EU Cyber Resilience Act: Digital Product Makers Face 24-Hour Cyber Incident Reporting Rule
Manufacturers placing products with digital elements on the European Union market are now subject to a new cybersecurity reporting regime requiring them to notify authorities within 24 hours of...
Manufacturers placing products with digital elements on the European Union market are now subject to a new cybersecurity reporting regime requiring them to notify authorities within 24 hours of becoming aware of certain actively exploited vulnerabilities or severe security incidents.
The reporting obligations under the EU’s Cyber Resilience Act (CRA) took effect on 11 September 2026, ahead of the regulation’s broader application in December 2027.
The requirement covers a wide range of hardware and software products with digital elements, meaning the compliance impact extends well beyond traditional technology companies. Products can include connected consumer devices, software and other digitally enabled products placed on the EU market.
Under the new regime, manufacturers must submit an early-warning notification within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting the security of a product.
A more detailed notification must follow within 72 hours, providing additional information and an initial assessment. Final reporting deadlines then depend on whether the matter concerns an actively exploited vulnerability or a severe incident.
For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective measure becomes available. For severe incidents, a final report is required within one month of the 72-hour notification.
Manufacturers are required to make their notifications through the CRA Single Reporting Platform (SRP) established by the European Union Agency for Cybersecurity (ENISA).
The system is intended to simplify compliance by allowing manufacturers to report once rather than separately notifying multiple national authorities. The notification is routed to the relevant national Computer Security Incident Response Team (CSIRT), with information generally made available simultaneously to ENISA. Digital Strategy+1
ENISA’s guidance specifies that the reporting process begins when a manufacturer becomes aware of an actively exploited vulnerability or severe security incident. The platform’s reporting fields can require information including vulnerability identifiers, exploitation details, severity, impact, mitigation measures and potential root causes. ENISA
The new deadlines effectively connect cybersecurity incident response with regulatory compliance.
Manufacturers will need processes capable of identifying potentially reportable incidents, escalating them internally and determining whether the CRA reporting threshold has been met quickly enough to satisfy the 24-hour requirement.
The European Commission’s July 2026 implementation guidance was designed to help manufacturers and businesses understand the CRA’s requirements, including reporting, cybersecurity risk assessment and vulnerability-handling obligations.
The CRA also requires manufacturers to address cybersecurity throughout the product lifecycle, including vulnerability management during the product’s defined support period. Digital Strategy
While the reporting provisions are already applicable, the full Cyber Resilience Act becomes applicable on 11 December 2027.
The regulation establishes cybersecurity requirements for hardware and software products made available on the EU market, with manufacturers bearing key responsibilities for security-by-design, risk assessment, vulnerability handling and user information.
For compliance and risk professionals, the immediate priority is therefore not simply preparation for 2027. The incident-reporting clock has already started.
Compliance takeaway: Manufacturers selling digital products into the EU should have a documented process for detecting, assessing, escalating and reporting actively exploited vulnerabilities and severe security incidents—and that process must be capable of triggering the required notification within 24 hours of awareness.


No Comment! Be the first one.