What changed

The European Commission published practical guidance on July 27 for manufacturers, developers and businesses applying the Cyber Resilience Act. The document explains when products fall inside the Act, what counts as a substantial modification, how support periods should be understood, and how companies should approach reporting and risk assessment. The Commission says the guidance includes 67 examples, use cases, flowcharts and graphs. It is not a new robot-safety standard, but it turns a broad digital-product law into a more operational checklist for companies building and maintaining connected machines.[1]

The calendar is the material change for systems teams. The Commission says the Act’s reporting duties begin on September 11, 2026, while its main obligations apply on December 11, 2027. ENISA’s Single Reporting Platform FAQ was updated on July 31, 2026, and describes the platform manufacturers will use. The platform is scheduled to be operational on September 11, so the next step is not a distant compliance exercise: it is a dated handoff between product security, incident response and market-surveillance processes.[1,2]

The mechanism reaches the robot stack

The Act applies to products with digital elements made available on the European Union market when their intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection. The Commission’s legal summary explicitly includes industrial control systems in the broad hardware category. It also places the manufacturer’s risk assessment across planning, design, development, production, delivery and maintenance, while giving importers and distributors duties to check compliance, support information and vulnerability handling. That is a lifecycle record, not only a patching record.[3]

For robotics, the practical boundary is a system rather than a humanoid label. An automated mobile robot, its controller, a fleet-management product, a remote-access component or an industrial drone may each contain software and communications that bring them into the Act’s product-with-digital-elements logic. That is an inference from the legal scope, not a blanket classification: the Act excludes some products already governed by sector-specific aviation, automotive, medical or marine rules, and the relevant core function and connection have to be assessed case by case.[3,4]

The reporting workflow is narrower than a general duty to disclose every bug. ENISA says manufacturers must report vulnerabilities for which there is reliable evidence of active exploitation and severe incidents that affect product security. The early warning is due without undue delay and within 24 hours of awareness; an initial notification follows within 72 hours; a vulnerability receives a final report no later than 14 days after a corrective measure is available, while a severe incident receives a final report within one month. The platform can also accept voluntary reports of vulnerabilities, threats, incidents and near misses after September 11.[2]

The control owner moves upstream

The change therefore reaches the control chain before a robot is blamed for an unsafe movement. A manufacturer needs a way to know which connected products and components are still supported, who can make a report, what evidence establishes active exploitation or a severe incident, and which corrective measure closes the record. ENISA’s platform routes the notification to the designated national CSIRT and to ENISA, with market-surveillance authorities able to receive the information. The security team owns the report, but the product and support teams own much of the evidence that makes the report credible.[2,3]

France’s implementation page makes the institutional split concrete: the national cybersecurity agency ANSSI describes the CERT-FR as the coordinating incident-response team, while the French National Frequency Agency is identified as the market-surveillance authority. It lists September 2026 reporting through the ENISA platform and December 2027 market controls. The page also describes possible sanctions of up to 15 million euros or 2.5 percent of a manufacturer’s worldwide annual turnover. That is a national enforcement framework, not evidence that any robot maker has already been penalized.[4]

What remains unproven

The evidence supports a changed operating requirement, not a claim that connected robots are now safer. The Commission calls its guidance non-binding. None of the reviewed records names a robot-specific enforcement action, recall, field incident or disclosed patch under the new framework, and the legal scope still depends on the product, its connections, its core function and any sector-specific exclusion. The first measurable checkpoint is September 11: whether the reporting platform is live and whether the first robot or industrial-automation notification reveals the quality of manufacturers’ asset, incident and remediation records. The next checkpoint is the CRA’s main December 2027 obligations.[1,2,3,4]