News & Updates

What! Another reporting obligation!?

Cartoon of a stressed office worker sitting at a computer desk biting his nails, thinking: "We're aware of a vulnerability with our EU software. What do we have to do now and who do we have to notify?!" Next to him is a calendar marked "11th September 2026."

Victoria (Vicky) Hordern – Privacy, Data and AI Partner at Digiphile.

September 8, 2026.

Somewhat overlooked by the excitement of other EU laws (most particularly the EU AI Act), a significant part of the EU’s Cyber Resilience Act will be coming into force later this week – Friday 11 September 2026. This is Article 14 – reporting obligations of manufacturers.

What does this mean from 11 September?

  • If you’re providing a product with digital elements (which includes software as well as hardware) in the EU, you will be subject to a new reporting obligation – there is no grace period for products already on the EU market.
  • The obligation is to report (i) actively exploited vulnerabilities in the product that you become aware of and (ii) severe incidents affecting the product’s security that you become aware of, both to be reported through a single reporting platform provided by ENISA (not yet operational but FAQs here)
  • You must report to the CSIRT (in the Member State where you have your main establishment) as well as to ENISA.

 

What are the timings for reporting?

  • ASAP and within 24 hours of becoming aware – the manufacturer must provide an early warning notification of an actively exploited vulnerability/ severe incident
  • Within 72 hours of becoming aware – provide a vulnerability notification or incident notification which provides more information including measures taken to mitigate
  • For vulnerability reports – within 14 days after a mitigating measure is available – provide a final report including more substantive information on the vulnerability
  • For severe incident reports – within 1 month after the incident notification – provide a final report on the incident.

 

What about affected users?

  • Manufacturers must also notify users of the product about the vulnerability or severe incident and provide information on how they can mitigate its impact on them.  If a manufacturer fails to tell users, a CSIRT can tell them instead.

 

The CRA reporting obligation sits alongside the other reporting requirements under GDPR, NIS2 plus other laws. Companies will need to develop new (or fine tune existing) processes to ensure compliance with their various reporting requirements.

Stay tuned for my colleague Marco Piana‘s post on the developments later this week…