
The Cyber Resilience Act (CRA) has reached a new stage in its implementation. Since 11 September 2026, manufacturers of products with digital elements have been required to report actively exploited vulnerabilities and severe incidents affecting the security of their products.
In short, for those looking for the key information first: an initial early warning must be submitted within 24 hours of the manufacturer becoming aware of the issue, followed by a more detailed notification within 72 hours and, subsequently, a final report. The entire process is handled through the single reporting platform managed by ENISA, and failure to comply may result in fines of up to €15 million or 2.5% of worldwide annual turnover.
Most of the obligations under Regulation (EU) 2024/2847 of 23 October 2024 will not apply until 11 December 2027. Article 14, which governs these reporting obligations, has already applied since September 2026.
This means that many businesses cannot wait until 2027 to start preparing. If they develop or market under their own brand software, connected devices or other products with digital elements in the European market, they must already have procedures in place to identify certain cybersecurity issues, assess them and report them within very short timeframes.
What is the Cyber Resilience Act?
The Cyber Resilience Act is the EU Regulation that establishes horizontal cybersecurity requirements for products with digital elements placed on the European Union market. It entered into force on 10 December 2024 and is being phased in through to December 2027.
Its purpose is to strengthen the security of hardware and software throughout their entire lifecycle. To achieve this, it introduces obligations relating to secure product design and development, vulnerability management, security updates, technical documentation, conformity assessment and the information that must be provided to users.
The concept of a product with digital elements is broad. It includes software and hardware products, their remote data processing solutions and components placed on the market separately. This can range from applications and software to IoT devices, connected equipment, operating systems and certain digital components.
The CRA is therefore not legislation aimed only at major technology manufacturers.
Who is affected by the new obligations from September 2026?
The obligations under Article 14 apply to manufacturers of products with digital elements falling within the scope of the Regulation.
For CRA purposes, a manufacturer is not only the party that physically produces a device. It also includes a natural or legal person for whom products with digital elements are designed, developed or manufactured and who markets them under its own name or trade mark, whether for payment, monetised in another way or provided free of charge.
This means that each business model needs to be analysed individually. A common example would be a company selling a connected device under its own brand that was manufactured by an Asian supplier, together with an application developed by an external consultancy. For the purposes of the Regulation, that company is the manufacturer of both products. The same may apply to software or IoT start-ups launching a product on the European market that has largely been built by third parties.
The Regulation also covers manufacturers established outside the European Union where they place products on the EU market. In these cases, Article 14 establishes an order of priority for determining the Member State to which the notification must be submitted, starting with the Member State in which the authorised representative is established.
Another particularly relevant point is that the reporting obligations apply to all products with digital elements within the scope of the CRA, including products placed on the market before 11 December 2027 (Article 69(3)). Businesses therefore cannot limit their review to products they intend to launch from 2027 onwards.
The Regulation also includes specific obligations for open-source software stewards. In their case, the reporting obligations will apply from 11 December 2027.
What must be reported under the Cyber Resilience Act?
The CRA does not require every software fault or vulnerability identified to be reported. Since September 2026, manufacturers have been required to report two types of events.
Actively exploited vulnerabilities
The Regulation defines an actively exploited vulnerability as one for which there is reliable evidence that a malicious actor has exploited it in a system without the system owner’s permission.
The distinction is important. The mere existence of a vulnerability does not trigger the Article 14 reporting obligation. There must be reliable evidence that the vulnerability is being or has actually been exploited.
Severe incidents affecting product security
Manufacturers must also report severe incidents affecting the security of a product with digital elements.
The Regulation considers an incident severe in two circumstances:
- Where it adversely affects, or is capable of adversely affecting, the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions.
- Where it has led, or is capable of leading, to the introduction or execution of malicious code in the product or in a user’s network and information systems.
One of the first challenges for businesses will therefore be to establish internally which events meet these criteria and who is responsible for making that assessment.
24- and 72-hour deadlines: how does the reporting process work?
One of the most important aspects of the new regime is the speed required.
The clock starts when the manufacturer becomes aware of the actively exploited vulnerability or severe incident. From that point onwards, a three-stage reporting process applies.
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Without undue delay and, in any event, within 24 hours | Without undue delay and, in any event, within 24 hours |
| Notification | Within 72 hours, including general product information, the nature of the vulnerability and corrective or mitigating measures | Within 72 hours, including the nature of the incident, an initial assessment and corrective or mitigating measures |
| Final report | No later than 14 days after a corrective or mitigating measure becomes available | Within one month of the 72-hour notification |
Where relevant, the early warning must indicate the Member States in which the product has been made available on the market. In the case of incidents, it must also indicate whether unlawful or malicious acts are suspected.
The operational logic behind this system is important. A company does not need to have all the information available before submitting the first notification, which is precisely why the process is divided into different stages. Waiting until a full technical investigation has been completed before activating the reporting procedure may make it impossible to meet the initial 24-hour deadline.
Who must be notified, and how? ENISA’s Single Reporting Platform
The manufacturer reports simultaneously to the CSIRT designated as coordinator in the Member State where its main establishment is located and to ENISA, the European Union Agency for Cybersecurity.
The main establishment is the place where decisions relating to the cybersecurity of the products are predominantly taken.
Both communications are completed through a single procedure. On 11 September 2026, when these obligations became applicable, ENISA launched its Single Reporting Platform (SRP).
The CSIRT receiving the notification shares it with the CSIRTs of the other Member States in which the product has been made available on the market, meaning that the manufacturer does not need to contact each national authority separately.
ENISA is responsible for developing, operating and maintaining the platform, which includes measures to protect the confidentiality of the information reported. The European Commission also summarises the procedure on its page covering CRA reporting obligations.
For affected businesses, this means that internal incident response procedures must address not only the technical investigation, but also who is authorised to submit the notification, what information needs to be collected and how technical, legal and management teams will coordinate.
This forms part of effective cybersecurity crisis management, which should ideally be defined before an incident occurs.
Do users also need to be informed?
Yes. Reporting to the authorities is not the only obligation businesses need to consider.
When a manufacturer becomes aware of an actively exploited vulnerability or severe incident, it must inform affected users and, where appropriate, all users of the product. Where necessary, it must also communicate the corrective or risk mitigation measures that users can take to reduce the impact.
An appropriate response to one of these events may therefore require action on several fronts at the same time: technically investigating the problem, meeting the CRA reporting deadlines and preparing appropriate communications for customers or users.
Does the CRA replace NIS2 or GDPR reporting obligations?
No. These are separate regimes and may apply simultaneously.
The CRA focuses on the product, while the NIS2 Directive focuses on the entity providing essential or important services, and the GDPR focuses on personal data.
A single incident may therefore trigger several reporting obligations at once. If an exploited vulnerability in a product also results in a personal data breach, the controller may need to notify the relevant data protection authority within 72 hours under the GDPR.
If the manufacturer is also an entity subject to NIS2 or the DORA Regulation, it will also have to comply with the relevant deadlines and reporting channels under those regimes.
For this reason, it is advisable to have a single internal incident response procedure capable of identifying from the outset which notifications are required in each case, rather than maintaining completely separate protocols for each piece of legislation.
What penalties does the Cyber Resilience Act provide for failure to report?
Failure to comply with the obligations under Articles 13 and 14 of the Regulation may result in administrative fines of up to €15 million or, where the offender is a company, up to 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher (Article 64(2)).
There is an important exception for smaller businesses.
Manufacturers that are microenterprises or small enterprises cannot be fined for failing to meet the 24-hour early-warning deadline.
This exception applies only to that deadline. All other reporting obligations, including the 72-hour notification and the final report, remain fully applicable.
What should businesses review now?
Now that Article 14 applies, businesses should review their internal procedures before an incident occurs.
In particular, companies that develop or market digital products should:
- Identify which products may fall within the scope of the CRA, including those already on the market.
- Assess whether the company qualifies as the manufacturer for each product, especially where development has been outsourced or products are sold under its own brand.
- Determine its main establishment in the European Union and, therefore, which coordinating CSIRT it will need to notify.
- Define how potential actively exploited vulnerabilities and severe incidents will be detected and escalated internally.
- Appoint primary and backup responsible persons, so that an alert does not depend on a single individual.
- Adapt incident response procedures to meet the initial 24-hour deadline, including at weekends and during holiday periods.
- Prepare the necessary access rights and roles to use ENISA’s Single Reporting Platform.
- Determine what technical, legal and commercial information needs to be collected for each stage of the notification process.
- Establish a procedure for informing affected users where necessary.
- Review contracts with developers, component suppliers and distributors to ensure they report vulnerabilities and incidents promptly.
- Coordinate cybersecurity, IT, product, management and legal teams so that a technical issue is not handled in isolation.
The 24-hour deadline makes preparation particularly important. Once a vulnerability or incident occurs, there is unlikely to be time to decide from scratch who should assess the case, who is authorised to report it and which procedure should be followed.
At Certus, we address these procedures as part of our cybersecurity and digital consultancy services.
11 December 2027 remains a key date
The fact that these reporting obligations now apply does not mean that the Cyber Resilience Act is already fully enforceable.
The Regulation will apply generally from 11 December 2027. From that date, other requirements will become applicable, including those relating to cybersecurity risk assessment, essential product security requirements, vulnerability management throughout the support period, technical documentation and conformity assessment procedures.
The obligations that began to apply in September 2026 can therefore serve as an initial test of how prepared businesses are.
A similar situation exists under the AI Act, where 2026 is also the year in which businesses need to catch up rather than waiting for the framework to become fully applicable.
Having a clear product inventory, well-defined responsibilities and effective vulnerability management and reporting procedures in place now will make the transition towards full CRA compliance in 2027 considerably easier.
Frequently asked questions about Cyber Resilience Act reporting obligations
When does the Cyber Resilience Act apply?
The Regulation entered into force on 10 December 2024, but it establishes different application dates.
The Article 14 reporting obligations have applied since 11 September 2026, while the CRA will apply generally from 11 December 2027.
What must manufacturers report from September 2026?
They must report actively exploited vulnerabilities of which they become aware and severe incidents affecting the security of their products with digital elements.
Not every vulnerability or incident triggers this obligation.
What is the deadline for reporting an incident under the CRA?
The early warning must be submitted without undue delay and, in any event, within 24 hours of the manufacturer becoming aware of the event.
A more complete notification must then be submitted within 72 hours, followed by a final report.
For vulnerabilities, the final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, it must be submitted within one month of the 72-hour notification.
Who must be notified of a vulnerability or severe incident?
The notification is made to the CSIRT designated as coordinator in the Member State of the manufacturer’s main establishment and, simultaneously, to ENISA.
Both communications are completed through a single procedure using the Single Reporting Platform, which has been operational since 11 September 2026.
Do these obligations apply to products sold before December 2027?
Yes.
The reporting obligations under Article 14 apply to all products with digital elements within the scope of the CRA, even if they were placed on the market before 11 December 2027.
Does the Cyber Resilience Act apply to Software as a Service (SaaS)?
As a general rule, the CRA regulates products rather than services, so pure SaaS falls outside its scope, without prejudice to other legislation such as NIS2.
However, remote data processing designed or developed by the manufacturer for its product, and without which the product could not perform one of its functions, is covered. This may include, for example, the cloud service on which an application or connected device depends.
Each case requires individual analysis.
What fines can apply for late reporting under the CRA?
Up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher.
Microenterprises and small enterprises cannot be fined for failing to meet the 24-hour early-warning deadline, but they may still face penalties for breaches of the remaining reporting obligations.
Preparing for the Cyber Resilience Act
The Cyber Resilience Act introduces an important change in the way businesses need to approach the security of digital products.
Cybersecurity is no longer solely a technical matter. It is also becoming a regulatory obligation embedded throughout the product lifecycle.
Since 11 September 2026, that change already has practical consequences. When certain vulnerabilities and incidents arise, manufacturers have very short deadlines in which to respond, report the issue and coordinate the necessary measures.
At Certus, we help businesses assess how the Cyber Resilience Act affects them, identify their obligations and adapt their internal procedures and contracts to the new European cybersecurity framework.
Find out more about our digital consultancy services or contact us through our contact page.
This article is for general information purposes only and does not constitute legal advice. Reference legislation: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), in particular Articles 3, 14, 16, 64, 69 and 71.
