12 sectoral authorities.
Manufacturers will need to comply with incident and vulnerability notification requirements from 11 September 2026, before the CRA enters into full application on 11 December 2027.
Why it matters
The CRA will introduce EU-wide cybersecurity requirements for products with digital elements, but national implementation will determine which authorities enforce the rules and how penalties are applied. This is relevant for manufacturers, importers, distributors, cybersecurity authorities and conformity assessment bodies.
What the content covers
The Benchmark tracks proposed and adopted national laws implementing the CRA in 19 EU countries, including designated market surveillance authorities, notifying authorities, CSIRTs and national penalties regimes.
Background
The Cyber Resilience Act establishes baseline cybersecurity requirements for hardware and software products with digital elements, from the design phase through expected use. As an EU regulation, it will apply directly across EU member states without national transposition, but member states must still designate enforcement authorities, incident notification bodies and penalty regimes. The full regulation will apply from 11 December 2027, while rules on notification of actively exploited vulnerabilities and severe incidents will apply from 11 September 2026.
Scope
Region: Europe
Countries covered: 19 EU countries (including Finland, Slovakia, the Czech Republic, France, Germany, the Netherlands, Spain, Sweden, Italy and Austria)
Policy area: Cybersecurity and product regulation
Source type: Benchmark
Published: 16 July 2026
For more information and access to the full benchmark, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
09 October 26
Four LATAM countries address connectivity gaps
Cullen International’s latest LATAM Telecoms Update highlights policy developments over the past three months affecting the regulation of radio spectrum, wholesale networks and consumer protection in six markets in the region: Argentina, Brazil, Chile, Colombia, Mexico and Peru.
08 October 26
Many European countries consider banning minors from accessing social media
Cullen International has just published a new version of its benchmark which tracks the current debates/ initiatives on banning access to social media to protect minors online in Europe.
05 October 26
Ireland, the Netherlands and France account for the highest sum of data protection fines against large digital platforms
Our latest benchmark tracks fines imposed on large digital platforms by data protection and other supervisory authorities in 19 European countries since May 2018. It covers GDPR and e-Privacy Directive infringements and identifies whether the GDPR consistency mechanism was used in cross-border cases.