Back
News

EU Cyber Resilience Act: What It Means for UK IoT

Sep 17th, 2026
5
minutes
EU Cyber Resilience Act text overlayed on an illustration of a network

Subscribe to newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The EU Cyber Resilience Act now requires makers of connected products to report actively exploited vulnerabilities within 24 hours. Most Millbeck customers deploy in the UK, where the law does not apply, but it still shapes the routers they buy and how those routers are kept secure.

The Cyber Resilience Act (CRA) is the EU law that sets cybersecurity rules for hardware and software products sold in the EU. The CRA is Regulation (EU) 2024/2847. Its reporting rules started on 11 September 2026, and its main security requirements apply from 11 December 2027.

At Millbeck, we supply cellular routers, IoT SIMs and antennas, mainly for UK deployments. This article sets out what has changed, why it matters to UK buyers, and what we do to help customers keep their routers secure.

What Changed on 11 September 2026?

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products to the EU through ENISA's Single Reporting Platform.

An actively exploited vulnerability is a security flaw that attackers are already using. ENISA, the EU Agency for Cybersecurity, launched the platform on the day the duty started. The European Commission sets these deadlines:

ReportDeadline
Early warningWithin 24 hours of the manufacturer becoming aware
NotificationWithin 72 hours of the manufacturer becoming aware
Final report (vulnerability)Within 14 days of a fix or mitigation becoming available
Final report (severe incident)Within one month of the 72-hour notification

The European Commission says the reporting duty covers products already on the EU market, not only new ones. Manufacturers must also tell affected users about an actively exploited vulnerability or severe incident.

Why Does the Cyber Resilience Act Matter to UK IoT Deployments?

The Cyber Resilience Act matters to UK IoT deployments because much of the industrial router hardware used in the UK comes from EU manufacturers, and routers sit in one of the CRA's higher-risk product classes.

The UK Government's explanatory memorandum on the CRA states that its substantive requirements will not apply to the UK. Great Britain's own Product Security and Telecommunications Infrastructure (PSTI) regime covers consumer connectable products only, so it does not reach most business and industrial IoT.

Annex III of the CRA lists 'routers, modems intended for the connection to the internet, and switches' as important products in Class I. For the EU market, their manufacturers must handle vulnerabilities, supply security updates and support each product for at least five years, unless the product is expected to be in use for less time.

In our view, UK buyers gain from this even though the law does not apply here. A manufacturer that must run a formal vulnerability process for its EU sales is likely to apply the same fixes to the same products wherever they are sold. The benefit only reaches a UK site if someone installs the updates, which is where most of the practical work sits.

The CRA applies in full to any UK business that sells connected products into the EU. If that includes you, you count as the manufacturer and the reporting duty applies to you now.

How Does Teltonika Approach Product Security?

Teltonika Networks, the Lithuanian manufacturer whose routers Millbeck supplies as a Teltonika Diamond distributor, runs a certified secure development process and publishes security advisories for its products.

Teltonika states on its Security Centre that it achieved IEC 62443-4-1 certification on 30 March 2026. IEC 62443-4-1 is the international standard for a secure product development lifecycle in industrial automation and control systems. Teltonika also states that its RUT, RUTX, RUTM, RUTC, TRB, TAP and OTD series met the Radio Equipment Directive cybersecurity requirements from 1 August 2025.

Teltonika's Security Centre includes a route to report a vulnerability and lists its security advisories. Teltonika has not published a CRA compliance statement on that page, and the CRA's main requirements do not apply until December 2027.

How Millbeck Helps Customers Keep Routers Secure

Millbeck helps customers keep routers secure by shipping them on current firmware, setting up remote updates through Teltonika RMS, and passing on Teltonika security advisories that affect their devices.

  • Current firmware on dispatch. Our router configuration service loads the latest firmware before dispatch, so each router ships with the manufacturer's most recent security fixes.
  • Remote updates through RMS. We help customers set up and use Teltonika RMS, the remote management platform that pushes firmware updates across an estate without site visits.
  • Security advisories passed on. When Teltonika publishes a security advisory affecting routers a customer runs, we tell that customer.
  • Security at the SIM. Our IoT SIM security options, including private APNs and VPNs, keep devices off the public internet, which limits what an attacker can reach while an update is pending.

Ben Finder, Technical Director, Millbeck

'The Cyber Resilience Act puts into law what good hardware makers should already do: fix known vulnerabilities quickly and support products for years, not months. For our UK customers, the practical step is the same whether the law applies to them or not. Keep router firmware current, and know who will tell you when a security fix is released.'

Cyber Resilience Act Key Dates

The Cyber Resilience Act applies in stages, with reporting live now and the main obligations applying from 11 December 2027.

DateWhat Applies
10 December 2024The CRA enters into force
11 June 2026Rules on conformity assessment bodies (notified bodies) apply
11 September 2026Vulnerability and incident reporting applies, and ENISA's Single Reporting Platform goes live
11 December 2027Main obligations apply, and the Radio Equipment Directive cybersecurity rules are repealed

What Should UK IoT Businesses Do Now?

UK IoT businesses should check whether they sell connected products into the EU, and make sure every router they run can be updated and is being updated.

  • Check your EU sales. If you place connected products on the EU market under your own name, the CRA reporting duty applies to you now.
  • Know your firmware position. List the routers in your estate, the firmware each runs, and whether you can update them remotely.
  • Ask about support. Ask your hardware supplier how long each model will receive security updates and how you will hear about fixes. Our CVE glossary entry explains how public vulnerabilities are tracked.

This Is Not Legal Advice

This article gives Millbeck's view of the Cyber Resilience Act for businesses that deploy IoT devices. Take advice from a qualified adviser on your own obligations.

Talk to Millbeck About Router Security

Millbeck is a Teltonika Diamond distributor and IoT SIM provider based in Leeds, UK. We can check the firmware and support status of the Teltonika routers in your estate, set up RMS for remote updates, and supply IoT SIMs with private APN and VPN options. You will speak directly to people who know the technology.

Speak to us about your project

Millbeck. IoT Connectivity

Frequently Asked Questions

Do I Need to Replace Routers Already Installed Because of the Cyber Resilience Act?

The Cyber Resilience Act does not require anyone to replace routers already installed. The European Commission says products placed on the EU market before 11 December 2027 fall under the main requirements only if they are substantially modified after that date. In the UK the CRA does not apply, but keeping installed routers on current firmware remains the most useful security step.

What Are the Penalties for Breaking the Cyber Resilience Act?

The Cyber Resilience Act allows fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaching the essential security requirements or the manufacturer and reporting obligations. Lower caps apply to other breaches. Microenterprises and small enterprises cannot be fined for missing the 24-hour early warning deadline, although the duty to report still applies.

Who Enforces the Cyber Resilience Act?

Each EU Member State enforces the Cyber Resilience Act through market surveillance authorities it designates, and each sets its own penalties within the CRA's limits. These authorities can assess products that present a cybersecurity risk and order non-compliant products off the market. An EU administrative cooperation group coordinates their work so the rules apply consistently.

What Happens to the RED Cybersecurity Rules When the CRA Applies?

The Radio Equipment Directive cybersecurity rules, set by Delegated Regulation (EU) 2022/30, have applied to wireless devices since 1 August 2025. On 16 February 2026, the European Commission adopted a delegated regulation that repeals those rules from 11 December 2027. From that date, the Cyber Resilience Act becomes the cybersecurity rulebook for connected radio equipment such as cellular routers.

Where Can I Read the Official Cyber Resilience Act Guidance?

The European Commission publishes Cyber Resilience Act guidance on its Shaping Europe's Digital Future website. The guidance published on 27 July 2026 covers product scope, substantial modification, support periods, reporting obligations, risk assessment and points for microenterprises and SMEs. ENISA runs the Single Reporting Platform that manufacturers use to file reports.

Sources and Further Reading

Frequently asked questions

No items found.

Share

Related articles

Latest news & insights

KB
September 17, 2026
IoT Security Best Practices
KB
April 20, 2026
IoT Security Guidelines
KB
September 18, 2026
Why Good Signal Strength Does Not Mean Good Connectivity