Europe Is Writing the Rules Your Gadgets Will Follow

Dark institutional corridor at night with a faint circle of gold stars projected on the floor

Policy · Security · Buyer’s Guide

Europe Is Writing the Rules Your Gadgets Will Follow

SMARTS · 19 August 2026 · 12 min read

On the morning of 11 September 2026, a rule written in Brussels begins to apply to almost everything with a processor that is sold in Europe. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents to EU authorities — an early warning within 24 hours of becoming aware, a full notification within 72, per the European Commission. The same month, several European countries are considering banning Meta’s smart glasses over privacy concerns, per PetaPixel. The two developments run on different legal tracks — one is cybersecurity law, the other privacy law — but they point the same way: the rules your gadgets will follow for the rest of this decade are being written in a city most American buyers will never visit, and they are inheriting the benefits without the vote.

The Feeling First

The Strange Comfort of Being Governed From Abroad

There is an unsettling feeling that comes from being protected by a law you never voted for. Consider what your hallway camera, your doorbell, and your child’s watch are currently obliged to tell you: nothing. The Federal Trade Commission audited 184 connected-product pages and found that only 21 — 11.4 percent — disclosed how long software support would last. The other 88.6 percent of the market treats the fact that determines a device’s usable lifetime as a trade secret.

Now imagine a rulebook that requires the manufacturer to declare a support period at the point of purchase, to keep security updates available for years after release, and to report the vulnerabilities being exploited against its products within hours. That rulebook exists. It is the EU Cyber Resilience Act, and from 11 December 2027 its main obligations apply to products sold in the European Union, per the European Commission. If you live in Ohio or Oregon, you are the beneficiary of a democracy you never participated in.

The feeling is not pure relief. It is the specific discomfort of being governed at a distance — the knowledge that the device on your nightstand is safer because of rules passed by a parliament across the Atlantic, and that nobody asked you. That discomfort is the price of the patchwork.

The Market

One Market, One Rulebook

The timeline is exact, and it is already running. The Cyber Resilience Act entered into force on 10 December 2024, per the European Commission. Reporting obligations apply from 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours of becoming aware and a full notification within 72 hours, filed once through the CRA Single Reporting Platform to their national CSIRT and to ENISA — the platform ENISA is standing up and will operate by the time the obligations bite, per the Commission’s reporting guidance. The main obligations — covering design, development, maintenance, and vulnerability handling — apply from 11 December 2027, per the European Commission. On 27 July 2026, the Commission published practical guidance for manufacturers, per its guidance library.

The scope is the entire connected household. The Commission’s own description of what the Act covers runs “from baby monitors to smart watches,” per the European Commission. Dentons notes the obligations include connected consumer devices, and compliance guides now circulate for IoT manufacturers, such as Cavli Wireless’s CRA guide. Crowell & Moring has called the reporting provision among the most operationally demanding of the Act, and Taylor Wessing’s analysis flags the 24-hour clock as the practical crux. This is not a server regulation. It is an appliance regulation.

Meanwhile, the same region is threatening the flagship product of the wearables market. Several European countries are considering banning Meta’s glasses over privacy concerns, per PetaPixel — the product that has sold seven million pairs, a company-reported, unaudited figure, and that researchers expect to reach as many as 100 million buyers in the next few years, per BBC News. It is also the category’s defining device, holding nearly 70 percent of the market, per the Los Angeles Times — which is why the European scrutiny matters beyond the continent. The Guardian‘s editorial board has told regulators to get on the front foot. Europe is doing two things at once: weighing a ban on the category’s most visible product while writing the security rulebook for everything else. Manufacturers ship one hardware line to the entire world, and the stricter rulebook becomes the baseline for all of it.

The Pain

The American Patchwork

Set the single rulebook against the American picture, which is a pile of fragments. The FTC’s audit of 184 connected-product pages found 11.4 percent disclosing support duration — an audit, not a rule, per the FTC’s report. No federal statute requires a connected-product maker to say how long it will support the thing it sold you.

The public wants the rule. Seventy-two percent of Americans with smart devices say manufacturers should be required to disclose how long software support will last, a finding of a joint statement by Consumer Reports, US PIRG, and the Secure Resilient Future Foundation, per Consumer Reports. California’s SB 898 would push connected consumer products toward support-period transparency — a bill Consumer Reports backs. New York’s S.9267, which requires opt-in for coordinated camera monitoring and caps footage retention at 72 hours for non-subscription devices, passed the state Senate 41–20 in June, per the New York State Senate.

The pain is that none of this covers you yet. Bills, audits, and a single state senate vote do not add up to a right. Your protection depends on your ZIP code, your lawyer, and the goodwill of a company that will one day make a spreadsheet decision about your device. Meanwhile the products keep shipping, and the buyer keeps guessing. American consumers face the worst of both worlds: hardware built to the lowest common denominator, and no law that tells them what the denominator is.

The Numbers

The Small Numbers That Changed the Industry

Twenty-four hours: the window for the early warning on actively exploited vulnerabilities, per the Commission’s reporting guidance, and law-firm walkthroughs such as HLC’s map the cascade in detail. Seventy-two hours: the full notification deadline, per the Commission. And a final report within 14 days of a corrective measure for vulnerabilities, or within a month for severe incidents, per the Commission’s reporting guidance. 11 September 2026: reporting obligations begin. 11 December 2027: full application. 10 December 2024: entry into force — all per the European Commission. Five years: the minimum support period for products placed on the EU market. Ten years: how long each security update must remain available after issue. And the end date of the support period must be stated — at least as month and year — at the time of purchase, per the final text of Article 13.

Now the American column: 21 of 184 pages, 11.4 percent, per the FTC. Seventy-two percent of owners want disclosure, per Consumer Reports and partners. Forty-one votes to twenty in one state senate, per the New York State Senate. The asymmetry is the story. Europe regulates the floor; America audits the absence of one.

The Box

What to Look for on the Box

01

The CE mark

Products will bear it to indicate CRA compliance, per the European Commission. A floor, not a seal.

02

The support end date

At least month and year, stated at the time of purchase, per Article 13(19).

03

A name and an address

Manufacturer identification on the product or its packaging, per Article 13(16).

04

A point of contact

A single point of contact for vulnerability reports, per Article 13(17). An anonymous box was designed for a market with no questions.

The Buy

How to Use Brussels as a Quality Signal

You cannot buy the Cyber Resilience Act. But you can buy as if it exists, and the market will do the rest.

1. Buy dual-market hardware. A device sold in both the United States and the European Union is built to the stricter rulebook, because no manufacturer can easily maintain two firmware lines for one product. All other things equal, the safer buy is the unit that has already cleared the higher bar.

2. Ask for the support period in writing. From December 2027, an EU-market unit must state its support end date at the point of purchase, in an easily accessible manner, per Article 13(19). Until then, ask the seller directly: when does support end? The FTC’s audit says most sellers will be silent, per the FTC. Silence is a data point.

3. Read the CE mark with context. Products will bear the CE marking to indicate CRA compliance, per the European Commission. It is a floor, not a seal of approval — a CE mark without a stated support period is a mark without its substance.

4. Check the box for a name and a point of contact. The CRA requires manufacturers to identify themselves on the product or its packaging and to maintain a single point of contact for vulnerability reports, per Article 13(16)–(17). An anonymous box was designed for a market with no questions.

“The EU did not set out to regulate your home. It set out to regulate its own market — and the two turned out to be the same thing.”

The Fine Print

What the CRA Is Not

1. Not a privacy law. The CRA is a cybersecurity and vulnerability-handling regime — devices must be designed, updated, and maintained to be safe, per the European Commission. It does not govern what companies do with your data. The European calls to ban Meta’s glasses run on a different track — privacy law — per PetaPixel. A CRA-compliant camera is still a camera.

2. Not a longevity guarantee. The support period is a floor that must reflect the expected lifetime of the product, with a minimum of five years, per Article 13(8). The manufacturer chooses the period within the floor. Five years is a minimum, not a promise of five years of excellent service.

3. Not retroactive, and not global. The obligations attach to products placed on the EU market, per the European Commission. A device sold only in the United States may never meet any of them, and the transition window runs until 11 December 2027. Reporting obligations apply now — but to the EU market, per the Commission’s reporting guidance.

4. Enforcement is the open question. National market surveillance authorities will enforce the rules, per the European Commission. The machinery is only as good as the willingness of member-state agencies to fund and operate it. Compliance is a legal floor; it is not a moral one.

The Last Word

None of this is an argument for smugness about European regulation or cynicism about American. It is an argument for reading the box differently. For a decade, the connected-hardware industry sold devices whose lifetimes were corporate secrets — the FTC’s own audit found that 88.6 percent of products never told you, per the FTC. From 11 September 2026, part of the world stops allowing that, and from 11 December 2027 the world’s largest single market will require the answer in writing, at the point of purchase, in month and year, per the final text of Article 13. American buyers inherit that requirement without having voted for it — an odd citizenship, but a real one. Buy like it. Ask the question the rulebook now forces someone, somewhere, to answer. The rules are being written this autumn, and you are not in the room — but you are in the market, and the market is how the rules reach you.

— THE SMARTS DESK

Sources

Research Appendix

Every statistic in this article links to its primary source. Full list, as of 19 August 2026:

Data point Institution Date Source
CRA entered into force 10 December 2024 European Commission 27 Jul 2026 Policy page
Reporting obligations apply from 11 September 2026 European Commission 27 Jul 2026 Policy page
Early warning within 24 hours; full notification within 72 hours; Single Reporting Platform live by 11 September 2026 European Commission 31 Jul 2026 Reporting guidance
Main obligations apply from 11 December 2027 European Commission 27 Jul 2026 Policy page
Scope covers products “from baby monitors to smart watches”; CE marking indicates compliance; practical guidance published 27 July 2026 European Commission 27 Jul 2026 Policy page
Support period at least five years; end date stated at time of purchase (month and year); each security update available at least 10 years after issue; manufacturer identification and single point of contact required CRA Article 13 (final text) 2024 Article 13 text
Reporting obligations include connected consumer devices Dentons 1 Jun 2026 Article
Reporting provision among the most operationally demanding obligations Crowell & Moring 2026 Client alert
Actively exploited vulnerabilities must be reported within 24 hours Taylor Wessing 3 Nov 2025 Overview
Several European countries considering banning Meta’s smart glasses over privacy concerns PetaPixel 4 Aug 2026 Article
Audit of 184 connected-product pages: only 21 (11.4%) disclosed software-support duration; 88.6% did not FTC FTC report (PDF)
72% of Americans with smart devices want mandatory support-duration disclosure Consumer Reports / US PIRG / Secure Resilient Future Foundation 12 Mar 2025 Joint statement
California SB 898: support-period transparency for connected consumer products (backed by Consumer Reports) Consumer Reports 6 Apr 2026 Research note
NY S.9267 passed Senate 41–20: opt-in for coordinated monitoring; 72-hour retention cap for non-subscription devices New York State Senate 2 Jun 2026 Bill page
Meta glasses: 7 million pairs sold (company-reported, unaudited); up to 100 million buyers expected BBC News 13 May 2026 Report
Smart-glasses shipments +139% YoY in H2 2025; AI glasses 88% of category Counterpoint Research 26 Feb 2026 Insight

Leave a comment