Skip to Primary Navigation

EU Cyber Resilience Act: New incident reporting obligations take effect

a hacker with an Anonymous mask on his face and a hood on his head uses a computer
Photo: Chesnot/Getty Images

The Cyber Resilience Act (CRA) brings manufacturers of products with digital elements under strict deadlines and new compliance responsibilities.


Manufacturers of hardware and software products with digital elements (PDE) placed on the EU market face new reporting requirements as of September 11,2026, under the Cyber Resilience Act (CRA).

The CRA, which entered into force in December 2024, is a horizontal framework that aims to strengthen EU’s approach to cybersecurity and safeguard consumers and businesses from buying products without the necessary cybersecurity protections.

As hardware and software products are subjected to cyberattacks, amounting to €5.5 trillion ($6.35 trillion) in global cybercrime cost, the CRA is implementing requirements for devices and software to be planned, designed, developed, maintained, and updated to ensure increased user protection.

Applying to a broad universe of products, ranging from smart watches, door-locking devices, and baby monitors to computer programs and connectable hardware, relevant items will bear the CE marking to signify compliance with the CRA.

While most of the obligations under the CRA start to apply from December 11, 2027, a specific subset of reporting obligations started to apply from September 11, 2026.

Reporting obligations

Under CRA (Art.14), manufacturers are required to report two categories of events:

  • Actively exploited vulnerability – vulnerability for which there is reliable evidence that a malicious actor has exploited it without permission.
  • Severe incidents having an impact on the security of the product – incidents that affect the security of the product itself.

While there may be overlaps, one way to distinguish between the two events is to see them as vulnerabilities of a product (for example, a software error in the product itself) versus an incident that compromises the process through which the product is developed, produced, or maintained (for example, the producer’s software update infrastructure has been compromised).

Upon identifying an actively exploited vulnerability, manufacturers need to:

  • Within 24 hours of becoming aware, submit an early warning;
  • Within 72 hours, submit a vulnerability notification with more detailed information;
  • Submit a final report no later than 14 days since the corrective measure has been implemented, providing further information on the vulnerability and remediation.

A similar procedure applies in the cases of severe incidents that have an impact on the security of the product, with the due date for the final report being one month.

Additionally, the content of the warning and report also differs. The vulnerabilities being reported focus on the flaw, exploitation, and remediation, while incidents center on the event, the flaw, and the root cause.

In either case, to complete the reporting, per CRA (Art.16), manufacturers should use the CRA Single Reporting Platform (SRP), developed by ENISA, the EU Agency for Cybersecurity. The notification is received by the Computer Security Incident Response Team (CSIRT) where the manufacturer has its main establishment, and it is also visible to ENISA.

The notification can be shared with other CSIRTs unless delaying dissemination is justified on cybersecurity-related grounds. The European Commission has further specified the conditions for doing so – for example, when the dissemination may create a cybersecurity risk in itself or when the mitigation measure by the manufacturer is imminent.

Compliance implications

Per CRA (Art 2), the rules apply to all products with digital elements that are placed on the EU market, including those that are already made available, and the use of which “includes a direct or indirect logical or physical data connection to a device or network.”

Exceptions apply to items already subjected to certain sector-specific rules such as medical devices or products related to national security and defense.

Given the rather broad scope, the European Commission has adopted guidance to help manufacturers in their compliance efforts, with the possibility of, under Article 26, issuing further guidance in the future.

For compliance professionals across sectors, the key priority would be to determine if the products offered fall under the scope of the CRA, to implement the necessary requirements relating to the maintenance of existing products and the development of new ones, as well as to ensure preparedness to report under the foreseen deadlines.

In addition to the broad scope of products, CRA is not limited to EU companies but can also affect non-EU manufacturers placing products with digital elements on the EU market. This also brings an added obligation for the compliance teams of entities that use such products, who will need to check if the CRA criteria are fulfilled.

In addition to other penalties, the CRA (Art. 64) foresees administrative fines of up to €15m ($17.3m) or 2.5% of worldwide turnover, whichever is higher, for the most serious breaches, including failure to comply with Art 14 reporting obligations.


Get full access, free for a month

This is a free article. Try Premium free for 28 days to get every article on GRIP and more – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience