Cyber Resilience Act reporting obligations: what applies now
9 min readRepresenta GmbH
Cyber Resilience Act reporting obligations started on 11 September 2026: early warning within 24 hours via ENISA's platform, also for older products.

The Cyber Resilience Act reporting obligations have applied since 11 September 2026 (Article 14 of Regulation (EU) 2024/2847). Manufacturers of connected products must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, starting with an early warning within 24 hours, also for products sold years ago. Here is what manufacturers outside the EU should do now.
What the Cyber Resilience Act reporting obligations require
The Cyber Resilience Act (CRA) is a regulation that applies directly in every member state, mostly from 11 December 2027. Article 71(2) (opens in a new tab) brings two parts forward: the rules on notified bodies from 11 June 2026 and the reporting obligations of Article 14 from 11 September 2026.
Two events must be reported: an actively exploited vulnerability in the product, and a severe incident affecting its security. An incident is severe if it can compromise the protection of sensitive or important data or functions, or lead to malicious code being introduced or executed (Article 14(5)).
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 hours of becoming aware, naming the member states where the product is available (Art. 14(2)(a)) | Within 24 hours, stating whether malicious or unlawful acts are suspected (Art. 14(4)(a)) |
| Notification | Within 72 hours, with general information and mitigation measures (Art. 14(2)(b)) | Within 72 hours, with an initial assessment (Art. 14(4)(b)) |
| Final report | No later than 14 days after a corrective or mitigating measure is available (Art. 14(2)(c)) | Within one month after the 72-hour notification (Art. 14(4)(c)) |
The clock starts when the manufacturer becomes aware: according to the Commission's guidance C(2026) 5252 of 27 July 2026, once a prompt initial assessment gives a reasonable degree of certainty. Impacted users must also be informed about the event and the measures they can take (Article 14(8)).
Which products are covered, including those already sold
The CRA covers hardware and software with a data connection to a device or network (Article 2(1)), including remote data processing such as the manufacturer's own cloud service without which the device cannot perform a function (Article 3(1) and (2)).
The duty reaches back to products already on the market. Article 69(3) applies Article 14 to all products in scope placed on the market before 11 December 2027. According to the Commission's guidance, reporting also continues after the support period has ended, but it is not retroactive: an exploitation known before 11 September 2026 need not be notified. A vulnerability in a third-party component counts once it is exploited in your product (paragraph 218).
Excluded are, among others, medical devices, type-approved motor vehicles, certified aviation products and marine equipment (Article 2(2) to (4)).
Where manufacturers outside the EU report
Notifications go through ENISA's Single Reporting Platform (SRP) to the CSIRT designated as coordinator in one member state. ENISA receives them simultaneously; the CSIRT forwards them to other member states where the product is available (Articles 14(7), 16(2)).
Decisive is the main establishment in the EU, where cybersecurity decisions are predominantly taken. Without one, Article 14(7) sets this order:
- the member state of the Authorized Representative acting for most of the manufacturer's products;
- otherwise, that of the importer placing most of its products on the market;
- otherwise, that of the distributor making most of its products available;
- otherwise, the member state with the most users.
According to ENISA, a notification sent to the wrong CSIRT may be invalidated. One point is open: Article 18 on Authorized Representatives applies only from 11 December 2027, and neither the Commission's guidance nor ENISA's FAQ explains how the first step works until then. Document which step you applied and why.
What to do now: a reporting checklist
- List the products in scope, including older models, apps and cloud services, and where each is available.
- Determine your CSIRT under Article 14(7) and document the reasoning; ENISA publishes the list of CSIRTs designated as coordinators.
- Prepare access. Reporters need personal EU Login accounts with multi-factor authentication; ENISA advises registering on the SRP only when a notification is due.
- Define when you become aware: who assesses customer reports, researcher e-mails and threat intelligence, and who starts the clock.
- Prepare content. Keep product data, affected versions, advice for users and channels to reach them ready. The platform is in English only at launch.
- Brief importers and distributors to forward security reports to you; from 11 December 2027 they must inform you of vulnerabilities (Articles 19(5) and 20(4)).
Practical example: a U.S. smart home camera brand
A U.S. brand sells Wi-Fi security cameras with app and cloud service in the EU, without an EU establishment or an Authorized Representative under the CRA. An importer in the Netherlands places most units on the market, so the brand reports to the Dutch CSIRT designated as coordinator (Article 14(7)(b)).
On Monday, a customer reports cameras streaming to an unknown server. On Tuesday at 10:00, the security team confirms that attackers exploit a flaw in the login function: the brand is now aware.
| Step | Due | Content |
|---|---|---|
| Early warning | Wednesday 10:00 | Exploited firmware vulnerability; sold in the Netherlands, Germany and France |
| Notification | Friday 10:00 | Affected models and versions, interim advice to users: disable remote access |
| Final report | 14 days after the update | Description, severity, attacker information if known, update details |
Had the attackers taken over the update server to push manipulated firmware instead, it would be a severe incident (Article 14(5)(b)), with the final report due one month after the 72-hour notification.
What follows on 11 December 2027, and how the RED fits in
From 11 December 2027, products placed on the market must meet the essential cybersecurity requirements of Annex I, and manufacturers have to:
- handle vulnerabilities during a support period of, as a rule, at least five years (Article 13(8));
- complete a conformity assessment, issue the EU Declaration of Conformity and affix the CE marking (Articles 28, 30 and 32);
- keep the technical documentation and Declaration of Conformity for at least 10 years or the support period, whichever is longer (Article 13(13)).
Routers and smart home security cameras are important products of class I (Annex III). Unless harmonized standards, common specifications or an EU certification scheme are applied in full, a notified body must be involved (Article 32(2)).
A manufacturer may appoint an Authorized Representative by written mandate covering at least document retention, information on request and cooperation with authorities. Design, risk assessment, vulnerability handling and drawing up the technical documentation cannot be delegated (Article 18).
Radio equipment already has cybersecurity duties: since 1 August 2025, Delegated Regulation (EU) 2022/30 applies Article 3(3)(d), (e) and (f) of the Radio Equipment Directive 2014/53/EU to internet-connected and certain other radio equipment. The EN 18031 standards give no presumption of conformity if users may skip setting a password (Implementing Decision (EU) 2025/138).
Delegated Regulation (EU) 2026/339 (opens in a new tab) repeals that act with effect from 11 December 2027 to avoid double rules. Equipment placed on the market between 1 August 2025 and 10 December 2027 remains subject to market surveillance under the RED.
Common mistakes with CRA reporting
- Checking only new products. Article 69(3) covers everything in scope already on the EU market.
- Reporting every bug. Only actively exploited vulnerabilities and severe incidents are mandatory; other findings can be reported voluntarily (Article 15).
- Mixing up channels. GPSR accidents go through the Safety Business Gateway (Article 20 of Regulation (EU) 2023/988), CRA notifications through the SRP.
- Waiting for the final report to inform users. Article 14(8) ties user information to becoming aware.
Conclusion: report now, prepare for CE marking
For manufacturers outside the EU, reporting is the first CRA duty that applies in practice. The work is mainly organizational: products in scope, the right CSIRT, EU Login accounts and a clear start for the 24-hour clock. The notifications remain the manufacturer's duty (Article 14).
The bigger step follows on 11 December 2027. Representa supports you with CE marking, from identifying the applicable directives and harmonized standards such as EN 18031 to reviewing the technical documentation, and with compliance consulting for a roadmap and team training.
Frequently asked questions
When do the Cyber Resilience Act reporting obligations apply?
Since 11 September 2026 (Article 71(2) CRA). They cover actively exploited vulnerabilities and severe incidents in products with digital elements, including products placed on the EU market before 11 December 2027 (Article 69(3)).
What are the CRA reporting deadlines?
An early warning within 24 hours of becoming aware and a notification within 72 hours. The final report is due 14 days after a fix is available for an exploited vulnerability, or one month after the 72-hour notification for a severe incident (Article 14(2) and (4)).
Where does a manufacturer outside the EU report?
Through ENISA's Single Reporting Platform, to the CSIRT of the member state determined by Article 14(7): where the Authorized Representative is established, otherwise the importer, then the distributor, finally where most users are. Each step looks at the highest number of products or users.
Do products sold before 11 December 2027 have to meet the CRA?
Only the reporting obligations apply to them (Article 69(3)); the other requirements apply only after a substantial modification (Article 69(2)). Compliance is assessed per unit: according to the Commission's FAQ, further units of an older, non-compliant type placed on the market from 11 December 2027 must comply.
What happens if I miss a CRA reporting deadline?
Article 64(2) CRA provides for fines of up to 15 million euros or 2.5% of worldwide annual turnover for breaches of Article 14; the member states lay down the rules. Like the other enforcement provisions, Article 64 applies from 11 December 2027. Micro and small enterprises are not fined for missing the 24-hour early warning (Article 64(10)(a)).
