Cyber Resilience Act UK applicability is the question every British software and hardware business selling into Europe should be asking right now. The short answer is yes: Regulation (EU) 2024/2847 applies to any company, anywhere in the world, that places products with digital elements on the EU market. The European Commission confirms the regulation covers software and hardware placed on the EU market and requires security across the whole product lifecycle. Brexit did not move your customers, and it does not move this law.
This article is the applicability guide in our Cyber Resilience Act series. Our Cyber Resilience Act compliance guide for UK software companies covers the whole regime, our guide to Cyber Resilience Act reporting requirements covers the 24-hour and 72-hour clocks, our Cyber Resilience Act checklist for software developers walks the engineering workstreams, our SBOM requirements guide unpacks the component inventory duty, and our guide to vulnerability handling requirements explains the eight post-sale duties.
Here we answer the question that comes before all of those: does the law reach your UK company at all? We map who is caught, who escapes, the Cyber Resilience Act UK deadlines that bind, how the EU rules sit alongside PSTI and the Cyber Security and Resilience Bill, and what to do about Northern Ireland.
Table of contents
- Cyber Resilience Act UK Applicability: The Short Answer
- Cyber Resilience Act UK Scope: What the Regulation Covers
- Which UK Companies Are Caught
- Which UK Companies Escape
- Cyber Resilience Act UK Timeline: The Dates That Bind
- What Compliance Actually Requires From a UK Company
- Cyber Resilience Act UK Penalties: What Ignoring Them Costs
- CRA vs UK Law: Why PSTI Is Not Enough
- What About Northern Ireland?
- Cyber Resilience Act UK Preparation: Four Practical Steps
- Cyber Resilience Act UK FAQ
- References
Cyber Resilience Act UK Applicability: The Short Answer
The test is market access, not registration
The regulation never asks where your company is incorporated. It asks one question: is a product with digital elements being placed on the EU market? If a Manchester software house licenses its product to customers in Dublin, Paris or Munich, the Cyber Resilience Act UK debate is already over — that product is in scope, and the manufacturer duties attach to the UK company that made it. Incorporation in England, a UK-only workforce and sterling invoicing change nothing.
That is the entire Cyber Resilience Act UK test: market access decides, nothing else.
What “placing on the market” actually means
Placing on the market means making a product available in the EU for the first time in the course of a commercial activity, whether for payment or free of charge. Selling licences, shipping devices, offering a paid download, bundling firmware into exported hardware and distributing a freemium app to EU users all count. Each individual product version placed after the deadline must comply, so a product first sold in 2025 does not stay exempt once new units or substantially modified versions reach EU buyers. Every one of those routes triggers the Cyber Resilience Act UK duties at the moment of first supply.
Why so many UK firms assume they escape
Post-Brexit, EU regulations no longer apply automatically inside Great Britain, and that is exactly why the Cyber Resilience Act UK question generates so much false comfort. The regulation does not need to apply in the UK to bind a UK exporter: it binds the product at the border. The same extraterritorial pattern already caught UK firms under GDPR and under NIS2, which we covered in our NIS2 guide for UK suppliers. The CRA simply extends that pattern from data and services to products.
Cyber Resilience Act UK Scope: What the Regulation Covers
Products with digital elements, hardware and software alike
The regulation covers products with digital elements: software or hardware whose intended use involves a direct or indirect data connection to a device or network. That includes desktop and mobile applications, operating systems, firmware, smart devices, routers, industrial sensors, commercial SDKs and code libraries. It also includes the remote data processing a product needs to function, so a device’s companion cloud service is pulled into scope with the device itself. That breadth is why the Cyber Resilience Act UK footprint is wider than most boards assume.
Security across the whole product lifecycle
The regulation requires cybersecurity to be designed in, not bolted on. Annex I demands secure-by-default configuration, protection of data in transit and at rest, attack surface minimisation and exploit mitigation at design time, then a living vulnerability handling process for the support period after sale — normally at least five years. For the Cyber Resilience Act UK exporters face, that lifecycle duty is usually the expensive part: it turns security from a launch checklist into a standing operating cost.
The reporting regime layered on top
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and their CSIRT: an early warning within 24 hours, a fuller notification within 72 hours, and a final report after fourteen days for vulnerabilities or one month for incidents. Those clocks run for UK manufacturers with products on the EU market just as they run for EU ones, making reporting the first live Cyber Resilience Act UK obligation. The reporting deep-dive in our series covers the exact triggers and portal mechanics.
Which UK Companies Are Caught
The scenarios below cover the common shapes of Cyber Resilience Act UK exposure. The pattern to notice: the duties follow the product, and the brand name on the product decides who the manufacturer is.
| UK scenario | In scope? | Why |
|---|---|---|
| Software licensed to EU customers | Yes | Placed on the EU market under your name |
| Devices sold via an EU distributor | Yes | You remain the manufacturer; the distributor has checking duties |
| App on an EU app store | Yes | Commercial availability to EU users is placing on the market |
| Components sold to an EU product maker | Yes | Commercial SDKs, libraries and modules are products in their own right |
| Software sold only to UK customers | No | Nothing is placed on the EU market |
| Pure SaaS with no product element | Mostly no | Standalone cloud services sit under NIS2, not the CRA |
UK manufacturers selling directly into the EU
If your company develops a product and makes it available to EU buyers under its own name or trademark, you are the manufacturer and you carry the full set of duties: essential requirements, conformity assessment, CE marking, technical documentation, vulnerability handling and reporting. This is the heaviest role in the regulation, and it is the default position for most of the Cyber Resilience Act UK software vendors we speak to.
Selling through importers, distributors and marketplaces
Routing sales through an EU importer does not transfer your manufacturer duties; it adds a second regulated party. Importers must verify that the manufacturer has done conformity assessment, drawn up the technical documentation and affixed the CE marking before they place the product on the market. An importer facing fines for your gaps will pass the pain straight back up the contract, so treat importer relationships as part of your vendor management exposure, not as a shield.
White-label and own-brand traps
Any EU business that sells your product under its own brand becomes the manufacturer of record for that product, but your contract will almost certainly make you warrant the compliance evidence behind it. Conversely, a UK firm that rebrands imported components and sells them into the EU takes on manufacturer duties for the combined product. Brand equals responsibility under this regulation, so map every white-label arrangement before assuming the Cyber Resilience Act UK impact stops at your direct sales.
Which UK Companies Escape
UK-only sellers stay outside
A company whose products never reach EU buyers has no duties under the regulation. That position needs evidence and maintenance, though: geo-restricting downloads, checking distributor territories and watching where resellers actually ship. The moment a distributor lists your product in an EU marketplace, you are back in the Cyber Resilience Act UK conversation whether you planned to be or not.
Standalone SaaS and the NIS2 boundary
Cloud services supplied on their own — hosting, pure web applications, managed platforms — are not products with digital elements, so the CRA leaves them alone. They are regulated instead as digital services under NIS2. The boundary is remote data processing: if your cloud back-end is necessary for a product to perform its functions, that processing is dragged into the product’s scope. A smart lock’s companion API is CRA territory; a standalone CRM is not. That functional-necessity test is the Cyber Resilience Act UK boundary for cloud businesses.
Open-source and the other carve-outs
Open-source software developed or supplied outside a commercial activity is out of scope, and non-profit open-source stewards get a lighter regime. Monetise it — paid tiers, paid support sold with the product, or shipping it under your trademark as a commercial offer — and manufacturer duties attach. Also excluded are products already covered by sector rules with equivalent security regimes: medical devices, civil aviation, marine equipment and type-approved vehicles.
Spare capacity is not an exemption strategy
What does not work: claiming the EU revenue is too small to matter, arguing the product is business-to-business only, or pointing at a UK certification such as Cyber Essentials. The regulation has no de minimis threshold, applies to consumer and enterprise products alike, and recognises no UK scheme as a substitute for conformity assessment. Small exporters carry the same duties as large ones; only the fines scale with turnover.
Cyber Resilience Act UK Timeline: The Dates That Bind
The regulation entered into force on 10 December 2024, and its obligations switch on in stages. The dates below are the Cyber Resilience Act UK milestones boards need in the risk register.
| Date | What starts | Who it hits |
|---|---|---|
| 10 December 2024 | Regulation in force; clock starts | Everyone in scope |
| 11 June 2026 | Notified body framework applies | Products needing third-party assessment |
| 11 September 2026 | Reporting of exploited vulnerabilities and incidents | All manufacturers with EU-market products |
| 11 December 2027 | Full application: essential requirements, CE marking, fines | Every product placed from that date |
One month to the first live duty
As this guide is published in mid-August 2026, the reporting obligation is one month away and the full regime is sixteen months out. Those are engineering timescales, not legal ones: standing up a vulnerability handling process, generating SBOMs and preparing a technical file routinely consumes a year of elapsed time. Sixteen months is tight for full Cyber Resilience Act UK readiness, as the chart shows.
Existing products and the modification trap
Products already on the EU market before 11 December 2027 are not retrospectively caught, with one exception: the reporting duties apply to them from September 2026 anyway. But every new unit, new version and substantial modification placed after the deadline must comply in full. For software, where shipping updates is the business model, that means almost every actively developed product crosses into scope at its first post-deadline release. In practice, your release cadence sets your real Cyber Resilience Act UK deadline.
Why waiting for UK guidance is a mistake
No UK government decision can change the Cyber Resilience Act UK exporters must satisfy, because the duty comes from the buyer’s side of the border. Waiting to see whether Westminster mirrors the rules only shortens your own runway. UK divergence matters for your domestic obligations — covered below — not for your EU market access.
What Compliance Actually Requires From a UK Company
The duties split by role. Most UK companies wear the manufacturer hat, but importer and distributor duties matter when you design your route to the EU market.
| Role | Core duties | Typical UK example |
|---|---|---|
| Manufacturer | Essential requirements, conformity assessment, CE marking, technical file, vulnerability handling, reporting | UK vendor selling its own product into the EU |
| Authorised representative | Holds documentation, liaises with authorities on the manufacturer’s mandate | EU firm appointed by a UK manufacturer |
| Importer | Verify conformity evidence before sale; stop non-compliant products | EU entity first selling a UK-made product |
| Distributor | Check CE marking and documents; act with due care | EU reseller of a UK product |
Essential requirements and CE marking
Annex I sets the security properties every product must demonstrate, and CE marking is how conformity is declared. Around ninety percent of products can self-assess against the essential requirements; products on the “important” lists face harmonised standards or third-party assessment, and a small critical category needs European certification. For most Cyber Resilience Act UK software firms, the work is self-assessment done honestly: threat modelling, secure defaults, hardening evidence and a documented risk assessment.
The technical file is the deliverable
Everything converges on the technical documentation described in Annex VII: product description, risk assessment, SBOM, test evidence, support period statement and the declaration of conformity. Market surveillance authorities can demand it for ten years, and it is where Cyber Resilience Act UK compliance either exists on paper or does not. Teams with mature DevOps pipelines have an advantage here, because most of the evidence can be generated by the build system rather than written by hand each release.
Your importer becomes your auditor
Because importers must verify your evidence before selling, expect EU partners to demand the declaration of conformity, the support period statement and proof of a vulnerability handling process in the next contract cycle — before the 2027 deadline, not after it. UK firms that cannot produce the pack will quietly lose shelf space to competitors that can. Treat the first importer questionnaire as the real compliance deadline.
Appointing an authorised representative
A UK manufacturer may appoint an EU-established authorised representative to hold documentation and deal with authorities. It is optional under this regulation, but it simplifies market surveillance contact and reassures buyers. Many UK firms already maintain one for other CE regimes; extending that mandate is usually cheaper than negotiating evidence clauses importer by importer.
Cyber Resilience Act UK Penalties: What Ignoring Them Costs
Three fine bands, one market
Breaching the essential requirements or the core manufacturer obligations carries administrative fines of up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. Breaching other obligations — importer, distributor and documentation duties — carries up to 10 million euros or 2 percent. Supplying misleading information to authorities carries up to 5 million euros or 1 percent. The chart compares the fixed Cyber Resilience Act UK fine ceilings.
Market withdrawal hurts more than the fine
For a UK exporter the sharper risk is not the fine but the order: market surveillance authorities can require corrective action, restrict availability, or force withdrawal and recall of a non-compliant product across the whole EU. One member state’s finding travels. For a business earning a third of its revenue in Europe, an interrupted quarter of EU sales dwarfs most realistic penalty scenarios — and it arrives with reputational damage your competitors will happily amplify.
CRA vs UK Law: Why PSTI Is Not Enough
What the UK regime actually covers
The UK’s Product Security and Telecommunications Infrastructure regime has been in force since April 2024, but it is far narrower: it covers consumer connectable products only, and its security requirements stop at banning default passwords, publishing a vulnerability disclosure route and stating the support period. Enterprise software, SDKs, industrial devices and most business hardware sit outside it entirely.
| Factor | UK PSTI regime | EU Cyber Resilience Act |
|---|---|---|
| Products covered | Consumer connectable devices | Nearly all hardware and software with digital elements |
| Standalone software | Not covered | Covered |
| Security requirements | Three baseline duties | Full Annex I lifecycle requirements |
| Vulnerability reporting to authorities | Not required | 24h and 72h clocks from September 2026 |
| Conformity marking | Statement of compliance | CE marking with technical file |
| Maximum penalty | GBP 10m or 4% UK revenue | EUR 15m or 2.5% worldwide turnover |
Dual compliance is the real UK position
A UK device maker selling at home and into Europe answers to both regimes at once: PSTI for UK consumer sales, the CRA for EU sales. Because the EU rules are the superset, the practical strategy is to build to the CRA and let PSTI compliance fall out of it, rather than maintaining two security baselines. That is the approach our compliance guide in this series recommends, and it is how the Cyber Resilience Act UK burden becomes an asset: one engineering standard that satisfies every market you sell in.
Services divergence: the Cyber Security and Resilience Bill
The UK is legislating in parallel, but for services rather than products: the Cyber Security and Resilience Bill updates the UK NIS framework for providers of essential and digital services. Nothing currently before Parliament mirrors the CRA’s product rules, which means UK product security law and EU product security law will keep diverging — and EU market access will keep being the stricter test.
What About Northern Ireland?
The Windsor Framework question
Northern Ireland trades goods under the Windsor Framework, which applies listed EU product legislation to goods placed on the Northern Ireland market. CE-marked goods regulation generally follows the EU rulebook there. Whether and exactly how the CRA will operate for Northern Ireland has not been spelled out in UK government guidance at the time of writing, so any firm selling connected products into Northern Ireland should treat the position as live and track official publications rather than assume exemption.
The practical position for NI sellers
The pragmatic reading: a GB business selling digital products into Northern Ireland should plan for CRA-equivalent expectations on that route, because its goods sit inside an EU-aligned goods regime and its distributors will ask EU-shaped questions. Firms already building to the CRA for EU sales lose nothing; firms hoping to carve Northern Ireland out of scope are betting against the direction of travel. Treat the Cyber Resilience Act UK standard as the Northern Ireland default until guidance says otherwise. When the guidance lands, the prepared position costs nothing extra.
Cyber Resilience Act UK Preparation: Four Practical Steps
Step one: map your EU exposure honestly
List every route by which your products reach EU users: direct sales, distributors, marketplaces, app stores, OEM deals and white-label arrangements. For each, record what is placed on the market, under whose brand, and when the next version ships. This map decides whether the Cyber Resilience Act UK duties are yours, your importer’s or your white-label partner’s — and it is the first document an EU customer’s procurement team will ask to see.
Step two: classify your products and pick assessment routes
Sort each in-scope product against the default, important and critical categories to learn whether self-assessment is available. Most business software self-assesses; security products such as password managers, VPNs and boundary devices tend to land in the important classes. Classification drives cost and timeline, so do it before budgeting; it is where Cyber Resilience Act UK budgets are won or lost. Our series checklist walks this in delivery order for engineering teams.
Step three: build the evidence into the pipeline
Start generating the compliance evidence now: SBOMs from the build, risk assessments per release, hardening baselines, penetration test records and a written support period. Automating this inside your delivery pipeline is dramatically cheaper than assembling it retrospectively, and it is where an experienced software development partner or managed IT services provider earns their fee. The reporting clocks start in September 2026; the evidence should exist before the first report is ever due.
Step four: decide who fronts the EU relationship
Choose your structure: appoint an authorised representative, negotiate evidence duties with your importers, or establish an EU entity if volumes justify it. Put the compliance warranties into distributor contracts this cycle. The companies that treat the Cyber Resilience Act UK question as a market-access project — not a legal afterthought — will be the ones still on EU shelves in January 2028.
Cyber Resilience Act UK FAQ
Does the Cyber Resilience Act apply to UK companies after Brexit?
Yes, whenever their products with digital elements are placed on the EU market. The regulation is extraterritorial by design: the duties attach to the product’s market access, not to the manufacturer’s location. A UK company with no EU sales at all is outside the regulation — until a distributor, marketplace or white-label partner takes its product across the border. That is the whole Cyber Resilience Act UK test.
Does it apply to UK SaaS businesses?
Usually not to the service itself: standalone cloud services fall under NIS2 rather than the CRA. But remote data processing that a product needs to function is in scope with the product, so SaaS businesses that ship agents, apps, devices or SDKs alongside the service should assess those components. The boundary is functional necessity, not marketing labels.
Do UK software companies really need CE marking?
Yes — from 11 December 2027, in-scope products placed on the EU market need CE marking, including pure software. For most software the route is self-assessment against the essential requirements with a technical file to prove it. It is the first time most UK software vendors will have touched CE marking, which is precisely why starting in 2026 is the safe course.
When does a UK company need to be ready?
Two dates. Reporting duties begin on 11 September 2026 for actively exploited vulnerabilities and severe incidents. Full compliance — essential requirements, conformity assessment, CE marking and the technical file — binds every product placed on the EU market from 11 December 2027. Working back from procurement lead times, UK companies should have their gap analysis done in 2026 and remediation underway through 2027. The Cyber Resilience Act UK clock does not wait for UK law to catch up.
References
Cyber Resilience Act | European Commission
NIS2 Directive | European Commission
Product Security and Telecommunications Infrastructure Act 2022
Cyber Security and Resilience Bill | GOV.UK
The Windsor Framework | GOV.UK
NCSC: Supply Chain Security Guidance
NCSC: Cyber Essentials Overview
NIST SP 800-218: Secure Software Development Framework