Cyber Resilience Act: obligations to report vulnerabilities and incidents from September 2026
Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), which came into force on 10 December 2024, lays down horizontal cybersecurity requirements applicable to products with digital components placed on the internal market. Although it will not be fully implemented until 11 December 2027, the notification obligations set out in Article 14 are enforceable from 11 September 2026, regardless of the date on which the product was placed on the market.
This article requires manufacturers to simultaneously notify the CSIRT designated as the coordinator and ENISA of any actively exploited vulnerability and any serious incident, via the Single Reporting Platform (SRP), which will be available from that same date. The system is based on a three-stage process: early warning (24 hours), detailed notification (72 hours) and a final report, the deadline for which varies depending on whether it concerns an actively exploited vulnerability (14 days from the availability of a corrective measure) or a serious incident (one month from the 72-hour notification).
On 27 July 2026, the European Commission published its first non-binding interpretative guidance on the implementation of the CRA, which clarifies, amongst other issues, the concept of ‘becoming aware’, the non-retroactive nature of the obligation, the treatment of vulnerabilities in third-party components, and the duties to inform users and to defer disclosure in certain circumstances.
As regards subjective scope, although Article 14 primarily assigns notification obligations to manufacturers, the CRA provides for other scenarios: importers and distributors who market a product under their own brand or who make a substantial modification to it shall be deemed to be manufacturers, whilst open-source software stewards are subject to a specific regime set out in Article 24, limited to the notification of actively exploited vulnerabilities.
Failure to comply with these obligations may result in a graduated system of penalties, with fines of up to 15 million euros or 2.5 per cent of global turnover in the most serious cases, in addition to the possible withdrawal of the product by market surveillance authorities. Organisations that manufacture, import or distribute products containing digital components must plan ahead and adapt their internal procedures to identify affected products, define responsibilities and establish escalation mechanisms to ensure compliance with the notification deadlines required by the Regulation.