Berlin, 8 September 2026

From 11 September 2026 the reporting obligations under the Cyber Resilience Act apply. The first deadline is 24 hours.

Article 14 of Regulation (EU) 2024/2847 (CRA) applies from 11 September 2026, while the Regulation otherwise applies only from 11 December 2027 (Article 71(2)). The obligation falls on manufacturers of products with digital elements; open-source software stewards are drawn in through Article 24(3).

What has to be reported

  • Actively exploited vulnerabilities contained in the product – reported simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform (Article 14(1), Article 16).
  • Severe incidents having an impact on the security of the product (Article 14(3)). An incident is severe where it negatively affects, or is capable of affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or where it has led or is capable of leading to the introduction or execution of malicious code (Article 14(5)).

The deadlines

  • 24 hours – early warning from the moment of knowledge, naming the Member States in whose territory the product has been made available; for an incident, also whether unlawful or malicious acts are suspected (Article 14(2)(a), (4)(a)).
  • 72 hours – the notification: the product concerned, the nature of the exploitation or of the incident, and the corrective and mitigating measures taken as well as those users can take (Article 14(2)(b), (4)(b)).
  • 14 days after a corrective or mitigating measure is available – final report on the vulnerability, with severity, impact and any known malicious actor (Article 14(2)(c)); for incidents, one month after the notification (Article 14(4)(c)).
  • Intermediate report where the coordinating CSIRT asks for one (Article 14(6)).

Informing users, and who coordinates

  • Impacted users – and where appropriate all users – must be informed about the vulnerability or the incident and about any risk mitigation and corrective measures they can take, where appropriate in a structured, machine-readable format. Where the manufacturer fails to inform users in time, the coordinating CSIRTs may inform them instead (Article 14(8)).
  • Which CSIRT coordinates follows the main establishment in the Union – the Member State where decisions on the cybersecurity of the products are predominantly taken. Manufacturers without an establishment in the Union follow a cascade: authorised representative, importer, distributor, then the Member State with most users (Article 14(7)). This has to be settled before an incident, not during one.

Fines

Infringements of Article 14 carry administrative fines of up to EUR 15 million or 2.5 % of total worldwide annual turnover, whichever is higher (Article 64(2)). The structure of the exemption matters: the derogation in Article 64(10) – for micro and small enterprises on the 24-hour deadline, and for open-source software stewards – operates against paragraphs 3 to 9. It leaves paragraph 2 untouched, and paragraph 2 is the one that carries Article 14.

What is not yet binding – and already matters

Annex I, Part II (vulnerability handling requirements) applies only from 11 December 2027: identify and document vulnerabilities and components, including a software bill of materials in a commonly used machine-readable format; address and remediate vulnerabilities without delay; provide security updates separately from functionality updates; test and review regularly; publish information about fixed vulnerabilities; put in place and enforce a coordinated vulnerability disclosure policy; provide a contact address for reporting; distribute updates securely, without delay and free of charge. None of that is due in September 2026 – all of it is what makes a 24-hour deadline survivable.

Our recommendation

Two documents should be in place now, not after the first report:

  • A cybersecurity policy that assigns responsibility, defines what counts as knowledge and sets the escalation path, including a deputy and a weekend rule – the 24 hours run from knowledge, not from the next working day.
  • A published coordinated vulnerability disclosure (CVD) policy with a working contact address for vulnerability reports.

Further reading: What must be done? · CRA FAQ · Regulation text with article navigation

We advise manufacturers, importers and open-source organisations on CRA readiness – reporting workflow, disclosure policy, licensing and governance. Your contact: Roman Ronneburger, or through our contact page.

More on the CRA

Berlin, 8 September 2026

From 11 September 2026 the reporting obligations under the Cyber Resilience Act apply. The first deadline is 24 hours.

Article 14 of Regulation (EU) 2024/2847 (CRA) applies from 11 September 2026, while the Regulation otherwise applies only from 11 December 2027 (Article 71(2)). The obligation falls on manufacturers of products with digital elements; open-source software stewards are drawn in through Article 24(3).

What has to be reported

  • Actively exploited vulnerabilities contained in the product – reported simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform (Article 14(1), Article 16).
  • Severe incidents having an impact on the security of the product (Article 14(3)). An incident is severe where it negatively affects, or is capable of affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or where it has led or is capable of leading to the introduction or execution of malicious code (Article 14(5)).

The deadlines

  • 24 hours – early warning from the moment of knowledge, naming the Member States in whose territory the product has been made available; for an incident, also whether unlawful or malicious acts are suspected (Article 14(2)(a), (4)(a)).
  • 72 hours – the notification: the product concerned, the nature of the exploitation or of the incident, and the corrective and mitigating measures taken as well as those users can take (Article 14(2)(b), (4)(b)).
  • 14 days after a corrective or mitigating measure is available – final report on the vulnerability, with severity, impact and any known malicious actor (Article 14(2)(c)); for incidents, one month after the notification (Article 14(4)(c)).
  • Intermediate report where the coordinating CSIRT asks for one (Article 14(6)).

Informing users, and who coordinates

  • Impacted users – and where appropriate all users – must be informed about the vulnerability or the incident and about any risk mitigation and corrective measures they can take, where appropriate in a structured, machine-readable format. Where the manufacturer fails to inform users in time, the coordinating CSIRTs may inform them instead (Article 14(8)).
  • Which CSIRT coordinates follows the main establishment in the Union – the Member State where decisions on the cybersecurity of the products are predominantly taken. Manufacturers without an establishment in the Union follow a cascade: authorised representative, importer, distributor, then the Member State with most users (Article 14(7)). This has to be settled before an incident, not during one.

Fines

Infringements of Article 14 carry administrative fines of up to EUR 15 million or 2.5 % of total worldwide annual turnover, whichever is higher (Article 64(2)). The structure of the exemption matters: the derogation in Article 64(10) – for micro and small enterprises on the 24-hour deadline, and for open-source software stewards – operates against paragraphs 3 to 9. It leaves paragraph 2 untouched, and paragraph 2 is the one that carries Article 14.

What is not yet binding – and already matters

Annex I, Part II (vulnerability handling requirements) applies only from 11 December 2027: identify and document vulnerabilities and components, including a software bill of materials in a commonly used machine-readable format; address and remediate vulnerabilities without delay; provide security updates separately from functionality updates; test and review regularly; publish information about fixed vulnerabilities; put in place and enforce a coordinated vulnerability disclosure policy; provide a contact address for reporting; distribute updates securely, without delay and free of charge. None of that is due in September 2026 – all of it is what makes a 24-hour deadline survivable.

Our recommendation

Two documents should be in place now, not after the first report:

  • A cybersecurity policy that assigns responsibility, defines what counts as knowledge and sets the escalation path, including a deputy and a weekend rule – the 24 hours run from knowledge, not from the next working day.
  • A published coordinated vulnerability disclosure (CVD) policy with a working contact address for vulnerability reports.

Further reading: What must be done? · CRA FAQ · Regulation text with article navigation

We advise manufacturers, importers and open-source organisations on CRA readiness – reporting workflow, disclosure policy, licensing and governance. Your contact: Roman Ronneburger, or through our contact page.

More on the CRA