EU Cyber Resilience Act: New reporting obligations now apply
A significant part of the EU’s Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements better known as “Cyber Resilience Act (CRA)” has entered into force. Since 11 September 2026, manufacturers of products with digital elements are subject to mandatory reporting obligations for certain cybersecurity vulnerabilities and incidents. The new requirements apply ahead of the CRA’s broader application from 11 December 2027.
Thus, manufacturers must notify actively exploited vulnerabilities contained in their products and severe incidents having an impact on the security of their products (Article 14 CRA). The reporting process follows a staged approach: an early warning must generally be submitted within 24 hours of becoming aware of the relevant vulnerability or incident, followed by a more detailed notification within 72 hours. Further final reporting requirements apply depending on whether the notification concerns an actively exploited vulnerability or a severe incident.
Notifications must be submitted through the new CRA Single Reporting Platform (SRP) established and operated by the European Union Agency for Cybersecurity (ENISA). The platform became operational on 11 September 2026 and is intended to provide a single reporting channel rather than requiring manufacturers to notify multiple national authorities separately. The notification is directed to the competent Computer Security Incident Response Team (CSIRT) and, subject to limited exceptions, is simultaneously made available to ENISA and subsequently shared with the relevant CSIRTs in other Member States in which the product has been made available.
The scope of the new obligations is potentially broad. According to the European Commission, the reporting requirements extend to products with digital elements made available on the EU market, including products already on the market. Consequently, the reporting regime is relevant not only to products first placed on the market after the CRA becomes fully applicable in December 2027.
The commencement of the reporting regime marks an important step in the phased implementation of the CRA. While most of the Regulation’s substantive cybersecurity requirements – including requirements relating to the design, development and maintenance of products with digital elements – will apply from 11 December 2027, the reporting provisions now constitute an independently applicable part of the EU cybersecurity framework. Reporting obligations for open-source software stewards will likewise apply from 11 December 2027.
The European Commission has published further information on the scope and operation of the new reporting requirements, while ENISA provides guidance, FAQs and practical materials concerning the use of the Single Reporting Platform.