Cyber Resilience Act Article 14 Reporting Starts 11 September 2026
04 Sep 2026
Manufacturers must Prepare Now to Meet new 24-hour and 72-hour Cybersecurity Reporting Deadlines
The next major Cyber Resilience Act deadline is approaching fast.
From 11 September 2026, manufacturers subject to the EU Cyber Resilience Act (CRA) must begin reporting certain actively exploited vulnerabilities and severe security incidents affecting products with digital elements.
While many organisations are focused on the CRA's broader product cybersecurity requirements that apply from December 2027, the reporting obligations arrive much sooner. Manufacturers have only days left to make sure they can identify and investigate a reportable event and submit the required information within tight regulatory timelines.
For organisations that do not yet have a defined CRA-aligned reporting process, now is the time to put one in place.
Imagine receiving credible evidence at 3 p.m. on a Friday that attackers are actively exploiting a vulnerability in one of your connected products used throughout Europe.
Could your organization determine whether reporting is required, identify the affected products, gather supporting evidence and submit an early warning before the reporting deadline expires?
What changes on 11 September 2026?
Article 14 of the CRA introduces mandatory reporting for two types of cybersecurity events:
Actively exploited vulnerabilities. These are vulnerabilities for which there is reliable evidence that a malicious actor has exploited a vulnerability in the product.
Severe incidents affecting the security of a product with digital elements. These include incidents that negatively affect, or could negatively affect, the product's ability to protect sensitive or important data or functions related to the product. An incident may also qualify if it has resulted, or could result, in malicious code being introduced or run on the product or within a user’s network or systems.
Manufacturers will report these events through the CRA Single Reporting Platform, established and managed by the European Union Agency for Cybersecurity (ENISA).
The reporting process begins when the manufacturer becomes aware of the actively exploited vulnerability or severe incident.
Once a reporting obligation is triggered, manufacturers have limited time to act.
An early warning must be submitted within 24 hours of becoming aware of the vulnerability or incident.
This is followed by a more detailed notification within 72 hours, including available information and an initial assessment.
Further reporting is then required:
- For an actively exploited vulnerability, a final report is required no later than 14 days after a corrective or mitigating measure becomes available.
- For a severe security incident, a final report is required within one month of the 72-hour incident notification.
The Single Reporting Platform provides one entry point for CRA reporting and distributes the notification to the relevant national CSIRT and ENISA.
Given these tight timelines, meeting the CRA reporting obligations without a defined process in place is impractical and creates unnecessary compliance and operational risk for the organisation.
Reporting Obligations can Apply to Products Already on the EU Market
Another important consideration is the scope of the September requirements.
The CRA’s broader product cybersecurity requirements generally apply from 11 December 2027. However, the reporting obligations start earlier, on 11 September 2026, and can apply to products that are already on the EU market.
This means manufacturers should not limit their preparations to new products being developed for future CRA compliance. Existing product portfolios may also need to be considered when establishing vulnerability and incident reporting processes.
Why Meeting the Reporting Requirement may be Harder Than it Sounds
A 24-hour notification deadline can appear straightforward: identify an event and report it.
In practice, several decisions may need to happen before a manufacturer can determine whether reporting is required.
For example:
- A vulnerability may first be identified by a security researcher, customer, supplier, or internal security team.
- The manufacturer must establish whether the vulnerability affects one or more of its products and determine whether there is evidence of active exploitation.
- An incident may need to be investigated to establish its impact and whether it meets the CRA criteria for a severe incident.
- Teams across product, engineering, cybersecurity, legal, regulatory and management may all need to provide information or make decisions.
- The organisation must also know when it became aware of the event, because that is what starts the regulatory reporting clock.
All of this may need to happen while the technical investigation and incident response are still underway.
Without defined responsibilities, escalation paths and decision-making processes, 24 hours can pass quickly.
What Should Manufacturers Do Now?
Manufacturers must not wait until the broader CRA requirements apply in 2027 to begin preparing.
At a minimum, organisations should now:
- Identify products that may be subject to the CRA reporting requirements.
- Establish clear ownership for CRA vulnerability and incident reporting.
- Ensure appropriate channels exist for receiving internal and external vulnerability information.
- Define how potential reporting events will be identified, investigated, and escalated.
- Establish how awareness dates and supporting evidence will be recorded.
- Confirm who is responsible for preparing, approving, and submitting CRA notifications.
- Validate that the process can operate within the required 24-hour and 72-hour timelines.
What Is the Risk of not Being Ready?
The reporting requirements are regulatory obligations.
The CRA provides for significant administrative fines for certain infringements, including penalties of up to €15 million or 2.5% of worldwide annual turnover in applicable circumstances.
Beyond financial penalties, organisations that wait until an active vulnerability or security incident occurs to define their reporting process may face delays, confusion and unnecessary internal escalation when fast decisions are critical.
Preparation can reduce that risk.
How Intertek Can Help
With the 11 September deadline approaching, Intertek can help manufacturers assess and strengthen their CRA reporting readiness.