Cyber Resilience Act Dates: What Applies in 2026 and 2027
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.

Since 11 September 2026, manufacturers of products with digital elements, including manufacturers outside the EU, must report actively exploited vulnerabilities and severe incidents under Article 14 of the Cyber Resilience Act. Reports go through the ENISA single reporting platform to a national CSIRT coordinator: an early warning within 24 hours, a notification within 72 hours and a final report later. The duty already covers products on the EU market today, including those placed before 11 December 2027.
The reporting obligations are set out in Article 14 of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847. They are addressed to the manufacturer of a product with digital elements. A manufacturer established outside the EU has the same duty as one established inside it.
The scope is wider than many exporters expect. Most CRA requirements apply only to units placed on the market from 11 December 2027. The reporting obligations are different. Under the transitional provisions in Article 69, they apply to all products in scope that are made available on the EU market. This includes products placed on the market before 11 December 2027.
In practice, this means the models you already sell in the EU are covered today. A controller shipped in 2024 and still in use by EU customers can trigger a report in 2026. For the overall calendar of the regulation, see our guide to Cyber Resilience Act dates.
Open-source software stewards also have reporting duties, but these currently apply only from 11 December 2027. This guide focuses on manufacturers.
Article 14 covers two kinds of events. They follow the same three-step logic but are defined differently.
Actively exploited vulnerabilities. The CRA defines these as vulnerabilities for which there is reliable evidence that a malicious actor has exploited them in a system without the permission of the system owner. A weakness found in your own testing, with no sign of exploitation, is not in this category. You still have to handle it under your vulnerability handling process.
Severe incidents having an impact on the security of the product. Under Article 14(5), an incident is severe where:
The classification depends on the facts of each case, so record your reasoning each time.
Article 15 also allows voluntary notifications, for example of vulnerabilities that are not actively exploited or of cyber threats. These are separate from the mandatory reports.
The clock starts when the manufacturer becomes aware of the vulnerability or incident. Each step must be done without undue delay and in any event within the time limit below.
| Step | Actively exploited vulnerability (Art. 14(2)) | Severe incident (Art. 14(4)) |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Within 24 hours of becoming aware |
| Notification | Within 72 hours of becoming aware | Within 72 hours of becoming aware |
| Final report | No later than 14 days after a corrective or mitigating measure is available | Within one month after the incident notification |
The content grows at each step:
The coordinating authority can also ask for intermediate status updates. Implementing acts may further specify the format and procedure, so check the latest position.
Reports go to the CSIRT (Computer Security Incident Response Team) designated as coordinator, and simultaneously to ENISA, the EU cybersecurity agency. You do not send them separately. Under Article 14(7) and Article 16, you submit them through the single reporting platform run by ENISA, using the electronic end-point of the relevant CSIRT.
The relevant CSIRT is the one of the Member State of your main establishment in the EU. If you have no main establishment in the EU, Article 14(7) sets an order, based on the information available to you:
Work this out in advance and write it in your procedure, product family by product family if needed.
Platform status. ENISA announced on 11 September 2026 that the CRA Single Reporting Platform had been launched, and the Commission describes it as operational from that date. According to ENISA's published FAQ, access requires an EU Login account with multi-factor authentication, and the platform launched in English only. ENISA's platform documents use the term "assigned representative" for the individual user who submits notifications on behalf of a manufacturer. This is a platform role. It is a different thing from the authorised representative defined in the CRA. Check ENISA's pages for current access details before you need them.
Reporting to the authorities is only one part. Under Article 14(8), the manufacturer must also inform the impacted users, and where appropriate all users, of the vulnerability or incident. Where necessary, you must also tell them which risk mitigation and corrective measures they can deploy. Where appropriate, this should be in a structured, machine-readable format.
If you do not inform users in a timely manner, the notified CSIRTs may inform them directly when they consider it proportionate and necessary.
For non-EU manufacturers, the EU partner matters in three ways.
Our guide to the EU authorised representative explains the mandate and how to choose a partner.
A 24-hour deadline leaves no time to design a process during an event. A practical setup covers these points:
This sits next to your other after-sale duties under EU product law, such as handling complaints and corrective actions. The Cyber Resilience Act course covers vulnerability handling and the wider CRA requirements in more depth.
Penalties for infringements of the CRA, including the reporting obligations, are laid down at national level by the Member States under Article 64. National authorities decide on penalties in individual cases. Check the national rules of the Member States where you sell.
According to the Commission's summary of the CRA, manufacturers that qualify as microenterprises or small enterprises may not be fined for failing to meet the 24-hour deadline for the early warning. This concerns fines for the 24-hour deadline only: the reporting obligations themselves still apply.
To see how the CRA fits into the CE marking system as a whole, start with the free first module of CE Marking Fundamentals.
CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.
Yes. Under Article 69 of the CRA, the reporting obligations apply to all products with digital elements in scope that are made available on the EU market, including those placed on the market before 11 December 2027. Models you already sell in the EU are covered since 11 September 2026.
You must send an early warning within 24 hours of becoming aware of it and a vulnerability notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure is available. For severe incidents the final report is due within one month after the incident notification.
Article 14 places the obligation on the manufacturer, and reporting is not among the minimum tasks of an authorised representative in Article 18(3). You can agree support in the mandate, but plan to meet the deadlines yourself. Your representative's Member State can decide which CSIRT you report to if you have no main establishment in the EU.
ENISA announced the launch of the CRA Single Reporting Platform on 11 September 2026, and the Commission describes it as operational from that date. ENISA's FAQ states that access requires an EU Login account with multi-factor authentication. Check ENISA's pages for the current access details.
This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.
What an EU authorised representative does, the Article 4 tasks of Regulation (EU) 2019/1020, mandate limits and how non-EU manufacturers choose an EU partner.
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.
Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.
Thanks, you are on the list. We will be in touch before launch.