What happened

The reporting duties in Article 14 of the EU Cyber Resilience Act became applicable on 11 September 2026. Manufacturers of products with digital elements made available in the EU must now submit an early warning to the authorities within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours. The same deadlines apply to severe incidents affecting the security of those products.

The obligations apply to manufacturers regardless of where they are based, subject to the regulation's exemptions. Reports are filed through ENISA's Single Reporting Platform and addressed to the coordinating computer security incident response team determined under the CRA. For a manufacturer established in the EU, that is generally the CSIRT for the member state where it has its main establishment, and separate rules decide the coordinator for manufacturers outside the bloc.

Manufacturers must also tell affected users about actively exploited vulnerabilities or severe incidents where appropriate, including the corrections or mitigations available, without undue delay. Failures under the CRA carry tiered fines, and the most serious reach €15 million or 2.5 percent of annual turnover, whichever is higher. The reporting duties are classified as core responsibilities, which means they can attract the maximum penalties.

This is the first wave. The remaining provisions, including security by design and by default, no default passwords and mandatory security updates, apply from 11 December 2027.

Why this is a GRC story

The clock starts at awareness, not at certainty. Twenty four hours is enough time to file a report if the path is already built: a named owner, a template, a decision on who approves the submission, and a route into the platform. It is not enough time to invent that process after the alert lands.

That turns an engineering question into a governance question. What counts as awareness inside your organisation? A support ticket from a customer, a threat intelligence feed, a researcher email at 6pm on a Friday? The people who can answer that fastest are usually not the ones running the vulnerability scanners, so the escalation path has to be written down and tested before it matters.

Scope is the other half. Because the duties apply to manufacturers outside the EU as well, a vulnerability handling function that was built as an internal PSIRT process is now a regulatory filing obligation with a deadline and a fine attached. Firms shipping products into Europe need to know which of their products are in scope and which exemptions apply, and that mapping is a legal and product question as much as a security one.

What to watch

Watch how ENISA's platform and the national CSIRTs handle the first weeks of volume, and what an early warning looks like in practice. Reporting at 24 hours means filing with incomplete information, and the guidance on how much detail is expected will shape how usable these reports are.

Watch the guidance on what actively exploited and awareness mean in concrete terms, and how the December 2027 tranche is enforced. For compliance teams already working through NIS2 and the rest of the EU's digital legislation, the open question is how these overlapping duties get coordinated inside one programme.

Attribution: Analysis based on The Register's reporting and the EU Cyber Resilience Act text. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News