This is Hamamoto from TIMEWELL. When Japanese companies try to sell into Europe, I still hear the same line: there are too many EU rules, and nobody knows where to start.
Export controls, product cybersecurity, personal data, CE marking, carbon border measures. Listing the names is exhausting. 2026 is the year several of them move at once. From 11 September, Cyber Resilience Act (CRA) reporting starts, and manufacturers that have not built a detection and support process are already short on time1.
This piece organises the main rules Japanese exporters face when shipping to or placing products on the EU market, as of 21 July 2026, using primary sources. First a priority table, then the detail by domain.
One table first: which EU rules matter most
| Priority | Domain | Core rule | 2026 operational anchor | Why Japanese firms feel it |
|---|---|---|---|---|
| 1 | Product cyber | CRA | 11 September 2026: vulnerability and severe-incident reporting | Smart devices, industrial IoT, software, embedded parts — early warning within 24 hours |
| 2 | Export control | Dual-Use Regulation 2021/821 | Continued use of the 2025 Annex I update | Classification plus Articles 4 and 5 catch-alls |
| 3 | Carbon border | CBAM | 1 January 2026: definitive regime | Steel, aluminium, and other covered imports; exporters supply emissions data |
| 4 | Product safety | CE / Machinery Regulation | New Machinery Regulation applies 20 January 2027 | AI-enabled machinery and cyber risk enter CE conditions |
| 5 | Chemicals | RoHS / REACH | Ongoing exemption and SVHC updates | Substance control and information duties at part level |
| 6 | Data and organisations | GDPR / NIS2 | GDPR procedure regulation in force from 2026; cross-border cases build from April 2027 | Even out-of-scope firms feel customer requirements |
Priority here is a mix of fine size and whether operations change inside 2026. Patchwork fixes cost more than designing compliance into the product lifecycle.
If you still lack a clean classification form for list and catch-all checks, start with the export classification template pack (2026). It is written for Japan’s FEFTA process, but the same discipline helps when you document EU Annex I decisions.
1. Export control — list controls and catch-alls
The EU controls dual-use goods, software, and technology that can serve civilian and military purposes. Japan has its own Foreign Exchange and Foreign Trade Act regime, but the EU framework is separate. Even when the first destination is the EU, re-exports and intra-EU transfers can create unexpected licence needs.
Dual-Use Regulation and the control list
The foundation is Regulation (EU) 2021/821. Controlled items sit in Annex I. Exports of listed goods, technology, and software generally require a licence2.
The 2025 control-list update refined and expanded coverage in areas such as quantum technology, semiconductor manufacturing equipment, advanced integrated circuits, advanced materials, and certain biosecurity-related equipment. The change tracks Wassenaar understandings and moves in the US and UK. Re-run classification if your catalogue sits near those edges.
| Area | Examples of tightened focus |
|---|---|
| Quantum | Quantum computers, cryogenic electronics, parametric amplifiers, cryogenic cooling |
| Semiconductor manufacturing | Atomic layer deposition, advanced lithography, EUV-related items, SEM, etch tools |
| Advanced electronics | Specific high-end computing devices |
| Advanced materials | High-temperature coatings; high-entropy alloy and refractory metal powders for metal 3D printing |
| Bio-related | High-purity peptide synthesis equipment and similar items |
Catch-all impact in practice
Not on the list does not mean free to ship. Unlisted items can still need a licence or a notification when end use or end user raises concern.
Two provisions matter most in day-to-day work:
- Article 4 military end-use catch-all — applies where there is a military end-use risk, including certain destinations subject to arms embargoes.
- Article 5 cyber-surveillance catch-all — can require notification when the exporter becomes aware that unlisted cyber-surveillance items may be used in connection with serious human rights abuses. Commission guidance has made due-diligence expectations more concrete since 2024.
If your product sits near face recognition or network inspection, do not treat Article 5 as someone else’s problem.
Japan-side classification and EU Annex I classification do not automatically match. Keep both paper trails. For the Japan side, see how METI classification works and list controls versus catch-all controls.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
2. Cybersecurity — CRA is the 2026 mountain
Cyber Resilience Act
The CRA, which entered into force in December 2024, requires cybersecurity measures across the lifecycle of products with digital elements sold in the EU. Scope is broad: smart appliances, industrial IoT, software, embedded components1.
| Date | What happens |
|---|---|
| Around 10 December 2024 | CRA enters into force |
| 11 June 2026 | Chapter IV on notifying conformity assessment bodies applies |
| 11 September 2026 | Manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents apply |
| Through 2026 | Harmonised standards continue to mature |
| 11 December 2027 | Main product obligations fully apply |
From 11 September 2026, manufacturers must generally provide an early warning within 24 hours of awareness, a fuller notification within 72 hours, and follow-up reporting afterward, via the Single Reporting Platform operated with ENISA3. Legacy products already on the market can be in scope. Designing only for next-generation SKUs is not enough.
Fines can reach 2.5% of worldwide annual turnover or EUR 15 million, whichever is higher. This is a board-level risk.
NIS2 and supply-chain spillover
NIS2 tightens cybersecurity duties for essential and important entities across energy, transport, finance, health, digital infrastructure, and other sectors. Member State transposition has been uneven, and the Commission has pursued enforcement against late countries. Through 2026, national regimes keep coming online.
Direct duties fall on EU operators, but those operators must manage supply-chain security. Japanese suppliers increasingly see NIS2-level questionnaires and contract clauses from EU customers.
3. GDPR — enforcement plus procedure
Two practical points for 2026:
- Transparency as a coordinated enforcement theme — privacy notices that exist only on paper are not enough.
- The GDPR procedural regulation (in force from January 2026) streamlines cooperation among supervisory authorities. Broader application to new cross-border cases is expected from April 2027. Faster investigations mean shorter response windows.
If a product includes cloud services or apps, review CRA product security and GDPR data duties in the same design gate.
4. Product safety and environment — CE to carbon border
CE marking and the new Machinery Regulation
CE marking signals conformity with EU safety, health, and environmental requirements. Many products cannot be placed on the market without it.
A major shift is Machinery Regulation (EU) 2023/1230, which replaces the old Machinery Directive and applies from 20 January 2027. It brings AI-enabled machinery and cybersecurity risk assessment into the frame. Digital instructions may be allowed under conditions, while certain safety information can still require paper. From 2027 onward, CE and CRA will increasingly reinforce each other.
RoHS and REACH
RoHS (hazardous substances in electrical and electronic equipment) and REACH (chemicals) remain baseline European export controls.
Market surveillance still finds RoHS non-conformity. Complex supply chains make part-level substance control hard. Exemption changes, including lead-related rows, continue to move through 2026. REACH SVHC candidate lists also keep growing. Above 0.1% weight SVHC content, information duties to customers kick in. You need supplier data you can actually verify.
CBAM — the definitive regime has started
On 1 January 2026, CBAM left the transitional reporting-only phase and entered the definitive regime4.
In short, when covered goods are imported into the EU, authorised CBAM declarants must handle certificates linked to embedded emissions, priced with reference to the EU ETS. Current categories include steel, aluminium, cement, fertilisers, hydrogen, and electricity.
| Item | Content |
|---|---|
| Definitive regime start | 1 January 2026 |
| Main goods | Steel, aluminium, cement, fertilisers, hydrogen, electricity, and related covered codes |
| Obligation holder | EU authorised CBAM declarant (importer or indirect customs representative) |
| Japanese exporter role | Provide embedded-emissions data and supplier information |
| De minimis | Small annual volumes (for example under 50 tonnes) may be exempt |
| Scope expansion | Downstream product expansion remains under discussion |
Even if you do not import into the EU yourself, your goods may sit inside a CBAM product as material or parts. Confirm coverage early.
Timeline anchors for 2026–2027
| When | Rule | What changes |
|---|---|---|
| 2025 | Dual-use control list | Quantum, semiconductors, and related updates in force |
| 1 January 2026 | CBAM | Definitive regime |
| January 2026 | GDPR procedure regulation | Entry into force; broader cross-border application later |
| 11 June 2026 | CRA | Notifying authority / conformity assessment body framework |
| Mid-2026 | RoHS and related | Recheck exemptions and technical files |
| 11 September 2026 | CRA | Vulnerability and incident reporting |
| 20 January 2027 | Machinery Regulation | Mandatory application |
| 11 December 2027 | CRA | Main product obligations |
These rules interconnect. CRA security requirements overlap CE conditions under the new Machinery Regulation. CBAM emissions data links into sustainability reporting. Bundling requirements by SKU is cheaper than treating each statute as a separate project.
Five actions Japanese companies can take now
- Sort the portfolio — map each SKU to dual-use, CRA, chemicals, CBAM, and data.
- Stand up CRA reporting roles — detection, internal escalation, and external reporting with clear SLAs before 11 September.
- Document Japan and EU classifications separately — use the 2026 classification template pack for Japan-side records.
- Refresh supplier declarations — RoHS, REACH, emissions factors. Do not ship on stale SDS files.
- Prepare answers for EU customer security questionnaires — sales and engineering need a shared playbook under NIS2 and CRA pressure.
How TRAFEED reduces export-control load
Even for EU shipments, end-user screening and classification records break when they stay fully manual. TIMEWELL’s AI export-control agent TRAFEED (formerly ZEROCK ExCHECK) matches counterparties and items against sanctions lists, export-control lists, and risk information, and returns reasoned determinations. Multi-LLM cross-checks have shown classification accuracy of 95% or higher (joint validation with Okayama University and internal testing).
See the TRAFEED service catalogue (PDF) or contact us.
Key takeaways
- For 2026 EU market access, CRA reporting on 11 September and the CBAM definitive regime are the hard operational anchors
- Export control rests on Regulation (EU) 2021/821 Annex I plus Articles 4 and 5
- CE tightens again on 20 January 2027 under the new Machinery Regulation
- RoHS and REACH fail most often at part-level substance control
- Rules interconnect — build one SKU requirements map and design compliance in early
Always verify against Commission pages and the Official Journal. This article is a snapshot as of 21 July 2026.
Related articles
- Foundations of EU Dual-Use Regulation 2021/821
- List Controls vs. Catch-All Controls in Japan
- METI Classification Guidance, Explained
- Sanctions and Restricted-Party Lists
- Global Export Regulation Overview 2026
References
- European Commission, Cyber Resilience Act (accessed 21 July 2026) https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
- European Commission, CRA Reporting obligations https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- ENISA, Single Reporting Platform (SRP) https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
- EUR-Lex, Regulation (EU) 2021/821 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0821
- European Commission, Carbon Border Adjustment Mechanism https://taxation-customs.ec.europa.eu/carbon-border-adjustment-mechanism_en
- European Commission, CBAM successfully entered into force on 1 January 2026 (14 January 2026) https://taxation-customs.ec.europa.eu/news/cbam-successfully-entered-force-1-january-2026-2026-01-14_en
- METI, Security Trade Control https://www.meti.go.jp/policy/anpo/
Footnotes
-
European Commission, "Cyber Resilience Act" (accessed 21 July 2026). Main obligations apply from 11 December 2027; reporting obligations from 11 September 2026. https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act ↩ ↩2
-
EUR-Lex, Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0821 ↩
-
European Commission, "Cyber Resilience Act - Reporting obligations". Early warning within 24 hours and notification within 72 hours for actively exploited vulnerabilities and severe incidents. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting ↩
-
European Commission, Taxation and Customs Union, "Carbon Border Adjustment Mechanism". Definitive period from 1 January 2026. https://taxation-customs.ec.europa.eu/carbon-border-adjustment-mechanism_en ↩






