Regulation (EU) 2024/2847 (the EU Cyber Resilience Act, CRA) activates its first compliance obligation on 11 September 2026, three years before the Act's general conformity assessment requirements take effect. From that date, manufacturers of products with digital elements within the CRA's scope must report actively exploited vulnerabilities and severe security incidents to the Computer Security Incident Response Team (CSIRT) designated in the member state where they have their main establishment.
Article 14 of the CRA governs the notification timeline. Manufacturers must submit an early warning through ENISA's Single Reporting Platform (SRP) within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. A full notification must follow within 72 hours. A final report is due no later than 14 days after a corrective measure becomes available for an exploited vulnerability, or within one month for severe incidents. The SRP routes each notification to the relevant member state CSIRT; ENISA receives the information simultaneously unless exceptional circumstances prevent it.
Software publishers, connected device manufacturers, IoT component producers, and industrial control system vendors placing products on the EU market must establish internal triage, detection, and escalation procedures capable of identifying and notifying a qualifying vulnerability or incident within hours of initial detection. Microenterprises and small enterprises are exempt from financial penalties for failing to meet the 24-hour early warning deadline specifically, but the reporting obligation itself applies to them. Manufacturers established outside the EU that sell into the EU market must designate an EU-established authorised representative to fulfil Article 14 obligations if they lack their own EU main establishment.
The CRA's full conformity assessment requirements, including mandatory third-party assessment for Important and Critical product categories defined in Annexes III and IV, do not apply until December 2027. Building Article 14 vulnerability management processes, monitored threat intelligence feeds, and incident classification procedures now reduces duplication of effort when the broader 2027 obligations become due.
We advise software vendors, hardware manufacturers, and their procurement counterparts on EU Cyber Resilience Act readiness, Article 14 vulnerability reporting programme design, and coordinated vulnerability disclosure policy drafting. Our partner network includes specialist cybersecurity law practices in EU member states. Work we undertake includes CRA scope analysis, vulnerability reporting programme design, ENISA Single Reporting Platform registration, and conformity assessment preparation.