Skip to content
AEGRYN
← Back to Blog

Compliance

The Cyber Resilience Act: Reporting Obligations for Digital Products Are Now Live

Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours of becoming aware. The CRA's full requirements only apply from December 2027, but the reporting clock is already running.

September 19, 2026 8 min read

Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), introduces mandatory cybersecurity requirements for products with digital elements throughout their lifecycle. Its reporting obligations, set out in Article 14, became applicable on 11 September 2026. Its main cybersecurity requirements, however, will only apply from 11 December 2027.

On the very day the reporting obligations took effect, ENISA launched the Single Reporting Platform (SRP), the single electronic channel through which manufacturers and open-source software stewards must simultaneously notify the coordinating national CSIRT and ENISA of any actively exploited vulnerability or severe incident.

Who must report, and about what

Article 14 obligations apply to manufacturers, defined as entities that design, develop or manufacture products with digital elements, whether themselves or through third parties, and place them on the EU market under their own name or trademark. Two categories of event must be reported.

  • Actively exploited vulnerability: a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner.
  • Severe incident: an incident that negatively affects, or is capable of affecting, the confidentiality, integrity or availability of the product's data or functions, or that has led or could lead to the introduction or execution of malicious code in the product or in a user's network and information systems.

A three-step clock, not a single deadline

Once a manufacturer becomes aware of a reportable event, the European Commission's guidance published in July 2026 sets out three successive deadlines, running from the moment the manufacturer has, following an initial assessment, a reasonable degree of certainty about the active exploitation or the severity of the incident.

  • Early warning: within 24 hours.
  • Notification: within 72 hours.
  • Final report: within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month of the 72-hour notification for a severe incident.

Manufacturers must also inform impacted users, and where appropriate all users of the product, so that they can take mitigating action on their own systems.

The scope is wider than it first appears

The reporting obligations already cover products placed on the EU market before the CRA's full application date, including legacy products, and continue to apply after a product's official support period has ended. The one relief confirmed by the Commission's guidance: manufacturers are not required to retrospectively report active exploitation they were already aware of before 11 September 2026.

11 sept. 2026

entry into application of the reporting obligations (Article 14)

11 déc. 2027

entry into application of the CRA's full cybersecurity requirements

24h / 72h / 14j

early warning, notification, final report

10 ans

minimum retention period for technical documentation

Why product security becomes a transaction question

For a tech vendor, a hardware manufacturer or an industrial software publisher, the CRA changes the due diligence conversation the same way NIS2 changed it for critical infrastructure operators. A buyer assessing a product company will increasingly ask not only whether the product works, but whether its manufacturer can demonstrate a functioning vulnerability disclosure and reporting process, evidence of security-by-design decisions taken during development, and ten years of retained technical documentation.

A company that has never had to report a vulnerability is not necessarily a company without vulnerabilities. It may simply be a company that has never tested whether it could report one within 24 hours.

Aegryn

Aegryn Advisory supports organisations that design, develop or manufacture products with digital elements in structuring vulnerability management, incident reporting readiness and technical documentation under the Cyber Resilience Act, and certifies the outcome under the CIFSO Security & Sovereignty dimension, ahead of the moment a buyer, insurer or regulator asks for proof.

IA

This article was written with the assistance of artificial intelligence and reviewed under Aegryn editorial responsibility. In accordance with Article 50 of the EU AI Act, we assume editorial responsibility for this content.

Insights Aegryn

Recevez chaque semaine les analyses Aegryn — M&A, valorisation, tech, CIFSO.

Ready to submit your asset or access the catalogue?