The Cyber Resilience Act entered into force on 10 December 2024. Since it will not apply in full until 11 December 2027, many companies have yet to start preparing. However, Article 14 already takes effect in September 2026, introducing mandatory early-warning obligations for manufacturers.
Cyber Resilience Act – in Brief
The Cyber Resilience Act (CRA) is a new EU regulation establishing cybersecurity requirements for all products with digital elements. Manufacturers, importers and distributors are subject to its requirements. The aim of the CRA is to make Security by Design and Security by Default mandatory throughout the entire product lifecycle. To achieve this, products will have to undergo a CRA conformity assessment.
The CE marking will subsequently indicate that the applicable requirements have been met. Vulnerability management also includes a machine-readable Software Bill of Materials (SBOM) documenting at least the product’s direct software dependencies. You can find out what SBOM tools should be capable of – not only with regard to the CRA – in the umbrella.associates blog article “Binaries in Focus – 360° Security with the Next Generation of SBOM Tools”.
What Qualifies as a Product with Digital Elements?
The CRA describes these products as follows: “Products with digital elements fall in scope of the CRA when they are made available on the market and their intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.”
At first glance, this appears to include all software and hardware products and related data-processing solutions. However, pure services or standalone SaaS offerings are not automatically considered products with digital elements. The following products are also among the exemptions:
- medical devices covered by the EU Medical Device Regulation
- certain type-approved motor vehicles, trailers and vehicle components
- products certified under European aviation legislation
- marine equipment falling within the scope of the Marine Equipment Directive
- products manufactured exclusively for national security, defence or the processing of classified information
The CRA requirements applying from 11 December 2027 generally affect products newly placed on the market after that date. For products that were already sold before then, the requirements will usually only apply if the product is substantially modified after that date.
A Maze of Obligations: What Applies When?
When first looking through the CRA, many decision-makers have focused primarily on this date and initially taken a more relaxed approach. After all, the transition period appears to leave some time for preparation. The major cut-off comes in mid-December 2027: from then on, manufacturers and other economic operators may only make affected products available and sell them in the EU if they can demonstrate CRA conformity.
But this means that many companies have overlooked another important date: 11 September 2026. From that point onwards, manufacturers of products with digital elements in particular will be required to report actively exploited vulnerabilities and severe security incidents.
Reporting Obligations – What Article 14 Requires and When
Before the other requirements apply, organisations already need to address the reporting obligations. These enter into force ahead of the other CRA requirements – on 11 September 2026. The CRA distinguishes between two types of reportable events.
Actively exploited vulnerabilities: A vulnerability is reportable if the company has reliable evidence that it has actually been exploited by a malicious actor. A vulnerability that could theoretically be exploited or has already been publicly disclosed does not automatically have to be reported.
Severe security incidents: Whether a security incident is considered severe depends on the availability, authenticity, integrity and confidentiality of important data and functions. Depending on the impact of an impairment, such an incident may become reportable. An incident is also considered severe if it has led, or may lead, to malicious code being introduced or executed in the product or in a user’s network and information systems.
In both cases, it is important to distinguish these events from ordinary operational disruptions, support cases and security events without severe consequences.
The reporting obligation does not distinguish between new and existing products. It applies to all products affected by an actively exploited vulnerability or a severe security incident, regardless of when the manufacturer placed them on the market. What matters is the date on which the manufacturer becomes aware of the issue.
Reporting Obligations in Three Stages
If one of the scenarios described above affects a product with digital elements, manufacturers must submit reports to the European Union Agency for Cybersecurity, ENISA – in three stages. The Single Reporting Platform, or SRP, has been set up for this purpose.
Early warning: Within the first 24 hours after becoming aware of the issue, responsible parties must submit an early warning. This should provide an initial assessment. If other Member States are affected, this information must be added. In the case of severe security incidents, manufacturers must also state whether there is reason to suspect that the incident resulted from unlawful or malicious activity.
Manufacturers can obtain the information required for this from their product inventory – including products, version statuses and countries of distribution – as well as from a Software Bill of Materials (SBOM).
Follow-up notification: No later than 72 hours after becoming aware of the incident or actively exploited vulnerability, a more detailed notification must be submitted. This must include the affected product with its exact name and version number, the nature of the vulnerability or incident, an initial assessment, measures already taken and any measures users can take themselves.
Final report: The final stage is divided into two different reporting deadlines. A final report for an actively exploited vulnerability must be submitted to ENISA no later than 14 days after a corrective or mitigating measure becomes available. It must address the severity, impact, information about the attacker where applicable, and details of the security update.
A final report for a severe security incident must be submitted within one month of the incident notification filed as part of the 72-hour stage.
Important: In addition to reporting to the competent authority, manufacturers must also inform affected users – and in some cases all other users. In particular, they must explain the risks involved as well as possible corrective and mitigating measures.
To-do List: How to Prepare for the CRA Reporting Obligations
Manufacturers now know what applies in the event of a security incident or an actively exploited vulnerability. But how can they prepare effectively given the limited time remaining?
- Define your product portfolio: Record all hardware, software and integrated remote components and document whether and why they fall within the scope of the CRA.
- Define responsibilities: Who does what? Establish a cross-functional CRA team that knows exactly what needs to happen and when in the event of an incident.
- Document the time of awareness: To comply with the deadlines, manufacturers must know exactly when they are considered to have become aware of an issue. Reports from bug bounty programmes, customer support, monitoring, threat intelligence and supplier communications should therefore be collected centrally.
- Develop a decision matrix: When is a vulnerability reportable? When is it considered actively exploited? When is an event an ordinary security event, and when does it qualify as a severe security incident? Clear definitions are essential to enable rapid action later on.
- Prepare reporting information: Product names, versions, affected EU countries, contact persons, user numbers, known impacts and available measures should all be accessible at short notice.
- Include suppliers and components: Check whether contracts and communication channels with suppliers ensure that information about exploited vulnerabilities is passed on to you without delay.
- Test reporting processes: Use a simulated scenario to check whether your reporting procedures work and whether you can meet the required deadlines.
Everything Covered?
Many manufacturers have not yet had the reporting obligations on their radar. But they can still catch up in just a few steps. Those who work through the to-do list now will be ready to meet their obligations in the event of an incident and report vulnerabilities or security incidents quickly. After all, this is also the first step towards addressing threats without unnecessary delay.
