Cyber Resilience Act
From that date, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities on a 24-hour clock — regardless of when the product shipped.
Last updated 14 August 2026
The EU Cyber Resilience Act's incident and vulnerability reporting obligation (Article 14) becomes enforceable. If your product has digital elements and reaches the EU market, and one of its vulnerabilities is being actively exploited, you are required to notify ENISA and your relevant national CSIRT: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available.
Sources: European Commission — CRA reporting obligations, Crowell & Moring — CRA countdown.
11 September 2026 only starts the reporting obligation above (Article 14). The bigger deadline is 11 December 2027 (Article 71): from that date, the CRA's full essential cybersecurity requirements, conformity assessment and CE marking apply to every relevant product placed on the EU market. A product that's already handling incident reporting correctly can still be non-compliant against this larger requirement if the underlying design and documentation work hasn't started.
Source: European Commission — Cyber Resilience Act (Article 71).
Products with digital elements: connected hardware, firmware-driven devices, IoT, embedded systems, and the software that ships with them. It applies to products already on the market, not only new launches — a device that shipped years ago is still in scope for as long as it's out there and you're still the manufacturer of record.
Reporting is triggered by active exploitation in the wild, not by every vulnerability disclosure. That's a narrower bar than "any CVE we find" — but it means the clock can start with no warning, on a vulnerability discovered by someone else, at any hour. The obligation is only meetable if the process to run it already exists before that happens.
The EU Cyber Resilience Act's incident and vulnerability reporting obligations (Article 14) become enforceable. Manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT — an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure becomes available.
If it has digital elements and reaches the EU market — hardware with firmware, connected devices, IoT, embedded systems, software — it's almost certainly in scope, including products that shipped years before this deadline. The trigger is active exploitation in the wild, not every CVE, but you need the process in place before it happens, not after.
A vulnerability-management process you can actually run under a 24-hour clock, a current software bill of materials (SBOM) for what you ship, and a designated route to ENISA and your national CSIRT. If none of that exists yet, the gap is process and documentation, not a lab booking — which is usually the faster part to close.
CE, UKCA and FCC are pre-market approvals — you get them once, before you sell. CRA reporting is an ongoing post-market obligation that runs for as long as the product is out there. A product can be fully CE-marked and still be non-compliant with CRA reporting if nobody owns the process.
No. 11 September 2026 only starts the incident and vulnerability reporting obligation (Article 14). Full CRA compliance — the essential cybersecurity requirements, conformity assessment and CE marking under the CRA itself (Article 71) — applies to every product placed on the EU market from 11 December 2027. A product can be past the reporting deadline and still have the bigger compliance deadline ahead of it.
We're the project-management layer that gets certification and compliance work actually delivered through accredited partners — CE, UKCA, FCC and now the process work CRA reporting requires. If you don't yet have an SBOM, a vulnerability-management process, or a clear route to ENISA and your national CSIRT, that's exactly the kind of gap a scoping call is for.
Book a scoping call