The CRA does to product security what the CE-marking directives did to product safety: it makes conformity a condition of market access. Manufacturers must meet Annex I’s essential requirements — secure development, no known exploitable vulnerabilities at release, secure defaults, security updates for the expected lifetime — and evidence it in technical documentation before affixing the CE mark. Importers and distributors inherit verification duties; open-source has carve-outs with edges worth checking.
Risk graduates the machinery. Default-category products self-assess. Important products — smart locks, cameras, baby monitors, connected toys, firewalls, password managers and more, pinned down by Implementing Regulation 2025/2392 — face constrained routes: Class I self-assesses only when applying harmonised standards, Class II requires a notified body regardless. Critical products (secure elements, HSMs, smart meter gateways) can be pushed by delegated act into mandatory European certification under EUCC.
Two clocks matter more than the headline date. Reporting obligations start 11 September 2026 — before any product requirement — turning PSIRT maturity into a legal obligation. And the harmonised standards the whole self-assessment economy depends on arrive late: product-specific standards from October 2026, horizontal ones through 2027, uncomfortably close to full application on 11 December 2027. Waiting for the standards is the most popular strategy and the worst one.