Client briefing

CRA reporting from 11 September 2026

For software and connected-product manufacturers

What changes on 11 September

The reporting obligations in Article 14 of the Cyber Resilience Act become applicable. From that date, a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting the product's security, must report it to the CSIRT designated as coordinator and to ENISA. The essential cybersecurity requirements do not apply until 11 December 2027, so this is the first CRA duty most manufacturers will meet, and it arrives roughly fifteen months before the rest.

The three clocks

All of them run from the moment the manufacturer becomes aware — not from confirmation, not from triage, and not from the next business day. In practice this is the hardest part to operationalise, because somebody has to be able to say when awareness occurred and be reachable to say it.

  • 24 hours — early warning
  • 72 hours — the fuller notification
  • A final report — on a trigger that is not the awareness time, and differs between the two cases

Two reporting cases, two different final-report triggers

The 24 and 72 hour steps look alike in both cases. The final reports do not, and treating them as one clock is the most common way a readiness plan goes wrong.

Actively exploited vulnerabilityArticle 14(1), timings Article 14(2)
Final report, Article 14(2)(c): no later than 14 days after a corrective or mitigating measure is AVAILABLE, so there is no due date until one exists.
Severe incident affecting the security of the productArticle 14(3), timings Article 14(4)
Final report, Article 14(4)(c): within one month after the SUBMISSION of the incident notification under 14(4)(b), so there is no due date until that has been filed.

Neither is computable from the awareness time alone, which means a plan that calculates all three deadlines up front is wrong about the third.

What clients should have in place before the date

  • Which products are in scope, and who owns each one.
  • Who decides that the organisation has become aware, who covers them out of hours, and how that moment gets written down when it happens.
  • Who prepares the early warning, and what it must contain.
  • Who runs the further investigation for the 72-hour notification.
  • Where the report is filed, and who has access to file it.
  • One rehearsal before 11 September. A plan nobody has run is a document, not a capability.

The full checklist, twenty-four items

Free and open resources, no account or email required: readiness check, scope check, and a free session on 3 September.

Prepared by Legalithm. Article 14 reporting obligations apply from 11 September 2026; general application of the Cyber Resilience Act follows on 11 December 2027. Operational guidance, not legal advice. Regulatory source: the English-language Official Journal text of Regulation (EU) 2024/2847.