Short answer: From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents — an early warning within 24 hours, a detailed notification within 72 hours, and a final report after that. Recipients are the coordinating CSIRT and ENISA simultaneously. The obligation also covers products that have long since shipped.
The common misconception is: "The Cyber Resilience Act arrives in 2027, there is time." It arrives in two stages. The Article 14 reporting obligation is the first, and it is the more uncomfortable one — because it does not apply at your next product release, but at your next incident.
Who is affected
The addressee is the manufacturer of a product with digital elements. That is broader than many assume: not only software, but also connected hardware — from machine controllers and IoT gateways to mobile apps. Anyone placing such a product on the EU market is covered.
Areas following their own sector-specific rules are excluded, among them medical devices, motor vehicles, aviation and marine equipment. Their reporting regimes apply instead — in some cases with shorter deadlines.
Two triggers, three stages
Article 14 knows two events. The first is an actively exploited vulnerability: what matters is not whether a flaw could be exploited, but whether it is being exploited. The second is a severe security incident. Paragraph 5 defines it in two cases: the event adversely affects the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions — or it leads to the introduction or execution of malicious code. Notably, it is sufficient that this effect may occur.
Both events run through the same three stages:
- Early warning — without undue delay, in any event within 24 hours of becoming aware.
- Detailed notification — within 72 hours of becoming aware.
- Final report — and here the paths diverge.
The early warning is allowed to be thin. In essence it requires who is reporting, which product in which version is affected, what this is about and in which Member States the product was made available. Missing details are supplied later. A late notification, by contrast, cannot be made up for.
The mistake that gets expensive
For the final report the deadline hangs on different anchors — and that is regularly confused in practice.
For an actively exploited vulnerability the final report is due within 14 days, counted from the point at which a corrective or risk-mitigating measure is available. As long as none is available, no deadline runs for the final report at all.
For a severe security incident it is due within one month, counted from the submitted 72-hour notification. Here the deadline hangs on an action of the manufacturer, not on the progress of remediation.
Anyone treating both cases the same will miscalculate one of them. In detail: The deadlines under Article 14 and Vulnerability or incident — which path applies?
Who receives the report
Reports go simultaneously to the CSIRT designated as coordinator and to ENISA — not sequentially, and not as a choice. Competence lies with the CSIRT of the Member State of main establishment; a fallback rule applies to manufacturers without an establishment in the Union. Submission runs via the single reporting platform under Article 16, which is still being built. More on this: Who receives the notification?
The obligation that tends to be forgotten
Paragraph 8 additionally requires informing affected users — about the vulnerability or incident and, where necessary, about risk-mitigating measures. This is not optional and not a marketing text; it runs in parallel with the authority notification.
What this means in practice
Three things pay off regardless of the date:
- A reliable list of your own products with versions and support period.
- A software bill of materials per release — you will need it anyway from 11 December 2027 for the technical documentation.
- A defined procedure: who is reachable within 24 hours in a real case and permitted to report?
The third point is where it fails in practice. A 24-hour deadline is not a task for the next sprint planning but for a named person with a deputy. And it runs on Saturdays too.
A free tool for it
We have turned the procedure into a tool: the CRA reporting assistant. It checks whether the obligation applies, calculates all deadlines from the moment you became aware, guides you through the mandatory details per stage and produces a submission-ready notification text in German and English — plus a case log as internal evidence.
Two things it explicitly does not do: it submits no notification — you do that yourself via the reporting platform. And it is not legal advice.
Your entries never leave the browser. There is no account and no storage on our servers; PDF generation runs locally too. That is not a side feature but a precondition: a form like this contains unpublished vulnerabilities.
And from 2027
The reporting obligation is the first date. On 11 December 2027 the remaining manufacturer obligations follow — essential requirements, conformity assessment, technical documentation, support period. Treating the first date as an isolated event means starting over a year later. The outlook: What is added from 11 December 2027. And if you also fall under NIS2: CRA and NIS2 — when does which apply?
Sources
- Regulation (EU) 2024/2847 of the European Parliament and of the Council (Cyber Resilience Act), in particular Article 14 (reporting obligations of manufacturers) and Article 16 (single reporting platform) — full text on EUR-Lex
- Article 14 in detail, paragraphs 1 to 8 — EUR-Lex, Official Journal L 2024/2847
- ENISA — the EU Agency for Cybersecurity, recipient of the notifications alongside the coordinating CSIRT — enisa.europa.eu
- BSI — CERT-Bund as the German national CSIRT — bsi.bund.de
This article reproduces the text of the regulation and stays general where the implementing acts on the format and procedure of notifications are still pending. It does not replace legal advice. As of 8 August 2026.

