What happened
The EU Cyber Resilience Act's reporting obligations took effect on 11 September 2026, well before the rest of the law. The broader product compliance regime arrives in December 2027, but manufacturers selling digital products into the EU are already on a reporting clock.
The duty lands on manufacturers, defined widely as anyone who develops products or has them developed and markets them under its own name or trademark. A product does not need to be built in the EU for the law to bite. It only has to be placed on the EU market. A US company selling through a distributor counts as a manufacturer, and non-EU manufacturers must designate an authorised representative in the EU. Importers and distributors must pass vulnerabilities to the manufacturer without undue delay, and a private-label seller that puts its own name on a product inherits the full obligation.
Reports go to ENISA's CRA Single Reporting Platform and to the CSIRT coordinating the Member State of the manufacturer's main EU establishment. For an actively exploited vulnerability, an early warning is due within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix becoming available. For a severe incident, the same 24 hour and 72 hour steps apply, with a final report a month later. The 72 hour filing is mandatory even where an early warning was already submitted.
A severe incident does not have to harm a customer. It can cover a compromise of the manufacturer's own development or build environment, such as malicious code injected into a build pipeline, where that could increase risk for users. Teams following only US breach notification standards, which typically require unauthorised acquisition of data, will miss this. Products placed on the EU market before December 2027 are exempt from the product requirements but are still caught by the reporting rules. Maximum penalties reach 15 million euros or 2.5 per cent of worldwide annual turnover.
Why this is a GRC story
Twenty-four hours compresses the escalation path. GDPR allows 72 hours. The CRA requires the first filing inside a single day, and the clock starts on awareness rather than confirmation. Most organisations cannot get from a technical observation to an approved filing inside that window.
Detection scope has to widen to the build pipeline. If a compromised build environment is reportable even when no customer is affected, monitoring and classification have to cover where the product is made, not just where it is used. Many manufacturers treat their engineering estate as out of scope for regulatory reporting.
Registration is a pre-incident task. Onboarding to the platform, designating a primary representative and choosing a CSIRT coordinator cannot be done inside a 24 hour window, so they belong on a standing checklist, not in the incident runbook.
Several clocks can run at once. One event may trigger obligations under the CRA, NIS2, GDPR, SEC disclosure rules, HIPAA and state breach laws. Mapping who reports what, to whom, and in what order is now control design.
What to watch
Watch whether authorities enforce. Member States set penalties within the EU caps, so the bite will vary by country. The larger test arrives in December 2027, when secure-by-default configuration, software bills of materials and conformity assessment by notified bodies all become live obligations.
Attribution: Analysis based on JD Supra's publication of the Fisher Phillips analysis and the CRA reporting provisions themselves. This article is original commentary, not a repost of the source material.
