Written by: Haim Ravia, Dotan Hammer
The reporting obligations under the EU Cyber Resilience Act (CRA) will take effect on September 11, 2026 — more than a year before the CRA’s general application date of December 11, 2027.
Under Article 14(1) and (3) of the CRA, a manufacturer of a product with digital elements placed on the EU market must notify, using the established single reporting platform, of any actively exploited vulnerability contained in its product with digital elements of which it becomes aware, and of any severe incident impacting the security of the product of which it becomes aware. The authorities that must be notified are a national Computer Security Incident Response Team (CSIRT) designated as coordinator under the CRA, and the European Union Agency for Cybersecurity (ENISA).
This Article 14 notification obligation applies from September 11, 2026, to all products with digital elements within the CRA’s scope. Unlike the vulnerability handling obligations in the CRA, which run only for the length of a product’s support period, the reporting obligations continue to apply after a product is no longer supported.
Where a manufacturer of a product with digital elements detects a suspicious event, or where a third party — an individual, a customer, an entity, an authority or a media organization — brings a potential incident or vulnerability to its attention, the manufacturer must assess the event immediately. It is regarded as having become aware when, after that initial assessment, it has a reasonable degree of certainty either that a vulnerability contained in its product is being actively exploited, or that a severe incident has occurred and has compromised the security of its product. The guidance stresses prompt action on the initial assessment, particularly where the vulnerability may pose a significant risk.
The notification structure is progressive. An early warning containing limited information is due without undue delay and in any event within 24 hours of becoming aware. A fuller notification with additional information follows without undue delay and in any event within 72 hours. The complete report is due within 14 days after a corrective or mitigating measure becomes available, in the case of an actively exploited vulnerability, or within one month of the 72-hour notification, in the case of a severe incident.
CRA guidance addresses several scope questions. There is no retroactive reporting: a manufacturer need not report vulnerabilities whose active exploitation it had already become aware of before September 11, 2026. But where it knew of a vulnerability before that date without knowing of any active exploitation, and exploitation subsequently occurs or comes to its attention after that date, the vulnerability becomes reportable. As to third-party components, a manufacturer must report an actively exploited vulnerability originating in a third-party component that is contained in its product; but where the vulnerable code either cannot be exploited in its product (for example, because it is not reachable) or has not been exploited in its product, the vulnerability is not subject to mandatory reporting.
Finally, Article 14(8) of the CRA requires manufacturers to inform impacted users and, where appropriate, all users, after becoming aware of an actively exploited vulnerability or severe incident; if they fail to do so in a timely manner, the CSIRTs that received the notification may inform users themselves where proportionate and necessary. The Commission reads this obligation in a risk-based and proportionate way: informing users does not mean indiscriminate public disclosure, and manufacturers may limit detailed information to the users or customers concerned, particularly for products used in sensitive or essential environments where public technical detail could itself increase risk. Broader disclosure becomes appropriate once the vulnerability has been adequately addressed.
Click here to read the European Commission’s guidance on the application of the Cyber Resilience Act.