On 11 September, a European regulation starts applying to products with digital elements. Sim racing hardware appears to qualify. The date itself is minor. What it points to, fifteen months later, is not.
On 11 September 2026, the reporting obligations of the European Union’s Cyber Resilience Act begin to apply. From that day, manufacturers of products with digital elements sold on the EU market must notify their national CSIRT and the European Union Agency for Cybersecurity of any actively exploited vulnerability within 24 hours, with a full notification within 72 hours and a final report within 14 days.
Regulation (EU) 2024/2847 entered into force on 11 December 2024. Its full compliance regime, covering secure design, conformity assessment, CE marking and technical documentation, applies from 11 December 2027. The reporting duty comes first, deliberately, because regulators want earlier visibility of exploited weaknesses.
Two aspects make this relevant now rather than in 2027. It applies to products already on the market, not only to new releases. And it applies to any manufacturer placing products on the EU market, regardless of where that manufacturer is based.
Why we think sim racing hardware is in scope
We are not lawyers, and the definitive answer for any specific product has to come from its manufacturer. But the reasoning is not difficult to follow.
The regulation covers products with digital elements, meaning hardware and software products, including components placed separately on the market, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or a network.
A wheel base connected to a PC by USB meets that description on its face.
Germany’s Federal Office for Information Security, the supervisory authority in the largest sim racing market in Europe, illustrates the scope with the example of a Japanese manufacturer selling games consoles into the EU. Legal analysis of the video games sector has separately flagged that the regulation is relevant to companies offering physical products with digital elements, including accessories with connectivity.
Now consider what sits in a modern sim racing rig:
- Firmware on every direct drive wheel base, pedal set, handbrake and shifter, updated over the product’s life.
- Companion PC software from every major brand, handling configuration, force feedback profiles and firmware delivery.
- Wireless steering wheels communicating over 2.4 GHz or Bluetooth.
- Telemetry integrations reading live data from simulators and, in some cases, connecting to online services.
If that does not describe a product with digital elements, it is not obvious what would.
What would a vulnerability in a wheel base even look like?

Not the wheel. The software.
Every major brand ships a Windows companion application that installs drivers or services with elevated privileges, updates itself over the network, and downloads firmware to push to the device. That combination is where the risk lives, and the gaming peripheral category has a documented history with it.
In 2021, researchers showed that simply plugging in a Razer mouse caused Windows to fetch and run the installer with SYSTEM privileges, and that the installation process could be used to obtain a command prompt at that same privilege level. A comparable weakness was reported in another major peripheral maker’s software around the same time. Physical access plus a cheap mouse was enough for full control of the machine.
The wireless side has precedent too. Research published in 2016 demonstrated that proprietary 2.4 GHz receivers from several large manufacturers accepted unencrypted, unauthenticated packets, allowing keystroke injection from a considerable distance. Wireless sim racing wheels use the same class of link, and we are not aware of any published security audit of one.
There are two further surfaces worth naming. Firmware that is not cryptographically signed can be replaced, and because a wheel base enumerates over USB as a human interface device, compromised firmware can behave like a keyboard. And motion platforms move a person, which shifts the conversation from data security to physical safety.
None of this means any current sim racing product is vulnerable. We have no evidence that any is. It means the attack surface is real, and that nobody has looked.
Why 11 September probably will not bite

Here is the objection, and it is a fair one. The September obligation only triggers on an actively exploited vulnerability or a severe security incident. Nobody is exploiting the firmware in a load cell pedal set. Realistically, most sim racing manufacturers will reach 11 September, and the months after it, without ever filing a report.
That is true, and it is the point.
The September date is not the problem. It is the first visible edge of a regime whose substance lands on 11 December 2027, when the full requirements apply to every new product placed on the EU market: cybersecurity built in from the design stage, a documented risk assessment, a technical file, a software bill of materials, conformity assessment and CE marking on that basis.
That is not a reporting inbox. That is engineering work, documentation work and certification cost, applied to a category that has never had to do any of it. And unlike the September obligation, it is not conditional on anything going wrong. It is a condition of selling.
Penalties across the regulation reach up to 15 million euros or 2.5 percent of global annual turnover.
So the useful question is not whether anyone files a report next month. It is whether an industry that has fifteen months to prepare has started.
The five-year problem

Here is where it stops being a paperwork question and becomes a business model question.
Under the regulation, manufacturers carry responsibility for the cybersecurity of their products across a defined support period, providing security updates free of charge. That period should reflect the product’s expected lifetime and, in most cases, is not less than five years.
Now look at the pace of this industry. In roughly eighteen months, MOZA moved from the R16 to the R16 Ultra. Simucube moved from the 2 series to the 3 series. Fanatec replaced the DD1 and DD2 with the Podium DD. Sim-Lab has just opened pre-orders for its first wheel bases. We covered the broader acceleration in our look at how direct drive became the standard.
A company launching a new flagship every eighteen months and carrying a five-year support obligation on every predecessor is maintaining three or four generations simultaneously. Some already do this well. Others have visibly struggled with firmware even on current products, as Fanatec’s own community discovered earlier this summer when an update caused problems for wheel base owners.
The question is not whether the big brands can absorb this. It is what it does to product roadmaps, to how long ranges stay on sale, and to the smallest manufacturers.
The importer question
The regulation does not stop at manufacturers. It applies to importers and distributors, who may only place products with digital elements on the market where those products and the manufacturer’s procedures comply. Importers are described as gatekeepers to the EU market, expected to verify conformity assessment, CE marking and documentation before products enter circulation.
A large share of sim racing hardware sold in Europe is manufactured in China by companies with no EU establishment. The European retailers who bring that hardware in are not incidental to this regulation. They are named participants in it.
The part nobody has checked

Sim racing has an unusually long tail of boutique manufacturers. Wheel makers, pedal makers, handbrake specialists, many of them run by a handful of engineers. These are microenterprises by any definition.
The European Commission acknowledges the burden and has committed to guidelines, help desks and regulatory sandboxes for smaller companies. Germany’s supervisory authority has published a technical guideline to help manufacturers implement the requirements. Support exists.
Awareness is a separate matter, and it is the one we are least confident about. We are not claiming any specific product is non-compliant. We are not claiming any company is unprepared. We have not seen evidence of either.
What we have established is that a binding EU-wide regime is arriving, that it appears on its face to cover the category, that it reaches manufacturers outside Europe and retailers inside it, and that we have been unable to find any coverage of it in the sim racing press.
Any of those four things could be wrong. We would rather be corrected in public than stay quiet.
What this means if you own the hardware
Practically, nothing changes for you on 11 September. This is an obligation on companies, not on consumers, and no product becomes illegal to own or use.
Over the longer term, if the regulation works as intended, it should mean better-supported firmware, clearer disclosure when something goes wrong, and defined support windows rather than silent abandonment. Those are things sim racers have wanted for years.
The risk runs the other way. Compliance costs fall hardest on the smallest manufacturers, and this is a hobby whose character has been shaped by small independent companies. Combined with the consolidation already under way, including Corsair’s acquisition of Trak Racer and the cost pressures we set out in our look at why 2026 would be a brutal year for hardware, the direction of travel favours scale.
The next visible moment is Gamescom, from 26 to 30 August, two weeks before the first deadline and roughly fifteen months before the one that matters. It would be a reasonable place to ask these questions in person, and we intend to.
See you on the track!
The regulation and the Commission’s implementation guidance, including material for small and medium-sized enterprises, are published on the European Commission’s Cyber Resilience Act page. Germany’s supervisory authority, the Federal Office for Information Security, maintains its own guidance for manufacturers, importers and distributors on its Cyber Resilience Act pages.
This article is journalism, not legal advice. Manufacturers, importers and distributors should take their own qualified advice on their obligations.
This website uses affiliate links which may earn a commission at no additional cost to you.









