Faegre Drinker·PRIVACY / DATA SECURITY

EU Sets 2026 Deadlines for Connected Product Data and Security Rules

Manufacturers of internet-connected products face key September 2026 compliance deadlines under the EU’s Cyber Resilience Act and Data Act.

Manufacturers selling internet-connected products in the European Union must prepare for two significant, near-simultaneous compliance deadlines in September 2026. On September 11, vulnerability and incident reporting obligations under the Cyber Resilience Act (CRA) will take effect, followed on September 12 by the Data Act's "access-by-design" requirements. These regulations represent a major development for companies in nearly every sector, imposing new duties on how products are designed, sold, and maintained. The CRA will mandate robust processes for identifying and reporting security flaws, while the Data Act will require that users can easily access data generated by their devices. For sophisticated clients and their counsel, this is a critical operational and compliance challenge, as failure to comply can result in significant penalties and market-access restrictions. Businesses should now be auditing their product portfolios to determine scope and mapping out the technical and organizational changes needed to meet these fast-approaching deadlines.

eucyber-resilience-actdata-actiotproduct-compliancecybersecuritydata-privacy
Read the original firm alert → Friday, September 11, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.