Regulatory watch

What changed, and what it means for you.

Short notes on the rules that move EU market access, written for the people who have to act on them rather than the people who draft them.

11 September 2026
Applies now

Cyber Resilience Act reporting duties start

Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under Article 14 of Regulation (EU) 2024/2847. One notification through the Single Reporting Platform, which opened on the same date, reaches both the CSIRT designated as coordinator and ENISA. The clock runs from the moment you become aware, not from the moment you finish investigating.

If your product connects to a network or runs software, this duty is live now, whether or not the rest of the CRA has caught up with you. The practical questions are whether anyone in your organisation is registered on the platform, designated to report, and able to work to 24 hours for an early warning, 72 hours for a full notification, and 14 days for the final report.

20 January 2027
Approaching

The Machinery Regulation replaces the Machinery Directive

Regulation (EU) 2023/1230 takes over from Directive 2006/42/EC. There is no transitional period in which both apply: machinery placed on the market from that date is assessed under the regulation. Digital documentation and cybersecurity come into scope, and the list of machinery requiring notified body involvement has been reworked.

Technical files built to the old directive need reworking before the date, not after it. If your product moves into a category needing a notified body, the lead time for that assessment is the constraint, not the paperwork. The Digital Omnibus on AI, Regulation (EU) 2026/1744, amended the Machinery Regulation in July 2026, but it did not move this date.

11 December 2027
On the horizon

Cyber Resilience Act becomes fully applicable

The remaining obligations of Regulation (EU) 2024/2847 apply from 11 December 2027, including the essential cybersecurity requirements, conformity assessment and CE marking for products with digital elements. Provisions on the notification of conformity assessment bodies have applied since 11 June 2026.

Products carrying a CE mark on other grounds will need the cybersecurity requirements folded into the same technical file and the same Declaration of Conformity.

13 December 2024
In force

GPSR reaches almost every consumer product

Regulation (EU) 2023/988 has applied since 13 December 2024. A consumer product may not be placed on the EU market unless a person established in the Union is responsible for it, and that reaches products with no CE marking obligation at all.

This is the requirement most sellers meet first, because the marketplaces enforce it. Amazon, eBay and others check for a named EU responsible person before a listing goes live, and suspend listings that lose one.

16 July 2021
In force

Market Surveillance Regulation, Article 4

Regulation (EU) 2019/1020 has required an economic operator established in the Union for most CE marked goods since 16 July 2021. That operator keeps the Declaration of Conformity and the technical documentation available and cooperates with the authorities.

A manufacturer established outside the EU cannot be that operator. Selling direct into the Union without appointing one leaves the product unlawfully placed on the market, whatever the state of its technical file.

These notes are general information, not legal or regulatory advice, and they do not take account of your product or circumstances. Dates and references on this page were verified on 13 September 2026 against the official sources. The only authentic versions of EU legal acts are those published in the Official Journal of the European Union.

Want to know which of these actually catch your product?

Four questions, two minutes, and a straight answer with the regulation and the date against each obligation.