Cullen International's latest Benchmark analyses how 19 EU countries are preparing to implement the Cyber Resilience Act (CRA). It tracks national laws, designated authorities, incident notification bodies and penalties ahead of the regulation’s application dates.
Key findings
Implementation remains at an early stage in most surveyed countries: Finland and Slovakia are the only countries that have adopted implementing legislation, while draft laws have been proposed in the Czech Republic, France, Germany, the Netherlands, Spain and Sweden.
Member states are taking different approaches to market surveillance: most countries that have proposed implementing legislation designate a single market surveillance authority, while the Czech Republic proposes 12 sectoral authorities.
Manufacturers will need to comply with incident and vulnerability notification requirements from 11 September 2026, before the CRA enters into full application on 11 December 2027.
Why it matters
The CRA will introduce EU-wide cybersecurity requirements for products with digital elements, but national implementation will determine which authorities enforce the rules and how penalties are applied. This is relevant for manufacturers, importers, distributors, cybersecurity authorities and conformity assessment bodies.
What the content covers
The Benchmark tracks proposed and adopted national laws implementing the CRA in 19 EU countries, including designated market surveillance authorities, notifying authorities, CSIRTs and national penalties regimes.
Background
The Cyber Resilience Act establishes baseline cybersecurity requirements for hardware and software products with digital elements, from the design phase through expected use. As an EU regulation, it will apply directly across EU member states without national transposition, but member states must still designate enforcement authorities, incident notification bodies and penalty regimes. The full regulation will apply from 11 December 2027, while rules on notification of actively exploited vulnerabilities and severe incidents will apply from 11 September 2026.
Scope
Region: Europe
Countries covered: 19 EU countries (including Finland, Slovakia, the Czech Republic, France, Germany, the Netherlands, Spain, Sweden, Italy and Austria)
Policy area: Cybersecurity and product regulation
Source type: Benchmark
Published: 16 July 2026
more news
17 August 26
Most countries in the Americas region tax over-the-top services
This Cullen International benchmark shows for each surveyed country whether OTT video and music service providers are subject to any regulation and/or taxation; or if there are national plans to adopt applicable regulations or taxes.
13 August 26
Countries in the Americas generally do not require licensing for social media platforms
Cullen International's benchmark shows what regulatory regimes, if any, apply to social media networks in each of the surveyed countries. It includes general rules, as well as what forms of content are restricted or forbidden on social media platforms, and any applicable safe harbours.
07 August 26
Global trends in data centres and cloud service providers
An updated Global Trends benchmark analyses policies and regulations of relevance for data centre and cloud service providers (CSPs) across 14 jurisdictions. It found there are different approaches worldwide on aspects such as licensing, ownership restrictions, cloud-related competition policies, cybersecurity and use of subsidies in the cloud sector.