Brussels, Sets

Brussels Sets Two Clocks Running: Data Access Rules Arrive First, Full Cyber Compliance by December 2027

Published on 10/03/2026 at 02:51 | Editorial boerse-global.de

EU Data Act rules apply since 12 September 2026, while non-compliant digital products lose EU market access on 11 December 2027 under the Cyber Resilience Act.

EU Data Act and Cyber Resilience Act: 2027 Market Access Deadline Looms
Brussels Sets Two Clocks Running: Data Access Rules Arrive First, Full Cyber Compliance by December 2027 Illustration mit AI erstellt.

European manufacturers and their suppliers are working to two separate regulatory deadlines that will reshape how industrial equipment handles data and how it is secured. The earlier of the two has already passed into force, while the later one threatens to shut non-compliant products out of the EU market entirely.

What the Data Act demands of connected products

Since 12 September 2026, makers of connected products and related services must build easy, secure data access into any device placed on the market after that date, in line with Article 3(1) and Article 50 of the Data Act. For networked industrial goods, that means access to usage and operational data has to be designed into the product itself rather than bolted on afterwards. Machine-readable, near-real-time access, interoperability and safeguards for trade secrets all form part of the package.

Users of connected devices can, as a rule, request the product and service data they generate free of charge and pass it on to third parties. Micro and small enterprises benefit from limited exemptions covering certain products and services they manufacture themselves.

Non-compliance carries consequences: reports point to possible fines under the Data Act, though no specific figures have been cited. A further deadline is already visible on the IT infrastructure side — cloud providers must drop switching fees from 12 January 2027.

Industrial firms are now being urged to map out their exposure to cloud and platform vendors. Specialist commentary recommends locking data access rights and exit scenarios into contracts, covering both termination and provider insolvency, and writing interoperability and data export requirements into tender documents. Proprietary cloud systems and tangled digital supply chains, the argument goes, put a company's grip on its own operational and production data at risk, and open interfaces plus open digital infrastructure are seen as the way to reduce reliance on any single vendor. Storm Reply is among the companies promoting data platforms and data-driven services for this purpose.

Cyber Resilience Act: reporting duties are live, market access ends in 2027

Running alongside the data rules is a second layer of obligations. Consultancy EY notes that the Cyber Resilience Act turns cybersecurity into a mandatory product requirement for anything with digital elements, with manufacturers obliged to supply security evidence across the entire support period. Where the Cyber Resilience Act governs product safety, rules such as NIS2 and the NISG 2026 cover day-to-day operations.

Some reporting duties are already active. Since 11 September 2026, manufacturers of digital products must issue an early warning within 24 hours and a detailed report within 72 hours. Responsibilities are split across four roles, and anyone who modifies a product or markets it under their own name counts as a manufacturer. How much testing is required depends on the product class. Pure cloud and SaaS services generally fall outside the Cyber Resilience Act's scope. The hard cutoff comes on 11 December 2027, when products that do not conform lose access to the EU market.

Legacy plant equipment is the sticking point

Process plant operators face the sharpest challenge. The Cyber Resilience Act calls for binding measures including secure software updates, structured vulnerability management and transparency about the components used. Yet industrial process facilities frequently run field equipment that is 10, 20 or more years old.

One recommended route is to migrate the control layer step by step from Profibus DP to Profinet while keeping existing field devices and cabling in place. Profinet brings higher bandwidth along with redundancy mechanisms and network-based security concepts, and Softing is marketing a gateway aimed at exactly this transition.

€11.5 million on offer for smaller firms

To ease the burden on smaller businesses, EU funding is available. The SECURE initiative has opened a second call for European micro, small and medium-sized enterprises, with €11.5 million available and applications accepted until 11 December 2026. The money is intended to help firms prepare for the Cyber Resilience Act and to fund general cybersecurity measures for products with digital components.

The first call made €5 million available and drew roughly 260 applications from 28 European countries. Overall, the programme's budget comes to just under €22 million, of which around €16 million is earmarked for direct support to small and medium-sized enterprises.

Disclaimer...

en | boerse | 70219000 |