Skip to content
Entourage
News6 min read

Three cyber deadlines hit the same teams, and the first one has already passed

11 and 12 September 2026 are one day apart. The first starts the reporting obligations under the Cyber Resilience Act, the second brings the Data Act design obligation to bear on newly placed connected products. The third deadline is not a coming one: the German NIS-2 implementing act has applied since December 2025.

EE

Entourage Editorial Team

In brief

Cyber Resilience Act, Regulation (EU) 2024/2847: reporting obligations from 11 September 2026, main obligations from 11 December 2027. Data Act, Regulation (EU) 2023/2854: the design obligation in Article 3(1) applies to connected products and related services placed on the market after 12 September 2026. NIS2UmsuCG: in force since 6 December 2025, registration with the BSI within three months, reporting chain of 24 hours, 72 hours, 30 days.

Anyone tracking cybersecurity obligations for connected medical devices and pharmaceutical sites usually has two dates in the calendar, both in September 2026. They are indeed one day apart. The real finding is a third date, and it does not lie in the future.

11 and 12 September 2026

The Cyber Resilience Act, Regulation (EU) 2024/2847, has been in force since 10 December 2024 and bites in stages. The reporting obligations apply from 11 September 2026, the main obligations only from 11 December 2027. Between them lies a year and three months in which you must report what need not yet be fully in place. Conformity assessment bodies have been notifiable since 11 June 2026. The Commission published practical implementation guidance on 27 July 2026.

One day after the CRA date, the Data Act, Regulation (EU) 2023/2854, takes hold. Its Article 50(3) is unusually precise, and the wording decides who is caught: the obligation under Article 3(1) applies to connected products and related services placed on the market after 12 September 2026.

That is not a transition period for the installed base. It is a cut-off tied to placing on the market. A product on the market on 12 September 2026 does not carry the Article 3(1) design obligation. The same product, in a variant placed on the market from 13 September, does. For development programmes launching in autumn 2026 this is not a footnote but a switch.

One qualification belongs here, and we write it down rather than leave it out: that connected medical devices and health wearables fall within scope is the consistent reading of several law firms, not a finding we verified against the legal text. Anyone basing an investment decision on it should have the classification of their own product examined legally rather than taken from an article, including this one.

The third deadline is the oldest, and it is not an announcement

NIS-2, Directive (EU) 2022/2555, had a transposition deadline of 17 October 2024. Germany missed it, along with many others: in November 2024 the Commission opened infringement proceedings against 23 member states, and on 7 May 2025 it sent a reasoned opinion to 19, Germany among them.

That is settled. The Bundestag adopted the NIS2UmsuCG on 13 November 2025, the Bundesrat on 21 November 2025, it was promulgated in Federal Law Gazette 2025 I No 301 of 5 December 2025, and it has applied since 6 December 2025. Implementation runs mainly through the recast BSI Act. The BSI now supervises around 29,500 entities.

From this follows a deadline that has quietly passed in many organisations. Registration with the BSI is due under Section 33 BSIG within three months of an entity first being in scope. For everyone in scope on 6 December 2025, that deadline expired by calculation in early March 2026. This cut-off is our arithmetic from two officially documented figures, the entry into force and the three-month period, and not a date any authority has published as such. The two figures it follows from are documented.

Two annexes, two routes into scope

Being in scope is decided in two steps: first the type of entity under Annex 1 or Annex 2 BSIG, then the size threshold under Section 28.

Annex 1, health sector, covers among others healthcare providers, EU reference laboratories, research and development of medicinal products, the manufacture of pharmaceutical products and the manufacture of critical medical devices.

Annex 2 assigns the manufacture of medical devices and in vitro diagnostics to manufacturing industry.

This is where the most common mistake happens. A device manufacturer looks in the health sector, does not find itself there because it sits in Annex 2, and concludes it is out of scope. Conversely, the same manufacturer may land in Annex 1 after all through the manufacture of critical medical devices. Which products count as critical additionally depends on the thresholds of the BSI-KritisV, and we have not checked those for individual product categories.

For the size threshold we deliberately give only the figure we can evidence in the legal text. An important entity under Section 28(2) no. 3 BSIG is one with at least 50 employees, or with annual turnover and annual balance sheet total each above 10 million euros. The higher thresholds for essential entities circulate in secondary sources with figures taken from the SME definition. We could not verify them in the legal text and therefore do not state them. Anyone who needs them should read Section 28(1) BSIG verbatim.

The BSI provides a scope self-assessment. It does not replace a legal review, but within half an hour it answers whether one is needed at all.

Three obligations, and a clock that runs faster than expected

Entities in scope carry three central obligations: registration with the BSI, reporting of significant security incidents, and implementation and documentation of risk management measures.

The reporting chain is the part most often underestimated, because it runs in three stages and the first is very short: 24 hours for the early warning, 72 hours for the incident notification, 30 days for the final or progress report, each from becoming aware. A 24 hour early warning is not a task for an escalation chain that is assembled after something has happened. For operators of critical installations the evidence cycle at least extends from two years to three.

Why the three belong together rather than in sequence

It is tempting to give the three regimes three owners: the CRA to product development, NIS-2 to IT, the Data Act to legal. That is precisely where such programmes fail.

The CRA catches the product, NIS-2 the organisation, the Data Act the moment of placing on the market. For a connected medical device that is one thing seen from three sides. Vulnerability reporting under the CRA and incident reporting under the BSIG run through the same people, often through the same phone number. Build two separate reporting processes and you have two clocks and one crew when it matters.

What to do now

Four steps, in this order:

  1. Answer the registration question in writing, this week. Not whether you are in scope, but whether you are registered. If the answer is no and you are in scope, the Section 33 BSIG deadline has already passed, and that belongs documented and remedied, not deferred.
  2. Look for your entity in Annex 1 and Annex 2, in both. Checking only the health sector misses the manufacturing assignment, and the reverse.
  3. Design the reporting chain for 24 hours, not 72. With named people, an on-call rota and a form somebody has filled in once already.
  4. Hold every development programme launching from autumn 2026 against 12 September 2026. A date that is being planned anyway decides a design obligation here.

The order is not a matter of style. Step 1 concerns a deadline that is probably already running, step 4 one that can be planned. Start at the other end and you work the visible date while the invisible one sits untouched.

Relevant for your project?

Similar questions in your current project?

In a first call we clarify what is specifically relevant for your situation, without obligation.

Request a call

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • Regulation (EU) 2024/2847 (Cyber Resilience Act)
  • Regulation (EU) 2023/2854 (Data Act), Article 3(1) and Article 50(3)
  • Directive (EU) 2022/2555 (NIS-2)
  • NIS2UmsuCG, Federal Law Gazette 2025 I No 301 of 5 December 2025
  • German BSI Act (BSIG), Section 28 (scope) and Section 33 (registration), Annex 1 and Annex 2
Sources
  • European Commission, Cyber Resilience Act, summary and reporting pages (digital-strategy.ec.europa.eu), practical guidance published 27 July 2026
  • Regulation (EU) 2023/2854, Article 50(3), official German language version, OJ L 2023/2854 of 22.12.2023 (CELEX 32023R2854)
  • BSI, NIS-2 FAQ, sector-specific FAQ, list of obligations and press release of 5 December 2025
  • German Bundestag, text archive kw46-de-nis-2; Bundesrat, decision of 21 November 2025
  • gesetze-im-internet.de, BSIG 2025, Section 28, Section 33, Annex 1 and Annex 2

Your project

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +49 89 4161170-0
info@theentourage.us

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences