Cyber Resilience Act and Crypto-Agility: The Product Duty Nobody Priced In

The EU Cyber Resilience Act is the first horizontal law to put binding cybersecurity requirements on virtually every product with digital elements sold in the EU, and most manufacturers are planning around the wrong date. The instinct is to treat 11 December 2027 — full application — as the deadline. But the operationally demanding obligation lands well before that, and underneath the headline requirements sits a duty most firms have not priced in at all: the product has to be able to update its own cryptography over its lifetime.

The date that actually bites first

The CRA (Regulation (EU) 2024/2847) entered into force in December 2024, but its reporting obligations under Article 14 apply from 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform on a hard cascade: an early warning within 24 hours, a fuller notification within 72 hours, and final reporting within 14 days of a fix. Crucially, this applies to products already on the market, including legacy ones — so it is not limited to new designs. To report a vulnerability, you have to know which components are in your product, which is why a software bill of materials becomes a practical necessity well before its formal 2027 deadline. Non-compliance carries fines up to €15 million or 2.5% of worldwide turnover.

The crypto-agility duty hiding in “security by design”

The CRA’s full obligations from December 2027 require security by design, vulnerability handling throughout the lifecycle, and a minimum support period. Read together, these amount to a requirement most product teams have not costed: the ability to change cryptographic algorithms in a deployed product without replacing it. A product expected to remain secure across a support period measured in years cannot rely on cryptography that may be deprecated within that window — and with post-quantum migration on exactly that horizon, a product shipped today with hard-coded, non-updatable crypto is a product that cannot meet its own lifecycle security duty. Crypto-agility stops being an architecture nicety and becomes a compliance requirement by implication.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

What product teams should do now

  • Inventory your products and components. Know what you ship into the EU, in what role (manufacturer, importer, distributor), and what is inside each product — the SBOM is the foundation for everything else.
  • Stand up vulnerability intake and the reporting cascade before September 2026. The 24/72-hour clock is unforgiving, and it applies to legacy products already in the field.
  • Design for cryptographic updates. Build products so algorithms can be replaced by update, not by re-manufacture. This is the durable capability that satisfies the lifecycle duty and survives the post-quantum transition.
  • Push it into your supply chain. Your product’s compliance depends on components you did not write; supplier contracts and diligence need to reflect the CRA.

The CRA rewards the firm that treats it as a product-engineering programme with a September 2026 first deadline, and punishes the one that files it under “2027.” The crypto-agility duty in particular is the kind of requirement that is cheap to design in and very expensive to retrofit across a fielded product line.

Who this is for

This reading is for:

  • CTOs and product leaders shipping connected products or software into the EU
  • Compliance leads mapping the CRA against existing security work
  • Firms that assumed the CRA was a 2027 problem
  • Boards of product companies weighing the cost of security-by-design

Sixteen Pillars helps product teams stand up the CRA reporting cascade before September 2026 and design the crypto-agility that the lifecycle security duty requires. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming