Skip to content

Cybersecurity

CRA reporting obligations now apply: what manufacturers must report

CRA reporting obligations have applied since September 11, 2026. Under Article 14 of the Cyber Resilience Act, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to a national CSIRT (computer security incident response team) and to ENISA, the EU Agency for Cybersecurity, in three steps: 24 hours, 72 hours and a final report. The duty covers products already on the EU market and manufacturers based outside the EU.

By the KDS security engineering teamPublished 7 min read

Key takeaways

  • Article 14 of the Cyber Resilience Act has applied since September 11, 2026, including to products placed on the market earlier.
  • Manufacturers must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
  • Mandatory notifications go through ENISA's single reporting platform to the CSIRT designated as coordinator.
  • Most other CRA obligations, including the essential cybersecurity requirements, apply from December 11, 2027.
  • Breaches of Article 14 can bring fines of up to EUR 15 million or 2.5% of worldwide annual turnover.
On this page

Who counts as a manufacturer under the CRA

The Cyber Resilience Act (opens in a new tab), Regulation (EU) 2024/2847, covers products with digital elements: software or hardware products and their remote data processing solutions, including components placed on the market separately. It applies when the product's intended or reasonably foreseeable use includes a data connection to a device or network.

A manufacturer is anyone who develops or manufactures such products, or has them designed, developed or manufactured, and markets them under its own name or trademark. This applies whether the product is sold, monetized in another way or offered free of charge. A company selling desktop software, a firmware vendor and a maker of connected devices can all be manufacturers.

Some products fall outside the CRA because other EU laws cover them, such as medical devices, in vitro diagnostic devices and vehicles under EU type-approval rules. Websites that do not support a product's function, and cloud services developed outside a manufacturer's responsibility, are also outside the CRA. Many of those services fall under the NIS2 Directive instead, which our NIS2 guide for suppliers explains.

What CRA reporting obligations cover

Article 14 sets two separate reporting duties:

  • Actively exploited vulnerabilities. A vulnerability in your product for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. A flaw found in your own testing does not trigger the duty on its own. Evidence of real exploitation does.
  • Severe incidents that affect the security of your product. An incident is severe if it harms, or could harm, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. It is also severe if it has led, or could lead, to malicious code running in the product or in a user's systems.

Both go to the CSIRT designated as coordinator and to ENISA at the same time, in one submission. Under Article 15 you can also report other vulnerabilities, cyber threats and near misses voluntarily.

The 24-hour, 72-hour and final report timeline

Deadlines count from the moment the manufacturer becomes aware of the vulnerability or incident. Each step is due without undue delay and at the latest by the deadline in the table, as the Commission's CRA reporting page (opens in a new tab) also summarizes.

CRA Article 14 reporting deadlines
StepActively exploited vulnerabilitySevere incident
Early warningWithin 24 hours of becoming aware. Where applicable, name the EU countries where the product is available.Within 24 hours, with the same country details. Also say whether you suspect unlawful or malicious acts.
NotificationWithin 72 hours: the product, the general nature of the exploit and vulnerability, measures taken, measures users can take and how sensitive the information is.Within 72 hours: the nature of the incident, an initial assessment, measures taken, measures users can take and how sensitive the information is.
Intermediate reportOnly if the CSIRT asks for a status update.Only if the CSIRT asks for a status update.
Final reportNo later than 14 days after a corrective or mitigating measure is available: the vulnerability, its severity and impact, information on the attacker where available and details of the fix.Within one month after the 72-hour notification: a detailed description, severity and impact, the likely threat type or root cause and the mitigation applied and ongoing.
CRA Article 14 reporting deadlines

Information you already gave in an earlier step does not have to be repeated. Note that the final report for a vulnerability runs from the date a fix or mitigation is available, not from the date you became aware.

Where to report: ENISA's single reporting platform

All mandatory notifications go through the single reporting platform (opens in a new tab) that ENISA runs. It became operational on September 11, 2026. You submit through the endpoint of the CSIRT designated as coordinator in the EU country of your main establishment. That is the country where decisions on your products' cybersecurity are mainly taken or, if that is unclear, where your EU establishment with the most employees is. The CSIRT then shares the notification with the CSIRTs of the other countries where your product is available.

A manufacturer with no main establishment in the EU uses the first option that fits, based on the information it has:

  1. The country where your authorized representative for the highest number of your products is established.
  2. The country where the importer placing the highest number of your products on the market is established.
  3. The country where the distributor making the highest number of your products available is established.
  4. The country with the highest number of users of your products.

ENISA's platform FAQ (opens in a new tab) repeats this order, and the platform page links to the list of CSIRTs designated as coordinators.

Informing your users

After you become aware of an actively exploited vulnerability or a severe incident, you must inform the affected users, and all users where appropriate. Tell them about the issue and, where necessary, the measures they can take to reduce the impact. Where appropriate, use a structured, machine-readable format. If you do not inform users in time, the CSIRT may do it for you.

Key CRA dates for manufacturers

  • December 10, 2024: the CRA entered into force.
  • June 11, 2026: the rules on conformity assessment bodies (Chapter IV) apply.
  • September 11, 2026: reporting under Article 14 applies to all products in scope, including those placed on the market before December 11, 2027.
  • December 11, 2027: the rest of the CRA applies, including the essential cybersecurity requirements for product design and vulnerability handling.

Products placed on the market before December 11, 2027 only need to meet the other requirements if they are substantially modified after that date. The reporting duty has no such exception, as the Commission's CRA summary (opens in a new tab) also notes. The EU's Digital Omnibus on AI, adopted in July 2026, amended the AI Act and the EU rules on civil aviation and machinery, not the CRA. Our post on what still applies after the Digital Omnibus covers the AI side.

Penalties for missing CRA reporting deadlines

Breaches of Article 14 can lead to fines of up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 64. Authorities consider the nature, gravity and duration of the breach and the size of the company. Article 64 also exempts microenterprises and small enterprises from fines for missing the 24-hour early warning deadline.

What non-EU manufacturers should do now

Reporting already applies, so the priority is a process that works at 2 a.m. on a Sunday. These steps help:

  1. Map your products. List every product with digital elements you sell into the EU, the countries where it is available and who places it on the market: you, an importer or a distributor.
  2. Find your CSIRT. Identify your main establishment or apply the order above. Decide whether to appoint an authorized representative in the EU by written mandate.
  3. Register early. Set up access to ENISA's single reporting platform before you need it, and name who may submit for your company.
  4. Define the moment of awareness. Decide who confirms that a vulnerability is actively exploited or an incident is severe, and record that time, because the 24-hour deadline starts there.
  5. Connect your intake. Route researcher reports, threat intelligence, customer tickets and monitoring alerts to one on-call owner.
  6. Prepare templates. Draft the three reports and a machine-readable user advisory in advance.
  7. Rehearse. Run a tabletop exercise with your engineering, legal and support teams. Time each step.

Our cybersecurity consulting team helps manufacturers build this process and run the first exercise. For the full regulation, including the requirements due in December 2027, see our Cyber Resilience Act guide. If your product includes an AI agent that talks to people, the AI Act's transparency rules apply as well, as our Article 50 guide explains.

Sources

  1. 1.Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 2, 3, 14, 15, 16, 64, 69 and 71, EUR-Lex, Publications Office of the European Union, 2024-11-20 (opens in a new tab)
  2. 2.Cyber Resilience Act: reporting obligations, European Commission, 2026-09-11 (opens in a new tab)
  3. 3.The Cyber Resilience Act: summary of the legislative text, European Commission (opens in a new tab)
  4. 4.Single Reporting Platform (SRP), ENISA, 2026-09-10 (opens in a new tab)
  5. 5.Single Reporting Platform: frequently asked questions, ENISA (opens in a new tab)
  6. 6.The CRA Single Reporting Platform is launched, ENISA, 2026-09-11 (opens in a new tab)
  7. 7.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)

Get a free 30-minute assessment

Tell us what you need to protect and which rules you must meet. We'll outline the first steps and what a full assessment would cover.

Frequently asked questions

When do CRA reporting obligations start?

Reporting under Article 14 of the Cyber Resilience Act has applied since September 11, 2026. It covers all products with digital elements in scope that are on the EU market, including products placed on the market before that date. Most other CRA obligations, including the essential cybersecurity requirements for product design, apply from December 11, 2027.

What is an actively exploited vulnerability under the CRA?

It is a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner. A weakness found in your own testing or reported by a researcher, with no evidence of exploitation, does not trigger the Article 14 duty on that basis alone. You can still report it voluntarily under Article 15.

Where do manufacturers submit CRA notifications?

Through the single reporting platform run by ENISA, the EU Agency for Cybersecurity, which became operational on September 11, 2026. You submit through the endpoint of the CSIRT designated as coordinator in the EU country of your main establishment. ENISA receives access at the same time, and the CSIRT shares the notification with the other countries where your product is available.

Do non-EU manufacturers have to report under the CRA?

Yes, if they make products with digital elements available on the EU market. Without a main establishment in the EU, they report to the CSIRT in the country of their authorized representative, then the importer, then the distributor and finally the country with the most users of their products. Each option applies only when the previous one does not.

What are the fines for breaking CRA reporting obligations?

Breaches of Article 14 can be fined up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Microenterprises and small enterprises are exempt from fines for missing the 24-hour early warning deadline. Each EU country sets the detailed penalty rules, and authorities consider the nature, gravity and duration of the breach and the company's size.

Services and use cases

  • Service

    Cybersecurity consulting

    Cybersecurity consulting for growing companies: security assessments, penetration testing, virtual CISO, incident response planning, NIS2 and CRA readiness.

    Explore cybersecurity consulting

Free 30-minute assessment

Find the one workflow worth automating first.

Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.

  • A senior engineer replies within one business day
  • We can sign an NDA before you share details
  • No fixed packages, every quote tailored to you
What can we help with?
About your company

Company size

When would you like to start?

How can we reach you?

Encrypted in transit · read only by our team · never sold

Free 30-minute AI assessmentGet it →

Before you go

Find out where AI can save your team time

Book a free 30-minute assessment. A senior engineer reviews one workflow with you and sends back the opportunities, the risks and a rough payback estimate.