EU Cyber Resilience Act Reporting Rules Take Effect for Tech Makers
New cybersecurity reporting requirements under the European Union’s Cyber Resilience Act (CRA) are now in effect, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents affecting their products. The reporting obligations began on September 11, making September 12 the first full day under the new regime.
Manufacturers must submit an early warning within 24 hours of becoming aware of a qualifying vulnerability or incident. A fuller notification is due within 72 hours, followed by a final report within specified deadlines depending on whether the case involves an exploited vulnerability or a severe incident.
24-Hour Reporting Clock Begins
The new rules cover hardware and software products with digital elements made available in the EU. That includes a broad range of connected products, software and components rather than only traditional cybersecurity products. The obligation is triggered when a manufacturer becomes aware that a vulnerability is being actively exploited or that a severe incident is affecting the security of its product.
The first notification is intentionally limited to an early warning. Manufacturers then have 72 hours to provide a fuller notification with additional information and an initial assessment. For an actively exploited vulnerability, the final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. Severe incidents have a separate final-report deadline of one month.
ENISA Platform Handles Notifications
The reporting process runs through the Cyber Resilience Act’s Single Reporting Platform, operated by the European Union Agency for Cybersecurity (ENISA). Manufacturers submit a notification through the platform to the relevant national Computer Security Incident Response Team, while the information is also made available to ENISA.
The system is designed to avoid forcing manufacturers to make separate reports to multiple EU authorities. The receiving CSIRT can share the notification with other relevant national CSIRTs and market-surveillance authorities where required.
Most CRA Requirements Come Later
The September reporting deadline does not mean the entire Cyber Resilience Act is now fully applicable. The broader set of CRA requirements, including the main cybersecurity requirements for products and related conformity obligations, will apply from December 11, 2027.
For manufacturers, however, the reporting obligation is already operational. The rules also apply to products that were already available on the EU market before the CRA's broader 2027 application date, although the reporting duty is triggered by when the manufacturer becomes aware of qualifying active exploitation or severe incidents.
The new reporting system gives European regulators a faster way to track serious security problems affecting connected products. For technology manufacturers selling into the EU, the immediate requirement is clear: when qualifying exploitation or a severe product-security incident is discovered, the reporting clock can start within hours.
