The reporting requirements under the Cyber Resilience Act (Regulation (EU) 2024/2847, 'CRA') take effect on 11 September 2026. This date is the first of the CRA's three phased deadlines, preceding the general compliance date of 11 December 2027 by more than fourteen months. The reporting obligations also apply to products with digital elements placed on the EU market before the CRA's full compliance date, provided those products remain on the market.
Article 14 CRA obliges manufacturers of products with digital elements to notify the designated national Computer Security Incident Response Team (CSIRT) and ENISA of any actively exploited vulnerability in their product and of any severe incident affecting product security. A preliminary notification is due within 24 hours of the manufacturer becoming aware of the event. A follow-up notification must be submitted within 72 hours. A final report is due no later than 14 days after a corrective measure is available for actively exploited vulnerabilities, or within one month for severe incidents.
Manufacturers placing products with digital elements on the EU market bear the reporting duty directly, with no exception for company size or sector. Affected entities include software publishers, IoT device makers, cloud service component providers, and any other entity whose product contains digital elements and is placed on the EU internal market. National market surveillance authorities hold enforcement powers under the CRA's penalty provisions.
ENISA launched the Single Reporting Platform on 11 September 2026 to receive mandatory notifications. ENISA is a coordination and collection point, not a supervisory authority for enforcement purposes. Products placed on the EU market before 11 December 2027 are also subject to the September 2026 reporting requirements if they remain on the market at that date.
Licentium and its partner network advise manufacturers and importers on CRA readiness. Work we undertake includes product compliance reviews, notification procedure design, CSIRT coordination support, and EU regulatory filing assistance.