EU Cyber Regulations and IoT Part 1 - What's Actually Coming
It's not as boring as it sounds
Plus it's going to drive lots of IoT security work and jobs!
One year ago I wrote that 2026 was going to be a big year for IoT security, and that the EU was going to be a big part of why. Well, here we are over halfway through 2026, and the first real deadline is a few weeks out.
"I am not a lawyer" - person who is not a lawyer
I want to be upfront about two things before we get into it. The first is that I'm an engineer and a hacker, not a lawyer (IANAL as they say on reddit), so none of this is legal advice and if you're a manufacturer trying to workout your obligations you probably need to hire someone who actually does this for a living. The second is that I work at a device manufacturer doing internal product security these days, so I'm looking at this from both sides, which has been an interesting change of perspective.
In this blog I'm going to lay out what's actually landing, what's already landed that a lot of people seem to have missed, and why I think this is the most interesting thing to happen to IoT security in the decade or so I've been messing with these devices.
There are two regulations, not one
and they'll overlap for a year +
Most of the conversation I see online is about the Cyber Resilience Act (CRA), and fair enough, it's the big one. But there's a second set of requirements that's been in force for a year already under the Radio Equipment Directive (RED), and I think a lot of people haven't realized yet that it actually applies to them.
Roughly, the RED requirements cover radio equipment that connects to the internet (pretty much all IoT devices fit this). The CRA is much broader and covers basically any product with digital elements sold into the EU, hardware or software, connected or not.
They overlap. From September 2026 to December 2027 both are live at the same time, and then the RED cybersecurity piece gets repealed and folded into the CRA.
RED already happened
August 2025, ICYMI...
The cybersecurity requirements in Articles 3(3)(d), (e) and (f) of the RED have actually been mandatory sinceAugust 2025. They were activated by a delegated regulation back in 2022, originally due to apply in August 2024, then pushed back a year to give everyone more time to get ready.
There are three protection objectives and one harmonized standard for each. EN 18031-1 covers network protection, EN 18031-2 covers personal data and privacy, and EN 18031-3 covers protection against fraud for devices handling money or virtual currency.
Here's the critical part. Those standards were published in the Official Journal with restrictions attached. If a restriction applies to your product then you don't get presumption of conformity from the standard alone, and like the saying goes "close only counts in horseshoes and hand grenades". A partial compliance doesn't count for these. If this happens you lose the self-declaration route and you're going through a Notified Body instead, which is slower and more expensive than most manufacturers were planning for.
I'll dig into this properly in the next blog because it's the most practically useful part of the whole RED story.
The CRA is still the big one...
and September 11th 2026 is coming fast
The Cyber Resilience Act entered into force in December 2024 with a staged rollout, which is the pattern the EU tends to use to give industry time to adjust (or procrastinate...).
The next milestone is September 11 2026. From that date, manufacturers have to report actively exploited vulnerabilities and severe security incidents. The clock is genuinely tight, an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix being available for a vulnerability, or a month for a severe incident. Reports go to the CSIRT where you're established and to ENISA at the same time, through a single reporting platform.
A little over a year later in early December 2027 the CRA applies in full. That's when all the essential requirements kickin, conformity assessment, CE marking, the lot. After that date non-compliant products can't be sold in the EU at all, and fines run up to €15 million. Yes you read that right, huge fines and loss of a large market, the EU doesn't mess around with this stuff.
24 hours is the number I'd point at if you're a manufacturer reading this. If you don't already know what's in your firmware, who owns the response, and who files the report, you cannot hit that window. That's not a compliance problem you can solve in September, it's an engineering and process problem you need to solve now.
Why I think this matters
For both ethical hackers and the manufacturers
For those of us who test (cough hack ethically) these devices, I think this is really good news. Manufacturers are going to need pentests, they're going to need somewhere for researchers to actually send reports, and they're going to need people who understand embedded systems rather than people who only know web apps. The supply for that demand has to come from somewhere.
There's also the thing I mentioned in my 2026 post about the California effect. Plenty of manufacturers will find it easier to build one product to the strictest standard than to maintain separate versions per market, so I expect some of this to leak well outside the EU.
For the people building devices, I'd say the reporting deadline is the wake up call and theDecember 2027 requirements are the actual work. Knowing what's in your firmware, having a way to ship updates, and having a real process for handling a report from a researcher are all things that take longer to build than people think.
I've spent years pulling apart devices running 10 year old kernels with vulnerabilities copied forward from firmware to firmware, and I've been pretty vocal that the industry got away with it for a long time. This is the first thing I've seen with actual teeth behind it.
What's coming in this series
You'll want to check it out, trust me 😄
Next up I'll cover RED in detail, the EN 18031 standards, and the restriction problem that decides whether you can self-declare or you're stuck with a Notified Body. After that I'll get into the September reporting obligations and what you need in place to actually meet them, and then theDecember 2027 essential requirements.
If you want the background on why I thought this year was going to matter, my earlier blog on it is here: https://www.digitalandrew.io/why-2026-will-be-a-big-year-for-iot-security/
Until next time...
Happy Hacking (or compliancinging if that's a thing) - DigitalAndrew