
Cyber Resilience Act: Monaco Impact
From 11 September 2026, the EU Cyber Resilience Act starts to bite. What it means for Monaco companies that sell software or connected products.
A Deadline Most Monaco Companies Haven't Heard Of
On 11 September 2026, the first hard obligations of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) start to apply. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents to EU authorities — on a clock measured in hours, not weeks.
The instinct in Monaco is to skim past this. Monaco is not an EU member state, so EU regulations do not automatically apply to Monegasque businesses. That instinct is usually right. Here it isn't quite, because the Cyber Resilience Act attaches to where a product is sold, not where the company is registered.
If your Monaco company puts software, an app, or a connected device on the EU market, you are potentially in scope. If you run a restaurant with a booking page, you are not. The gap between those two situations is where the useful work is.
Why Being Outside the EU Doesn't Get You Out of It
The Cyber Resilience Act is market-placement legislation, in the same family as CE marking. It applies to products with digital elements made available on the EU market, regardless of where the manufacturer is established. A company outside the Union that sells into the Union is in scope.
For a non-EU manufacturer the practical consequence is structural: someone inside the EU has to carry the compliance obligations. That means designating an authorised representative established in the EU, or relying on an importer who takes on the relevant duties. For a Monaco software company selling to customers in France, Italy or Germany, this is not a formality you can leave until the product ships — it changes who signs what.
Monaco's position here is genuinely distinctive. Monaco is in the French VAT territory, which routinely gets confused with EU membership. It is not the same thing, and neither fact settles the Cyber Resilience Act question. What settles it is whether you place a product with digital elements on the EU market.
What Counts as a "Product With Digital Elements"
This is where most Monaco businesses will find relief, and where a few will find work.
The regulation covers connectable hardware and software — the Commission's own examples run from baby monitors and smart watches to apps and computer programs. Alongside the product itself, remote data-processing solutions necessary for the product to function are treated as part of that product and are covered too. Products are then sorted into tiers that decide how conformity is assessed: most sit in a default category and can be self-assessed, while tighter tiers cover password managers, VPNs, operating systems and firewalls, and a small critical group such as smart meters and secure elements faces mandatory certification.
In practice, for the typical Monaco business:
- A brochure website, a booking page or a corporate site is not the target of this regulation. Your web development work does not suddenly become a CE-marked product.
- A native mobile app you publish and sell is a much closer call, and deserves a proper look.
- Connected hardware — a device sold with companion software — is squarely what the regulation was written for. Monaco has more of this than people assume, particularly around yachting and building technology.
- Pure standalone SaaS is more nuanced: the scope is built around products rather than services, but cloud components tied to a product's function are pulled in. If your revenue depends on the answer, get it from a qualified adviser.
The 24-Hour and 72-Hour Clock
The September obligation is narrower than full compliance, but operationally demanding. For an actively exploited vulnerability or a severe incident affecting your product's security:
- Early warning within 24 hours of becoming aware.
- Full notification within 72 hours.
- Final report within 14 days of a corrective measure being available for a vulnerability, or within one month for a severe incident.
Reporting goes through the CRA Single Reporting Platform to the relevant CSIRT, the intent being that you report once rather than to every member state separately.
Twenty-four hours is the number that should focus attention. It is not enough time to work out who decides, who writes, and who holds the credentials for the reporting platform. Those questions have to be answered before the incident — the same lesson Monaco businesses learned from the 72-hour breach notification duty under Law No. 1.565, and a good reason to handle both in one piece of work. If you already have an internal process for APDP data protection reporting, extend it rather than starting fresh.
What to Do Before 11 September
- Decide whether you are in scope at all. Write down what you sell, in what form, to whom, and in which countries. Most Monaco companies will finish this in an afternoon with a clear negative — and that written answer is worth having.
- Identify your EU economic operator. Selling products into the EU with no authorised representative or importer arrangement is the gap to close first.
- Name an owner and a route. One person accountable for the 24-hour early warning, with documented access to the platform and a deputy for holidays.
- Know where your software comes from. Reporting on exploited vulnerabilities assumes you know your components. That means a dependency inventory and a monitoring habit — work for an ongoing website maintenance and support arrangement, not a one-off audit.
The Bigger Date Is 11 December 2027
September 2026 is the reporting trigger. The substantive requirements — secure-by-design obligations, vulnerability handling across the support period, technical documentation, conformity assessment and CE marking — apply from 11 December 2027. Notably, the reporting duties reach products already on the EU market, so an application you shipped years ago is not automatically outside the frame.
Fifteen months sounds comfortable and isn't, if your product needs a conformity assessment route or a redesign of how you ship updates. Map your exposure now and 2027 becomes execution rather than improvisation.
One honest caveat: the Act is new, guidance is still being published, and scope questions at the edges — particularly around SaaS — reward a proper legal reading. Where the answer affects your roadmap or your ability to sell into the EU, verify it with a qualified professional. Nothing here is legal advice.
For most Monaco businesses, the right outcome of reading this is a short, documented "not in scope". For the minority building software and connected products for European customers, it is the start of a real project — one that pairs naturally with the digital strategy decisions you are already making about which markets to serve. To work out which side of that line you fall on, get in touch — a short conversation is usually enough to tell.
Related services