Alessandro Del Ninno
News
Cyber Resilience Act: Vulnerability and Severe Incident Reporting Obligations Apply from 11 September 2026.
CYBERSECURITY
11/09/2026

From 11 September 2026, one of the first sets of substantive obligations under Regulation (EU) 2024/2847 – the Cyber Resilience Act (CRA) has become applicable: manufacturers of products with digital elements are now required to report actively exploited vulnerabilities and severe incidents having an impact on the security of their products, in accordance with the timelines and procedures laid down in Article 14 of the Regulation. At the same time, ENISA has made the CRA Single Reporting Platform (SRP) operational as the single EU reporting point through which such notifications must be submitted.

This marks a particularly significant stage in the CRA’s phased implementation. The Regulation entered into force on 10 December 2024 and will become fully applicable on 11 December 2027. However, the EU legislature brought forward the application of certain provisions: following the rules concerning conformity assessment bodies, applicable from 11 June 2026, the Article 14 reporting obligations have applied since 11 September 2026.

The new requirements directly concern manufacturers of products with digital elements, broadly meaning entities that place on the Union market, under their own name or trademark, hardware or software products featuring a direct or indirect logical or physical connection to a device or network. The scope is therefore extremely broad and includes IoT devices, connected equipment, software, applications, operating systems, hardware and software components, industrial devices and numerous other categories of digital products.

A particularly important point is that the reporting obligations also apply to products with digital elements already made available on the Union market before 11 December 2027. Businesses should therefore not assume that they may wait until the CRA becomes fully applicable before adapting their vulnerability and incident management procedures: the Article 14 reporting regime is already in force.

Which events must be reported

The CRA distinguishes between two categories of events subject to mandatory reporting.

The first consists of “actively exploited vulnerabilities”. The mere existence of a vulnerability, or the fact that it could theoretically be exploited, is therefore insufficient. Under the Regulation, a vulnerability is considered actively exploited where there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner.

The second category concerns severe incidents having an impact on the security of a product with digital elements. An incident is considered severe where it negatively affects, or is capable of negatively affecting, the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or where it has led, or is capable of leading, to the introduction or execution of malicious code in the product or in the network and information systems of one of its users.

This distinction is also important from an operational perspective: not every vulnerability is subject to mandatory reporting under Article 14; the requirements for “active exploitation” must be met. Similarly, not every security anomaly or event will automatically qualify as a “severe incident”. Businesses must therefore be capable of rapidly assessing and classifying events against the definitions set out in the Regulation.

Reporting is subject to particularly stringent deadlines

The CRA establishes a sequence of successive notifications.

For an actively exploited vulnerability, the manufacturer must submit:

  • an early warning within 24 hours of becoming aware of the vulnerability;
  • a vulnerability notification within 72 hours, including, where available, general information concerning the affected product, the nature of the exploit and vulnerability, the corrective or mitigating measures already taken, and the measures that users may take;
  • a final report within 14 days after a corrective or mitigating measure becomes available, including at least a description of the vulnerability, its severity and impact, any available information concerning the malicious actor, and details of the security update or other corrective measures made available.

For severe incidents, the manufacturer must instead submit:

  • an early warning within 24 hours of becoming aware of the incident, indicating at least whether the incident is suspected of being caused by unlawful or malicious acts;
  • an incident notification within 72 hours, including, where available, information on the nature of the incident, an initial assessment and any corrective or mitigating measures taken;
  • a final report within one month of the 72-hour notification, providing a detailed description of the incident, its severity and impact, the likely type of threat or root cause, and the mitigation measures adopted or still underway.

The point at which the manufacturer becomes aware of the event is therefore critical, as it triggers very short reporting deadlines. Businesses must be capable not only of identifying relevant events, but also of documenting when the organisation first became aware of them and immediately activating their internal escalation process.

A single notification through ENISA’s EU reporting platform

In order to avoid fragmented reporting to multiple national authorities, Article 16 of the CRA provides for a Single Reporting Platform, developed, operated and maintained by ENISA and operational since 11 September 2026.

Manufacturers submit notifications through the endpoint of the CSIRT designated as coordinator in the Member State in which their main establishment in the Union is located. The notification is simultaneously accessible to ENISA and is subsequently shared, in accordance with the mechanism laid down in the Regulation, with the other CSIRTs concerned. The SRP therefore implements a “report once” mechanism, avoiding the need for businesses to submit the same notification separately in every Member State in which the product is made available.

For CRA purposes, the main establishment is deemed to be located in the Member State in which decisions relating to the cybersecurity of products with digital elements are predominantly taken. Where that Member State cannot be identified, the relevant establishment is the one employing the highest number of employees in the Union. The Regulation also establishes specific criteria for manufacturers that do not have a main establishment in the EU, referring, in sequence, to the Member State of the authorised representative, importer or distributor or, ultimately, the Member State in which the largest number of users of the products concerned is located.

Reporting to authorities is not enough: users must also be informed

Article 14 introduces a further obligation of particular importance. Upon becoming aware of an actively exploited vulnerability or severe incident, the manufacturer must inform the affected users and, where appropriate, all users of the product, and must also communicate, where necessary, any corrective or mitigating measures that users can take to reduce the impact.

Event management therefore cannot be treated as an exclusively internal process or one limited to communications with regulatory authorities. Businesses need procedures capable of coordinating technical incident response, legal assessment, regulatory reporting and communications to users, while ensuring the consistency and timeliness of the information provided.

Importers, distributors and substantial modifications also require attention

The obligations under Article 14 are addressed primarily to manufacturers. However, the CRA provides for circumstances in which importers or distributors themselves are deemed to be manufacturers: this occurs, for example, where they place a product on the market under their own name or trademark or carry out a substantial modification of a product already placed on the market. The same consequence applies to other persons that carry out a substantial modification and subsequently make the product available on the market.

Businesses operating along the supply chain should therefore carefully assess their legal status rather than assuming that the reporting obligations apply exclusively to the original technology manufacturer.

A specific regime applies instead to open-source software stewards: the reporting obligations applicable to them under Article 24(3) will apply from 11 December 2027, rather than from 11 September 2026.

What businesses should do now

The application of Article 14 requires immediate organisational adjustments. Manufacturers within scope should first map the products with digital elements covered by the CRA and clearly identify the entity responsible for reporting within the relevant corporate group.

From an operational perspective, businesses should establish or update a dedicated CRA vulnerability and incident reporting procedure, integrating it with their existing vulnerability management, product security and incident response processes. The procedure should enable them to:

  • rapidly determine whether a vulnerability qualifies as “actively exploited” and whether an incident reaches the threshold of a “severe incident”;
  • accurately record the point in time at which the manufacturer becomes aware of the event;
  • ensure immediate escalation to cybersecurity, legal, compliance and product functions;
  • collect, within extremely short deadlines, the information required for the 24-hour and 72-hour notifications;
  • identify in advance the persons authorised to operate through the Single Reporting Platform;
  • coordinate notifications to authorities with communications to affected users;
  • ensure traceability of corrective measures, security updates and mitigation activities undertaken.

Particular attention should also be paid to contractual arrangements throughout the supply chain. A manufacturer may depend on suppliers of hardware or software components in order to become promptly aware of a vulnerability or obtain the technical information required for reporting. Contracts, vulnerability disclosure clauses, cooperation obligations and escalation mechanisms should therefore be reviewed in light of the CRA reporting deadlines.

The new process must also be coordinated with any parallel notification obligations arising under other regulatory frameworks, including the NIS2 Directive and the relevant national implementing rules, the GDPR where a personal data breach is involved and, for entities in the financial sector, DORA. Event classifications, recipients, thresholds and deadlines may differ: the existence of the CRA Single Reporting Platform does not automatically replace or remove notification obligations arising under other regulatory regimes.

11 September 2026 therefore marks the transition of the Cyber Resilience Act from a regulatory framework still largely in its preparatory phase to a regime imposing immediately applicable obligations subject to extremely short response times. For hardware and software manufacturers, the ability to detect, classify, document and promptly report vulnerabilities and incidents has already become an essential component of EU cybersecurity compliance, more than a year before the CRA becomes fully applicable.