Skip to Primary Navigation

Reporting exploited vulnerabilities and severe security incidents under CRA

Computer Engineers seen Through Circuit Board
Photo: Getty Images

The vulnerability was real; the exploit was impossible; the EU Cyber Resilience Act reporting obligation was … unclear? We discuss the intricacies of the Act and compare with UK approach.

Beginning September 11, 2026, manufacturers of products with digital elements that are made available on the European Union market must report actively exploited vulnerabilities and severe security incidents concerning those products under the EU Cyber Resilience Act (CRA).

The CRA applies to products with digital elements, including hardware and software products such

Get full access, free for a month

Start your 28-day free trial to continue reading and accessall content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience