Written by: Haim Ravia, Dotan Hammer
On September 11, 2026, the reporting obligations under the EU Cyber Resilience Act (CRA) began to apply. Manufacturers of hardware or software products covered by the CRA must now promptly report actively exploited vulnerabilities and severe security incidents to EU authorities and to users, with an initial notification due within 24 hours.
The CRA applies to “products with digital elements” made available on the EU market where their intended purpose or foreseeable use includes a data connection to a device or network. The concept is broad, covering mobile applications, web platforms, standalone software, connected devices, laptops and tablets, standalone hardware components such as monitors and printers, and combinations of hardware and software such as smart TVs. The reporting obligations fall on “manufacturers,” a term that includes anyone who develops or manufactures a product with digital elements and markets it under their own name or trademark, whether for payment, for monetization or free of charge, and extend to companies marketing white-label products under their own name. Manufacturers established outside the EU are equally subject to these obligations where they make covered products available on the EU market.
Two categories of events must be reported. The first is any actively exploited vulnerability in the manufacturer’s product of which it becomes aware — meaning a vulnerability for which there is reliable evidence that a malicious actor has exploited it without the permission of the system owner. An exploited zero-day vulnerability is therefore reportable even where no patch is yet available. The second is any severe incident having an impact on the security of the product, meaning an incident that affects the product’s ability to protect the availability, integrity or confidentiality of sensitive or important data or functions, or that could lead to the introduction or execution of malicious code in the product or in the user’s network or information systems.
The reporting process is staged. An early warning notification is due within 24 hours of the manufacturer becoming aware of the event. A more detailed intermediate notification is due without undue delay and in any event within 72 hours, unless the relevant information has already been provided. A final report is due no later than 14 days after a corrective or mitigating measure becomes available, in the case of an actively exploited vulnerability, or within one month of the intermediate notification, in the case of a severe incident. The clock starts when the manufacturer becomes aware of the event, which occurs when its initial assessment confirms with reasonable certainty that a vulnerability in its product is being actively exploited or that a severe incident has occurred and compromised the product’s security. Notifications are submitted through the CRA’s Single Reporting Platform. Manufacturers must also inform affected users of the vulnerability or incident and, where necessary, of mitigation measures, extending to all users where appropriate.
The European Commission has clarified that the reporting obligations persist even after a product’s support period has ended, so manufacturers may still bear reporting obligations in respect of legacy products that are no longer supported. Failure to comply may result in administrative fines of up to €15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Click here to read the EU Cyber Resilience Act.
Click here to read the EU Commission guidance on the application of the Cyber Resilience Act (CRA).