
Compliance & News
Cyber Resilience Act from 11 September 2026: What it means for connected vending machines
From 11 September 2026, the notification obligations of the Cyber Resilience Act take effect, and they cover not only new devices. Manufacturers must report actively exploited vulnerabilities and serious security incidents within 24 hours going forward, even for products already in the field. For vending-machine operators, this is not an obligation, but a change in the relationship with the supplier.
The basis is Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements, announced on 20 November 2024 and in force since 10 December 2024. The full requirements for new products do not take effect until 11 December 2027. The notification obligations come two and a half years earlier.
What must be reported from September onwards
Two types of event trigger the obligation: an actively exploited vulnerability in the product and a serious incident that affects the security of the product. The recipient is not a German authority alone, but simultaneously the national CSIRT designated as coordinator and the EU agency ENISA, via a joint notification platform.
The timeline is tight. Within 24 hours of becoming aware, an early warning is issued; within 72 hours, a more detailed report. The final report follows for a vulnerability no later than 14 days after a fix or risk mitigation becomes available, for an incident one month after the 72-hour report. Micro and small enterprises are not subject to a fine if they miss the 24-hour deadline for the early warning.
The point that affects the installed base
What is interesting for operators is the distinction by manufacturing year, and it turns out differently than expected. Products placed on the market before 11 December 2027 are not subject to the publication obligation. However, the notification obligations under Article 14 apply to them from 11 September 2026 onwards.
For the notification obligation, what matters is the in-market installed base, not the manufacturing year. If you operate a connected vending machine today whose manufacturer must report an exploited vulnerability within a day from September onwards, you will notice something: in the form of security advisories, updates and possibly service appointments.

Whether your vending machine is affected depends on the configuration ordered
According to the regulation, a product with digital elements is hardware or software together with associated remote processing solutions whose intended use includes a direct or indirect data connection to a device or network. Excluded are, among others, medical devices, vehicles and civil aviation products. Coffee vending machines and sales machines are not excluded.
What matters is not the model, but the configuration. And it is less commonly networked than market communications suggest. In our own test database, of 25 machines reviewed, 7 have telemetry as standard, 13 others have it as explicitly optional—meaning it is only present if the module was ordered with the machine. One device has no telemetry provisions; four lack the specification in their datasheets. A specification of connection type—such as Ethernet, WLAN, Bluetooth or cellular—is found in 14 of the 25 machines.
This leads to an uncomfortable insight for your own inventory: two machines of the same model can be affected differently if one has the telemetry module and the other does not. Add to this the payment terminal, which itself is a product with digital elements, regardless of whether the vending machine is otherwise networked.

What operators should do now
The obligation rests with the manufacturer—the party that develops or has the product manufactured and markets it under their name or brand. An operator who purchases and installs vending machines is not that party. However, anyone distributing machines under their own brand should take the manufacturer definition seriously.
Three steps make sense regardless. First, inventory: document for each location which machine actually has a data connection, what type it is, and whether a payment terminal is installed. Second, the channel: clarify which address the manufacturer sends security advisories to and who reads them in your own organization. An advisory that lands in a departed colleague's inbox is lost. Third, the path for updates: whether a security update can be deployed remotely or requires an on-site technician determines response time and cost. This belongs in the service contract, not in improvisation.
What comes next
The full requirements take effect on 11 December 2027. From then on, new products must meet the basic cybersecurity requirements before being placed on the market, vulnerabilities must be addressed throughout the product lifecycle, and users must be informed accordingly. By then, the establishment of conformity assessment bodies and marking requirements will be underway, which will visibly change procurement from 2028 onwards.
For the coming weeks, 11 September remains the relevant date, and practical preparation consists not of technology but of two lists: which machines are networked and who reads the manufacturer's notifications.
Legal status as of 17 August 2026. Two points remain open here because they could not be conclusively confirmed from publicly available summaries: the specific penalty frameworks and the conditions under which an importer or distributor is treated as a manufacturer. Both are stated in the regulation text and should be verified there or with the competent authority if in doubt. The networking figures refer to the 25 currently published test reports on this site and to manufacturer datasheet specifications, not to the overall market.
Frequently asked questions
- From when do the notification obligations of the Cyber Resilience Act apply?
- From 11 September 2026. The full requirements for new products do not take effect until 11 December 2027; the notification obligations come two and a half years earlier.
- Must a vending-machine operator report incidents themselves?
- No. The obligation rests with the manufacturer—the party that develops or has the product manufactured and markets it under their name. An operator who purchases and installs vending machines is not that party. However, anyone distributing machines under their own brand should take the manufacturer definition seriously.
- Are vending machines in the installed base affected?
- For the notification obligations under Article 14, yes, from 11 September 2026 onwards. Products placed on the market before 11 December 2027 are exempt from the publication obligation. For the notification obligation, what matters is the in-market installed base, not the manufacturing year.
- How do I know if my vending machine counts as a networked product?
- By its configuration, not by its model. Of 25 machines reviewed, 7 have telemetry as standard, 13 have it as explicitly optional. Two machines of the same model can therefore be affected differently. Add to this the payment terminal, which itself is a product with digital elements.
More news

EUDR from 30 December 2026: What the Deforestation Regulation means for coffee in vending machines
The EU Deforestation Regulation takes effect on 30 December 2026 for coffee too. What vending machine operators need from their suppliers and what they don't need to do themselves.

Packaging Law from 12 August 2026: What's New for Vending-Machine Operators
The new packaging implementation law applies from 12 August 2026. What vending-machine operators need to know about registration, verification thresholds and deadlines.
