Two years ago, adding smart glasses to an optical catalogue was a curiosity line. This year it is a real category with real volume, sold through real optical retail, with prescription lenses fitted to it.
It is also, in the European Union, a product with digital elements — and on 11 September 2026 the first operative deadline of the EU Cyber Resilience Act arrives.
If your catalogue is entirely passive eyewear, this post is a bookmark for the day that changes. If you have anything with a camera, a microphone, a speaker, a display, a companion app or a Bluetooth chip in it, read the section on who counts as the manufacturer, because that is where merchants get caught. Then read the note at the end about what happens the following day, because the 11th is not the only date on your calendar that week.
What actually happens on 11 September
The Cyber Resilience Act entered into force in December 2024 with a staged timetable. Most of it — CE marking, the essential cybersecurity requirements, conformity assessment, technical documentation — applies from 11 December 2027. That is the date the industry is planning around. (One earlier tranche has already passed: the chapter governing notifying authorities and notified bodies has applied since 11 June 2026.)
But the reporting obligations start fifteen months earlier, on 11 September 2026, and they are sharp:
- Actively exploited vulnerabilities: early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure being available.
- Severe security incidents affecting product security: 24 hours, 72 hours, and a final report within one month.
- Reports go through the CRA Single Reporting Platform to the relevant national CSIRT, with ENISA notified in parallel.
- Affected users must be told about the vulnerability and the fix without undue delay.
ENISA's Single Reporting Platform opens on 11 September itself — the day the obligation starts, with no run-in, and with mandatory reporting only in this first phase. If it is unavailable when you need it, ENISA's guidance is to contact your national CSIRT directly where the matter cannot wait, and to file through the platform anyway once it is back.
A 24-hour clock is a genuinely demanding operational requirement. It means someone has to be reachable, has to know what the threshold is, and has to have the reporting route set up in advance. Nobody assembles that in 24 hours.
These reporting duties fall on manufacturers. Which raises the only question in this post that really matters to a retailer.
Are you the manufacturer? You might be
The CRA follows the standard EU product-law structure: manufacturers carry the heavy obligations, and importers and distributors carry lighter verification and notification duties. Importers and distributors are broadly expected to check that the required documentation and markings exist, to refrain from placing non-compliant product on the market, and to inform the manufacturer and the market surveillance authorities when they become aware of a cybersecurity risk.
That is manageable. The trap is written into the Regulation itself. Article 21 provides that an importer or distributor “shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14” where it places a product with digital elements on the market under its own name or trademark, or carries out a substantial modification of a product already placed on the market. Article 14 is the reporting article — the one whose clock starts on 11 September. So the provision that catches a private-label seller is precisely the one that bites first.
None of this is a CRA innovation. It is how the New Legislative Framework has worked for years, and it is the same logic that catches private-label sellers under the GPSR. The CRA simply writes it down.
So consider the eyewear-specific version of that. An optical brand finds a contract manufacturer in Shenzhen making an audio frame. It puts its own logo on the temple, ships it under its own brand, and sells it to European customers.
Under Article 21, that brand is not a distributor of somebody else's smart glasses. It is the manufacturer of a product with digital elements for the purposes of this Regulation — with the reporting clock from September 2026, and CE marking, technical documentation and conformity assessment from December 2027, for a device whose firmware it did not write and cannot patch.
That is the scenario worth an hour of someone's attention this fortnight. Not “do we sell connected eyewear” but “whose name is on it, and who can actually ship a firmware fix”.
There is a second wrinkle. Connected consumer wearables may not sit in the default self-assessment category at all — the CRA's tiered annexes push certain wearable and security-relevant product classes into a stricter regime with tighter conformity assessment routes. Where exactly a camera-equipped or health-adjacent smart frame lands is a question for someone reading the annexes against your specific product, not for a blog post. But the difference between the default tier and the tier above it is the difference between a self-declaration and a third-party assessment, and it is not a difference you want to discover in late 2027.
What the penalties look like
Article 64 sets the fines in the way that has become standard for EU digital regulation, and they are large:
- Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential cybersecurity requirements and the reporting obligations in Articles 13 and 14.
- Up to €10 million or 2% for other obligations.
- Up to €5 million or 1% for supplying incorrect or misleading information to notified bodies and market surveillance authorities.
Note where the top tier sits. The reporting duty that starts this week, and the article that makes an own-brand seller a manufacturer subject to it, are both in the most expensive band.
Alongside that sit the practical consequences that arrive much sooner than a fine: market surveillance authorities can order withdrawal or recall, and marketplaces and logistics partners have shown, through the GPSR enforcement wave, that they will pull listings on their own initiative long before a regulator does.
Realistically, no market surveillance authority is opening 2027 by fining a boutique optical store. The likelier path is exactly what happened with GPSR: a compliance email from a marketplace with a two-week deadline and a document request you cannot satisfy, and the listing goes dark in the meantime.
The other date, one day later
On 12 September 2026 — the next day — a different European regulation reaches the same shelf. The EU Data Act's access-by-design obligation applies to connected products placed on the market from that date: the data a connected product generates has to be accessible to the user.
It is a completely unrelated regime with a completely different purpose, and the only thing it has in common with the Cyber Resilience Act is the list of SKUs it lands on and the week it lands in. That is precisely why it is worth mentioning here rather than leaving to a separate audience: the inventory you are about to compile for the 11th is the same inventory you need for the 12th, and the email you are about to send your supplier can carry both sets of questions.
There is also a sting in the Data Act half that is worth knowing before you send that email. The 12 September date is the engineering obligation, and it sits on manufacturers. The provision that reaches a retailer — the pre-contractual duty to tell the buyer what data the product generates, how it is stored, and how they get at it — has applied since September 2025. If you sell connected eyewear, the deadline in the news is not the one you have already missed. That is the subject of its own post, and it should be the next thing you read.
What an eyewear seller should actually do this month
Inventory the connected SKUs. Anything with a chip, an app or a radio in it. For most stores this list has between zero and five items on it, and knowing that is worth the hour. Keep the list — it is the input to the Data Act work too.
For each one, write down who the manufacturer is. Not who made it — who is named on it and who placed it on the EU market. If the answer is “us”, escalate it now.
Get the CE marking and the documentation from your supplier in writing. For genuine distribution this is most of your obligation, and it is a purchase-order question, not a legal project.
Ask who patches the firmware, and how fast. The 24-hour reporting clock is meaningless without a party who can produce a fix. If the contract with your supplier is silent on security updates and disclosure, that is the gap.
Send one supplier email, not two. While you are asking about CE marking, security updates and disclosure routes, ask what data the product generates, where it is stored, for how long, and how a user gets a copy of it. Same supplier, same week, two regulations, one reply to chase.
Set the reporting route up before you need it. If you are the manufacturer, know which national CSIRT you report to and who inside the business is allowed to press send at two in the morning.
Keep the passive catalogue out of it. A frame with no electronics in it is not in scope of either regime. Do not let a compliance panic spread across four hundred SKUs that the regulation does not touch.
Where this joins up with the rest of your compliance load
Look at what has landed on European eyewear orders in fourteen months. The de minimis exemption was removed and duty now attaches per tariff line. Packaging came under PPWR in August, with registration and empty-space duties on every parcel. GPSR enforcement is pulling listings over missing Responsible Person details. AI Act transparency obligations began applying in August. The connected part of the catalogue enters a cybersecurity regime with a 24-hour clock on the 11th of this month — and a data-access regime on the 12th.
Every one of those attaches to the imported physical object and the parcel it travels in. Not one of them attaches to the prescription lens work — which is domestic, configured per customer, carries no CE marking obligation, no firmware, no packaging register, and generates no product telemetry anyone has a right of access to.
That is now the fifth time this year the same structural conclusion has arrived from a different direction. The regulated, tariffed, reportable part of an eyewear business is the hardware. The unregulated, high-margin, defensible part is the lens configuration and the prescription relationship. A catalogue of a few connected hero products supported by a deep prescription business is a very different compliance profile from a catalogue built the other way round — and it happens to be the more profitable shape as well.
Frequently asked questions
Does the CRA apply to ordinary prescription glasses? No. It covers products with digital elements — hardware or software that connects to a device or network. A passive frame with prescription lenses is outside its scope, though it remains subject to GPSR and the eyewear product rules.
We only resell smart glasses from a known brand. What do we have to do? As a distributor, broadly: check that CE marking and required documentation are present, do not sell product you know to be non-compliant, and notify the manufacturer and the authorities if you become aware of a cybersecurity risk. Confirm the precise list with the regulation's distributor article rather than with this summary. Note separately that the Data Act's pre-contractual information duty may reach you as a seller even where the CRA does not.
We sell a private-label smart frame. Is that different? Yes, and materially so. Article 21 provides that an importer or distributor placing a product with digital elements on the market under its own name or trademark is considered a manufacturer for the purposes of the Regulation and is subject to Articles 13 and 14 — Article 14 being the reporting article whose clock starts on 11 September. This is the single question worth taking to counsel.
What if we are outside the EU? The regulation reaches products placed on the EU market regardless of where the business is established. Being a US or UK company is not an exemption.
Is 11 September the compliance deadline? It is the deadline for the reporting obligations. The bulk of the requirements — CE marking, essential requirements, conformity assessment — apply from 11 December 2027.
What is the 12 September date I keep seeing? That is the EU Data Act, not the CRA — a separate regulation about access to the data a connected product generates. It reaches the same products in your catalogue one day later. See the Data Act post for what it asks of sellers specifically.
This article is general information about regulatory developments, not legal advice. Rules of this kind apply differently depending on your catalogue, your suppliers and where you sell; take advice on your own position before acting.
VisioncarePro adds structured prescription capture and lens selection to any Shopify product, including smart frames that need Rx inserts. The lens step is the part of your catalogue nobody regulates and everybody pays for. Free to install.
Install VisioncarePro free on the Shopify App Store →
Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 13, 14, 21, 64 and 71, read from the EUR-Lex consolidated text (CELEX 02024R2847-20241120) · Regulation (EU) 2023/2854 (Data Act) · ENISA, “Single Reporting Platform” and its FAQ, enisa.europa.eu · European Commission, “Cyber Resilience Act — Reporting obligations”, digital-strategy.ec.europa.eu · Crowell & Moring, “EU Cyber Resilience Act Countdown: 11 September 2026 Incident/Vulnerability Reporting Deadline” · Wilson Sonsini, “New EU Cybersecurity Obligations for Connected Devices” · Freshfields, “Decoding the Cyber Resilience Act — Part 1: Scope and Impact”.