A French-speaking SME that manufactures machines, sensors or electronic enclosures has spent the last twenty years managing the safety of its products in the classic sense: not injuring the user, not catching fire, withstanding electromagnetic disturbances. The European Union is now adding a dimension, cybersecurity, and it is adding it in the same place as the others: in the conditions for accessing its market.

This is Regulation (EU) 2024/2847, known as the Cyber Resilience Act or CRA. It entered into force on 10 December 2024. Its first operational deadline falls on 11 September 2026, in less than two months.

Why does a European regulation concern you from Switzerland?

Switzerland is not a member of the European Union. The CRA is therefore not Swiss law, no Swiss authority will come and check its application at your premises, and there is no obligation to comply with it in order to sell in Switzerland.

In practice, this changes very little, for a simple reason. The regulation does not target European companies, it targets products placed on the market of the Union. The connecting criterion is the product’s destination, not the manufacturer’s registered office. A company in Bulle that supplies machines to a German customer is a manufacturer within the meaning of the regulation, exactly like a German company.

This is the same logic as the CE marking you already know for machine safety or electromagnetic compatibility. The CRA joins this family. The CE marking you affix will, in due course, also attest to compliance with cybersecurity requirements.

Do not rely on your importer

Some Swiss SMEs think their European distributor or importer will absorb compliance. The regulation does impose duties on importers and distributors, but they mainly consist of checking that the manufacturer has done its job: CE marking present, documentation available, contact details provided. Design requirements, technical documentation and vulnerability reporting remain with you. An importer who discovers that your product is not compliant is obliged not to place it on the market.

What is a “product with digital elements”?

The phrase sounds administrative, but the reality is very concrete. The regulation targets any product, hardware or software, that has a data connection, direct or indirect, with a device or a network.

Translated into objects you may manufacture:

  • a production machine whose controller reports production data;
  • a temperature, level or vibration sensor that transmits wirelessly;
  • a scale, pump or doser controlled by a touch screen;
  • an electronic lock or access control system;
  • a telemetry unit installed on a vehicle or an installation;
  • a mobile app or business software sold to customers;
  • a consumer connected device, from a thermostat to a fitness tracker.

The connection can be indirect. A device that has no network card but that is updated via a USB key or configured via Bluetooth from a phone falls within scope. The fact that the product is never connected to the internet is not enough to exclude it.

Some families are excluded because they already fall under other European texts: medical devices, vehicles and aeronautics in particular. If you are in one of these fields, cybersecurity is required of you by your sector-specific regulation, not by the CRA.

Am I affected? Four cases of Swiss SMEs

SituationAffected by the CRA?
You manufacture connected industrial machines and export 40% to Germany and FranceYes, as a manufacturer, for products intended for the EU market
You develop management software sold on subscription to Swiss and French customersYes for making it available in the EU, including for remote data processing solutions linked to the product
You manufacture mechanical parts with no electronics or software whatsoeverNo, there is no digital element
You sell a connected sensor only in Switzerland, with no customer in the EUNot directly, but your exporting industrial customers will ask you for these guarantees

The last case deserves emphasis, because it affects many French-speaking subcontracting SMEs. Even if you do not export yourself, your customer who exports will have to document the security of its finished product, and therefore of your components. The pressure moves down the value chain. This is exactly the mechanism described in our article on supply chain attacks, but applied this time to compliance rather than to the threat.

The timeline: what falls due when

Three dates structure the regulation. The first is already behind us, the second is imminent, the third requires starting now.

DateWhat appliesWhat it means for you
10 December 2024Entry into force of the regulationThe countdown starts, no obligation yet active for manufacturers
11 June 2026Chapter on the notification of conformity assessment bodiesNotified bodies can be designated, the assessment ecosystem is put in place
11 September 2026Reporting obligations (Art. 14)You must report actively exploited vulnerabilities and severe incidents, within very short deadlines
11 December 2027General application of the regulationEssential cybersecurity requirements, technical documentation, conformity assessment, CE marking
The September 2026 deadline is the one people underestimate

Many companies remembered "end of 2027" and think they have time. Yet the reporting obligation applies more than a year before the rest. It does not require redesigning your products, it requires an internal organisation: knowing who receives the information, who decides, who drafts and who sends, within 24 hours. A company that does not have this process on 11 September 2026 will be in default the day a flaw in its product is exploited.

The manufacturer’s concrete obligations

The regulation asks for two things of a very different nature: securing the product, and remaining present after the sale.

Designing the product securely. A cybersecurity risk assessment must accompany the design, development and production. The product must be delivered without any known exploitable vulnerability, in a secure default configuration, with adequate access control, encryption of sensitive data, and a reduction of unnecessary attack surfaces. These requirements are set out in Annex I of the regulation.

Documenting. Technical documentation must exist and be capable of being presented. It notably includes an inventory of the software components used, what the industry calls a software bill of materials. In concrete terms, you must know which libraries and third-party components run in your product. Many SMEs discover at this stage that they do not know, because the firmware was developed by a subcontractor.

Ensuring support over time. The regulation provides for a support period during which vulnerabilities must be effectively handled, and sets in principle a duration of at least five years, unless the product is clearly intended for a shorter period of use. This duration must be communicated clearly at the time of purchase. For an industrial SME, this is often the heaviest point: you must plan the capacity to produce and distribute patches for years.

Reporting. From 11 September 2026, an actively exploited vulnerability in one of your products, or a severe incident affecting their security, must be the subject of an early warning within 24 hours, a fuller notification within 72 hours, and then a final report. Reporting is done through a single European platform, to the competent CSIRT, with transmission to ENISA.

Publish a security contact address

The least costly and most useful measure: create an address such as [email protected], publish it on your website and in your manuals, and make sure someone reads it. This is how a researcher, a customer or an integrator will warn you of a flaw. Without this channel, you will learn of the problem from the press or from a furious customer, and your 24-hour deadline will already have started running without your knowledge.

Where to start, realistically

You do not need a complete compliance project this summer. You need three things before September, and a trajectory for 2027.

  1. Draw up the list of your products that contain software and note for each one whether it is sold in the EU, directly or through a customer. A one-page table is enough to reveal the real scale of the issue.
  2. Open the reporting channel and name a person in charge. This is the prerequisite for the September 2026 deadline.
  3. Write the one-page response procedure: who qualifies the information, who decides that it is an active exploitation, who drafts the alert, who sends it, within what deadline.
  4. Ask your software subcontractors for the inventory of components they use in your firmware. Put it in the contract for future developments.
  5. Identify the category of your products (ordinary, important class I or II, critical), since it determines whether a third-party assessment will be necessary. This is the point to have validated by a specialist.
  6. Cost the support period you are able to sustain, and build it into your prices and contracts rather than having it imposed on you.

The good news is that this work largely overlaps with the security hygiene expected of any company, and that internal maturity matters as much as technique. In Switzerland, the National Cyber Security Centre recorded 64,733 voluntary reports in 2025, against 62,954 in 2024 (NCSC, half-yearly report 2025/II, 30 March 2026): the pressure on companies is not letting up, and a manufacturer that already knows how to handle an incident internally will find it easier to handle one at a customer’s site.

Nothing in this article constitutes legal advice. The exact qualification of your product, its category and the regime applicable to your existing range generally need to be validated with a product compliance specialist.

To gauge your company’s maturity in a few minutes, the cyber check-up gives you a score and your three priorities. The “am I affected by the CRA?” test deals specifically with the question of scope. Manufacturers of connected radio equipment should also look at the EN 18031 standards, and industrial companies at IEC 62443. Your Swiss obligations remain fully in force in parallel, starting with your FADP obligations. All applicable texts are grouped in the Regulations pillar.