The EU Cyber Resilience Act: What Georgian Technology Companies Should Do Before September 2026
The EU Cyber Resilience Act incident-reporting duties begin on 11 September 2026. What does this mean for technology businesses operating from Georgia?
Cyber incidents are now legal and commercial events
The EU Cyber Resilience Act (CRA) introduces cybersecurity requirements across the life cycle of products with digital elements. The European Commission’s 27 July 2026 guidance confirms that reporting duties for actively exploited vulnerabilities and severe incidents begin on 11 September 2026, while the Act becomes fully applicable on 11 December 2027.
This matters to Georgian businesses selling software, SaaS, IoT devices, apps or embedded software into the EU. Market access increasingly requires evidence of secure design, vulnerability handling, updates and incident response.
If an incident happens in Georgia
Georgia’s Law on Information Security defines public- and private-sector responsibilities for information-security protection. If personal data is exposed, the Law on Personal Data Protection may also apply. One incident can therefore raise contract, customer-notification, regulatory-cooperation and damages questions.
Seven-point checklist
- Map every product that connects to a network, app or service.
- Inventory assets, third-party providers, open-source components and support periods.
- Create a vulnerability intake, assessment, remediation and customer-notification process.
- Appoint an incident owner and an emergency contact channel.
- Review customer, distributor and cloud-provider contracts.
- Preserve logs, risk assessments, patches and decision records.
- Decide in advance when to involve counsel, technical experts and a data-protection specialist.
CRA may not automatically cover every Georgian business, but its requirements are already becoming part of international contracts, insurance and investor due diligence. Preserve evidence and assess data exposure before making public statements.
## წყაროები / Sources - European Commission, CRA business guidance, 27 July 2026: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-new-guidance-support-businesses-implementation-cyber-resilience-act - European Commission, CRA reporting obligations: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting - Law of Georgia on Information Security: https://matsne.gov.ge/en/document/view/1679424?publication=8 - Law of Georgia on Personal Data Protection: https://www.matsne.gov.ge/en/document/view/5827307
NoticeThis publication is for general information and is not individual legal advice.