Cybersecurity
CRA reporting obligations now apply: what manufacturers must report
CRA reporting obligations have applied since September 11, 2026. Under Article 14 of the Cyber Resilience Act, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to a national CSIRT (computer security incident response team) and to ENISA, the EU Agency for Cybersecurity, in three steps: 24 hours, 72 hours and a final report. The duty covers products already on the EU market and manufacturers based outside the EU.
By the KDS security engineering teamPublished 7 min read
Key takeaways
- Article 14 of the Cyber Resilience Act has applied since September 11, 2026, including to products placed on the market earlier.
- Manufacturers must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
- Mandatory notifications go through ENISA's single reporting platform to the CSIRT designated as coordinator.
- Most other CRA obligations, including the essential cybersecurity requirements, apply from December 11, 2027.
- Breaches of Article 14 can bring fines of up to EUR 15 million or 2.5% of worldwide annual turnover.
On this page
Who counts as a manufacturer under the CRA
The Cyber Resilience Act (opens in a new tab), Regulation (EU) 2024/2847, covers products with digital elements: software or hardware products and their remote data processing solutions, including components placed on the market separately. It applies when the product's intended or reasonably foreseeable use includes a data connection to a device or network.
A manufacturer is anyone who develops or manufactures such products, or has them designed, developed or manufactured, and markets them under its own name or trademark. This applies whether the product is sold, monetized in another way or offered free of charge. A company selling desktop software, a firmware vendor and a maker of connected devices can all be manufacturers.
Some products fall outside the CRA because other EU laws cover them, such as medical devices, in vitro diagnostic devices and vehicles under EU type-approval rules. Websites that do not support a product's function, and cloud services developed outside a manufacturer's responsibility, are also outside the CRA. Many of those services fall under the NIS2 Directive instead, which our NIS2 guide for suppliers explains.
What CRA reporting obligations cover
Article 14 sets two separate reporting duties:
- Actively exploited vulnerabilities. A vulnerability in your product for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. A flaw found in your own testing does not trigger the duty on its own. Evidence of real exploitation does.
- Severe incidents that affect the security of your product. An incident is severe if it harms, or could harm, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. It is also severe if it has led, or could lead, to malicious code running in the product or in a user's systems.
Both go to the CSIRT designated as coordinator and to ENISA at the same time, in one submission. Under Article 15 you can also report other vulnerabilities, cyber threats and near misses voluntarily.
The 24-hour, 72-hour and final report timeline
Deadlines count from the moment the manufacturer becomes aware of the vulnerability or incident. Each step is due without undue delay and at the latest by the deadline in the table, as the Commission's CRA reporting page (opens in a new tab) also summarizes.
| Step | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 hours of becoming aware. Where applicable, name the EU countries where the product is available. | Within 24 hours, with the same country details. Also say whether you suspect unlawful or malicious acts. |
| Notification | Within 72 hours: the product, the general nature of the exploit and vulnerability, measures taken, measures users can take and how sensitive the information is. | Within 72 hours: the nature of the incident, an initial assessment, measures taken, measures users can take and how sensitive the information is. |
| Intermediate report | Only if the CSIRT asks for a status update. | Only if the CSIRT asks for a status update. |
| Final report | No later than 14 days after a corrective or mitigating measure is available: the vulnerability, its severity and impact, information on the attacker where available and details of the fix. | Within one month after the 72-hour notification: a detailed description, severity and impact, the likely threat type or root cause and the mitigation applied and ongoing. |
Information you already gave in an earlier step does not have to be repeated. Note that the final report for a vulnerability runs from the date a fix or mitigation is available, not from the date you became aware.
Where to report: ENISA's single reporting platform
All mandatory notifications go through the single reporting platform (opens in a new tab) that ENISA runs. It became operational on September 11, 2026. You submit through the endpoint of the CSIRT designated as coordinator in the EU country of your main establishment. That is the country where decisions on your products' cybersecurity are mainly taken or, if that is unclear, where your EU establishment with the most employees is. The CSIRT then shares the notification with the CSIRTs of the other countries where your product is available.
A manufacturer with no main establishment in the EU uses the first option that fits, based on the information it has:
- The country where your authorized representative for the highest number of your products is established.
- The country where the importer placing the highest number of your products on the market is established.
- The country where the distributor making the highest number of your products available is established.
- The country with the highest number of users of your products.
ENISA's platform FAQ (opens in a new tab) repeats this order, and the platform page links to the list of CSIRTs designated as coordinators.
Informing your users
After you become aware of an actively exploited vulnerability or a severe incident, you must inform the affected users, and all users where appropriate. Tell them about the issue and, where necessary, the measures they can take to reduce the impact. Where appropriate, use a structured, machine-readable format. If you do not inform users in time, the CSIRT may do it for you.
Key CRA dates for manufacturers
- December 10, 2024: the CRA entered into force.
- June 11, 2026: the rules on conformity assessment bodies (Chapter IV) apply.
- September 11, 2026: reporting under Article 14 applies to all products in scope, including those placed on the market before December 11, 2027.
- December 11, 2027: the rest of the CRA applies, including the essential cybersecurity requirements for product design and vulnerability handling.
Products placed on the market before December 11, 2027 only need to meet the other requirements if they are substantially modified after that date. The reporting duty has no such exception, as the Commission's CRA summary (opens in a new tab) also notes. The EU's Digital Omnibus on AI, adopted in July 2026, amended the AI Act and the EU rules on civil aviation and machinery, not the CRA. Our post on what still applies after the Digital Omnibus covers the AI side.
Penalties for missing CRA reporting deadlines
Breaches of Article 14 can lead to fines of up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 64. Authorities consider the nature, gravity and duration of the breach and the size of the company. Article 64 also exempts microenterprises and small enterprises from fines for missing the 24-hour early warning deadline.
What non-EU manufacturers should do now
Reporting already applies, so the priority is a process that works at 2 a.m. on a Sunday. These steps help:
- Map your products. List every product with digital elements you sell into the EU, the countries where it is available and who places it on the market: you, an importer or a distributor.
- Find your CSIRT. Identify your main establishment or apply the order above. Decide whether to appoint an authorized representative in the EU by written mandate.
- Register early. Set up access to ENISA's single reporting platform before you need it, and name who may submit for your company.
- Define the moment of awareness. Decide who confirms that a vulnerability is actively exploited or an incident is severe, and record that time, because the 24-hour deadline starts there.
- Connect your intake. Route researcher reports, threat intelligence, customer tickets and monitoring alerts to one on-call owner.
- Prepare templates. Draft the three reports and a machine-readable user advisory in advance.
- Rehearse. Run a tabletop exercise with your engineering, legal and support teams. Time each step.
Our cybersecurity consulting team helps manufacturers build this process and run the first exercise. For the full regulation, including the requirements due in December 2027, see our Cyber Resilience Act guide. If your product includes an AI agent that talks to people, the AI Act's transparency rules apply as well, as our Article 50 guide explains.
Sources
- 1.Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 2, 3, 14, 15, 16, 64, 69 and 71, EUR-Lex, Publications Office of the European Union, 2024-11-20 (opens in a new tab)
- 2.Cyber Resilience Act: reporting obligations, European Commission, 2026-09-11 (opens in a new tab)
- 3.The Cyber Resilience Act: summary of the legislative text, European Commission (opens in a new tab)
- 4.Single Reporting Platform (SRP), ENISA, 2026-09-10 (opens in a new tab)
- 5.Single Reporting Platform: frequently asked questions, ENISA (opens in a new tab)
- 6.The CRA Single Reporting Platform is launched, ENISA, 2026-09-11 (opens in a new tab)
- 7.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)