Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Technology Quotient
  4. Cyber Resilience Act reporting obligations take effect on 11 September 2026
3MIN

Cyber Resilience Act reporting obligations take effect on 11 September 2026

Aug 31 2026

The Cyber Resilience Act (Regulation (EU) 2024/2847, the CRA) enters its next implementation phase on 11 September 2026. From that date, manufacturers must report certain cybersecurity vulnerabilities and incidents affecting products with digital elements (PDEs), more than a year before most other CRA requirements apply. The reporting obligations also cover PDEs placed on the EU market before the CRA becomes fully applicable in December 2027.

In our previous three-part series, Decoding the Cyber Resilience Act, we examined its scope and impact, the lifecycle approach to compliance and the management of CRA risk in practice. With the first operational reporting requirements now approaching, manufacturers should ensure that their reporting processes are ready.

What must be reported?

Under Article 14 CRA, manufacturers of PDEs must report:

  • Actively exploited vulnerabilities contained in a PDE. A vulnerability is actively exploited where there is reliable evidence that a malicious actor has exploited it in a system without the system owner’s permission.
  • Severe incidents affecting the security of a PDE. An incident is severe if it affects, or could affect, the PDE’s ability to protect sensitive or important data or functions, or if it has led, or could lead, to malicious code being introduced or executed in the PDE or a user’s systems.

Notification must be submitted through the CRA’s Single Reporting Platform (SRP). The platform is not yet live and is expected to become operational on 11 September 2026. ENISA has already published FAQs and user guidance on the platform and the reporting process. 

An early warning is required within 24 hours of becoming aware of the event, followed by a more detailed notification within 72 hours. For an actively exploited vulnerability, a final report must follow within 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after submission of the incident notification.

Manufacturers must also inform impacted users and, where appropriate, all users about the vulnerability or incident and any measures they can take to mitigate its impact.

When does the reporting clock start?

The reporting periods begin when the manufacturer becomes aware of the relevant vulnerability or incident. According to the CRA guidance published by the European Commission on 27 July 2026, this occurs when an initial assessment provides a “reasonable degree of certainty” that a vulnerability is being actively exploited or that a severe incident has occurred and compromised the PDE’s security.

As practitioners will know from other EU reporting regimes, the clock does not stop at weekends or on public holidays. This follows from the general rules on calculating EU time limits set out in Regulation (EEC, Euratom) No 1182/71.

What should manufacturers do now?

The short reporting windows leave little room to establish processes after an event occurs. Manufacturers should put in place dedicated procedures for receiving, assessing and escalating information about potential vulnerabilities and incidents. They should clearly allocate responsibility for determining whether the reporting threshold is met, submitting notifications and communicating with affected users. Their processes should also address how CRA notifications will be coordinated with parallel obligations under the NIS2 Directive and the GDPR (at least as long as the Digital Omnibus has not yet consolidated the reporting channels – see our previous blog post for more detail). Clear internal ownership and rapid escalation will be essential to meeting the CRA’s reporting deadlines.

Tags

eu cyber resilience acteu digital strategydata cybersecurity and tech regulationtechnology

Authors

Düsseldorf, Frankfurt am Main

Theresa Ehlen

Partner
Brussels

Satya Staes Polet

Partner
Brussels

Quentin Fontaine

Associate
Berlin

Dr. Leonie Wittershagen

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome