← Back to CRA Insights
CRA and other EU law

There Is No "UK Cyber Resilience Act" - Here's What You're Actually Looking For

Editorial cover for an article distinguishing the EU Cyber Resilience Act from the UK's Cyber Security and Resilience Bill. Two distinct regulatory territories side by side - suggest a channel or border between two document stacks. Calm, institutional, no flags used as caricature, no text baked into the image. Brand navy #1C3D6E dominant with a small #E0A100 accent on the dividing line.

If you searched "UK Cyber Resilience Act" and landed here, you are not alone - and the confusion is understandable. But there is no such law. The phrase is a mashup of two distinct pieces of legislation that do very different things. Getting them mixed up is an expensive mistake.

Key points

  • There is no law called the "UK Cyber Resilience Act." The phrase conflates two separate regimes.
  • The EU Cyber Resilience Act - Regulation (EU) 2024/2847 - is a product law. It applies to anyone placing a product with digital elements on the EU market, regardless of where they are based. Brexit changed nothing here: a UK manufacturer selling into the EU is a manufacturer under the CRA with full obligations.
  • The UK Cyber Security and Resilience Bill is a domestic organisational law - a modernisation of the UK NIS Regulations 2018. It regulates operators of essential services and certain digital service providers. It does not regulate products.
  • If you make a connected product, the law governing your product is the EU CRA (if you sell into the EU), plus UK product law such as the Product Security and Telecommunications Infrastructure (PSTI) Act 2022 for consumer connectable products.
  • The UK Bill is not yet law and its detail may still change before Royal Assent.

Why the EU CRA reaches UK companies

The EU Cyber Resilience Act entered into force on 10 December 2024. Its main obligations apply from 11 December 2027, with reporting obligations switching on earlier, from 11 September 2026.

The territorial logic is the same as GDPR. The CRA applies to any product with digital elements placed on the EU market, regardless of where the manufacturer is based. A UK company that sells a connected device, an industrial sensor, or a software product into Germany, France, or any other EU member state is a manufacturer under the CRA and carries the full weight of manufacturer obligations: security by design, a cybersecurity risk assessment under Article 13, Annex I essential requirements, a technical file, an EU Declaration of Conformity, CE marking, and a coordinated vulnerability disclosure policy.

The common assumption - "we are not an EU company, so the CRA does not apply to us" - is one of the most expensive misreadings of the regulation.

What about an EU authorised representative?

Under Article 18 of the CRA, appointing an EU-based authorised representative is optional for non-EU manufacturers - unlike some other EU product regulations where it is mandatory. You can read the detail in our post on CRA authorised representatives under Article 18. The practical reality, however, is that if you ship through an EU-established importer, that importer carries its own verification duties: they must confirm that you have carried out the appropriate conformity assessment, that your technical documentation exists, and that CE marking is correctly affixed - before they place the product on the EU market. Your EU distributor or importer will start asking for your Declaration of Conformity and Annex II technical documentation. That pressure arrives before any regulator does. See our post on importer and distributor obligations under the CRA for what they are required to check.

star Important

Reporting obligations apply from 11 September 2026 — to products already on the EU market. Article 14 reporting duties cover actively exploited vulnerabilities and severe incidents. They apply to all products with digital elements available on the EU market, including those placed there before 11 December 2027. If you sell into the EU today, this date is already relevant to you.


The UK's Cyber Security and Resilience Bill is a different animal

The Cyber Security and Resilience (Network and Information Systems) Bill is the UK's own domestic cyber legislation. It is emphatically not a UK equivalent of the EU CRA. It does not regulate products. It regulates organisations - specifically, those operating essential services and certain digital services in the UK.

What it does

The Bill would amend the Network and Information Systems (NIS) Regulations 2018 to include additional sectors and update incident reporting duties. For the first time it pulls managed service providers, data centres and designated critical suppliers directly into a statutory regime, with fines of up to £17 million or 4 per cent of global turnover and an incident-reporting clock that starts ticking within 24 hours.

In limited circumstances, small and micro-businesses that supply critical goods or services to essential and digital services can be designated as "critical suppliers" - a measure designed to combat the cyber risks stemming from increasingly complex supply chains.

Whereas the existing regime focuses on continuity of services, the Bill would extend the focus to security of services as well, with certain security duties for parties such as regulated managed service providers.

Where it stands right now (4 August 2026)

The Bill was introduced to Parliament on 12 November 2025, received its second reading in the Commons on 6 January 2026, cleared committee stage, and completed all remaining Commons stages before entering the House of Lords on 25 June 2026. It passed all of its House of Commons stages and is now before the House of Lords (HL Bill 32), where Second Reading was completed on 14 July 2026 and Committee Stage is scheduled for 1 September 2026, with Royal Assent expected in late 2026.

The Lords completed their Second Reading on 14 July 2026 with cross-party support in principle. However, most operational obligations will not take immediate effect on Royal Assent. The government has confirmed a phased implementation approach, with key requirements brought into force through secondary legislation following further consultation. Full implementation is not expected until 2028.

Important: The Bill is not yet law. It could still be amended at Lords committee stage (scheduled 1 September 2026) or later. Do not treat its current text as settled until Royal Assent. Analysis from Taylor Wessing notes that although not expected to fully enter into force until 2028, there are steps to start thinking about now - including a preliminary scoping exercise to understand whether your business is likely to be in scope.


Side by side: EU CRA vs. UK Cyber Security and Resilience Bill

EU Cyber Resilience ActUK Cyber Security and Resilience Bill
What it regulatesProducts with digital elements (hardware and software)Organisations operating essential services and digital services
Who it bindsManufacturers, importers, distributors — regardless of where establishedOperators of essential services, managed service providers, data centres, designated critical suppliers
The triggerPlacing a product with digital elements on the EU marketOperating a regulated service in the UK
Key early date11 September 2026 — Article 14 reporting obligations begin1 September 2026 — Lords committee stage (Bill not yet law)
Full application11 December 2027~2028 via secondary legislation after implementation consultation
Legal status (Aug 2026)In force since 10 December 2024Bill before the House of Lords — not yet law
Enforcement bodyNational market surveillance authorities in each EU member stateUK sector regulators (e.g. Ofcom, FCA, sector-specific competent authorities)
PenaltiesUp to €15 million or 2.5% of global annual turnoverUp to £17 million or 4% of global turnover (higher tier)
Covers products?Yes — this is its entire purposeNo
Covers services/infrastructure?Only incidentally (remote data processing tied to a product)Yes — this is its entire purpose

Three situations UK companies find themselves in

(a) UK manufacturer selling into the EU

The EU CRA applies to you in full. You are a manufacturer under Regulation (EU) 2024/2847. Your obligations include the Article 13 risk assessment, Annex I essential requirements, a technical file, an EU Declaration of Conformity, CE marking, and Article 14 incident and vulnerability reporting from 11 September 2026. The fact that you are based in the UK and that the UK has not adopted the CRA is irrelevant - the trigger is placing a product on the EU market, not where you are incorporated.

Start now. The 11 September 2026 reporting deadline is weeks away.

(b) UK manufacturer selling only in the UK

The EU CRA does not apply to you. However, if you make consumer connectable products, the PSTI Act 2022 already imposes baseline security requirements (no universal default passwords, a vulnerability disclosure policy, and transparency about security update periods). Watch the UK Cyber Security and Resilience Bill if you also operate services that could bring you into scope as an essential service operator or managed service provider - but the Bill does not regulate your products.

(c) UK company that is both a product maker and an operator of essential services

Both regimes can bite - on different things. The EU CRA governs your products (if sold into the EU). The UK Cyber Security and Resilience Bill, once in force, will govern your service operations. These are parallel obligations with different triggers, different documentation requirements, and different enforcement bodies. Do not assume that compliance work done for one satisfies the other.


Use this decision tool to find your starting point


What to do now

The landscape is moving fast. Here is a sequenced action list depending on your situation.

1
Confirm whether any of your products reach the EU market

Check every product line — hardware, software, firmware, SaaS with a network-connected component. If any of it is placed on the EU market (sold, distributed, or made available), the CRA applies. Use the scope checker if you are unsure.

2
If yes: get Article 14 reporting in place before 11 September 2026

This is the nearest hard deadline. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. You need a workflow, a designated contact point, and clarity on what counts as a reportable event — before the date arrives, not after. See our 11 September 2026 deadline guide.

3
Work the CRA compliance sequence for full application by 11 December 2027

The sequence is: confirm scope → classify your product (Default, Important, or Critical) → complete the Article 13 risk assessment → implement Annex I essential requirements → build your technical file → draw up the EU Declaration of Conformity → affix CE marking. The CRA compliance checklist walks through each step.

4
Understand your supply chain position

If you sell through an EU-established importer or distributor, they will ask for your Declaration of Conformity and documentation before they place your product on the market. Get ahead of that conversation. If you are the importer, read your own verification duties at /blog/cra-importer-distributor-obligations.

5
Track the UK Bill through Lords committee stage on 1 September 2026

If you operate essential services or managed IT services in the UK, the Cyber Security and Resilience Bill is the law to watch. Committee stage begins 1 September 2026 — amendments are possible. Do not treat the current Bill text as final. Monitor the UK Parliament Bill page for updates.

6
Do not assume UK conformity work substitutes for CRA conformity

PSTI Act compliance, Cyber Essentials certification, and ISO 27001 are all valuable — but none of them satisfy the CRA's essential requirements, technical documentation obligations, or conformity assessment routes. They are parallel frameworks, not substitutes.


Further reading on CRA Facts

lightbulb Tip

Stay current as both regimes develop. The UK Bill is still moving through Parliament, and CRA harmonised standards are still being finalised. Subscribe to The CRA Brief at /subscribe for plain-English updates the moment anything changes — Lords amendments, new Commission guidance, or standards citations in the Official Journal.


This article is general guidance on the regulatory landscape, not legal advice. The correct compliance route for your specific situation depends on your products, your markets, and your organisational structure. Confirm specifics against Regulation (EU) 2024/2847 and the UK Parliament Bill page, and seek qualified legal counsel for your situation. The UK Cyber Security and Resilience Bill has not yet received Royal Assent; its provisions may change.