As of 2025, 43% of UK businesses and 30% of charities have reported significant cyber breaches, with the average cost of a data breach in the UK climbing to a staggering £3.29 million. For manufacturers and software developers looking to trade in the UK and EU, the arrival of the Cyber Resilience Act (CRA) and the domestic PSTI Act marks the end of the “patch-later” era. At CFECERT, we recognize that navigating these overlapping regulations is the greatest challenge facing digital innovators today.
The EU Cyber Resilience Act (CRA) introduces a rigorous “Security by Design” framework, mandating that products with digital elements meet strict essential requirements before they can bear the CE marking. While the full regulation applies from December 2027, the first major hurdle is much closer: starting 11 September 2026, manufacturers must comply with mandatory reporting obligations for actively exploited vulnerabilities and severe incidents. Failing to implement these processes now could result in administrative fines of up to €15 million or 2.5% of global turnover, effectively barring non-compliant products from the European market.
For those targeting the British market, the Product Security and Telecommunications Infrastructure (PSTI) Act 2024 remains the primary gatekeeper for consumer IoT. However, the UK is not standing still; the government is currently progressing the Cyber Security and Resilience Bill (2026) to further strengthen supply chain protections. Understanding the nuances between the UK’s PSTI requirements and the EU’s CRA is vital for maintaining a seamless cross-border trade route.
To bridge these regulatory gaps, forward-thinking organisations are aligning with international standards like ISO/IEC 27001 for information security and the new ISO/IEC 42001 for Artificial Intelligence Management Systems (AIMS). These frameworks provide the documented evidence and risk management structures that regulators demand. At CFECERT, our UKAS and CPD accredited services allow us to support businesses globally, ensuring that your management systems are not only compliant but globally competitive.
Preparation is a marathon, not a sprint. Integrating “Security by Design” and establishing the required vulnerability disclosure programs can take up to 24 months. Whether you need a comprehensive Gap Analysis, specialised Lead Auditor training, or a full ISO 42001 certification, our expert team at CFECERT acts as your strategic partner to ensure you meet the 2026 reporting deadlines with confidence.