
Imagine a vulnerable device that, in the space of a single day, is distributed to thousands of customers across Europe. Until now, in such situations, it has largely been down to the manufacturer’s goodwill as to when and how they inform the public and the authorities. From 11 September 2026, however, this voluntary approach will become a clearly defined legal obligation – and the clock will start ticking the moment the manufacturer becomes aware of the problem.
What is this about?
The Cyber Resilience Act (Regulation (EU) 2024/2847, hereinafter referred to as the CRA) entered into force on 10 December 2024 and will only become fully binding on 11 December 2027. Most of the public debate has therefore so far focused on this furthest date – that is, on CE marking, conformity assessment and technical documentation. However, lurking in its shadow is another, much nearer date: 11 September 2026, when Article 14 of the CRA, governing the reporting of actively exploited vulnerabilities and severe security incidents, and Article 16, which provides for the establishment of a Single Reporting Platform (SRP), come into force.
This is therefore the first provision of the CRA that will affect manufacturers of products with digital elements (PDEs) in practice, regardless of whether they have already completed their conformity assessment or are only now preparing their documentation. Furthermore, the obligation also applies to products already on the market today – it is not, therefore, a rule that applies only to new products placed on the market after that date.
Two triggers, three deadlines
Article 14 CRA distinguishes between two situations in which a manufacturer is under an obligation to report. The first is an actively exploited vulnerability – a flaw in the product that attackers are demonstrably exploiting at that moment. This is not a routine CVE that a security team discovers and quietly patches as part of standard vulnerability management. The second trigger is a severe incident affecting the security of a product with digital elements.
In both cases, the same three-step process applies:
Within 24 hours of the manufacturer becoming aware of the problem, an early warning must be issued – a brief report stating that the incident has occurred, including information on whether there is any suspicion of unlawful or deliberate action, and in which Member States the product has been made available.
This is followed, within 72 hours, by a more detailed notification containing general information about the product, the nature of the vulnerability or incident, and any available corrective or mitigating measures.
The final report varies depending on the type of incident: in the case of an exploited vulnerability, it is submitted within 14 days of a corrective measure becoming available; in the case of a severe incident, within one month of the 72-hour report being submitted.
The key phrase is ‘becomes aware’ – that is, the moment the manufacturer has credible information about the exploitation, not the moment when everything is 100 per cent confirmed and documented. The clock may therefore well start ticking on a Friday evening.
Where and how to report?
Under Article 16 of the CRA, a Single Reporting Platform (SRP) is established at EU level, which is set up and operated by the European Union Agency for Cybersecurity (ENISA). The principle is simple: the manufacturer submits a report once, to the electronic endpoint of the CSIRT designated as coordinator for the Member State in which the manufacturer has its head office within the Union. The information is simultaneously made available to ENISA, and the relevant CSIRT shares it without undue delay with the CSIRTs of the other Member States where the product has been made available on the market.
The CRA also anticipates that individual Member States may, within this framework, establish their own national electronic entry points, which will be linked to the SRP. For manufacturers based in Slovakia, this national entry point is the existing NBÚ JISKB (Cybersecurity Single Information System) – reports submitted via JISKB are forwarded to the ENISA system and shared with the relevant CSIRTs in other Member States where the product is available. Manufacturers based in Slovakia should therefore focus primarily on JISKB, rather than attempting to report directly via the European SRP portal.
Why this is a fundamental change?
The previous practice of coordinated vulnerability disclosure (CVD) was largely voluntary and flexible in terms of timing. Article 14 of the CRA replaces this with fixed deadlines that carry legal weight. For organisations, this means that the entire process – from detection through internal escalation and legal assessment to the submission of a notification – must be completed within a matter of hours, not weeks, as was previously the case.
The practical impact is particularly noticeable in three areas:
Visibility into one’s own product portfolio and its components. Without an up-to-date overview of everything a product contains – that is, without a functioning SBOM (Software ) – it is impossible to reliably assess whether a specific vulnerability affects the product at all.
The supply chain. Many manufacturers rely on information from suppliers of components and software libraries. If contractual relationships do not include a clear obligation on the part of the supplier to report exploited vulnerabilities, the manufacturer may lack the information needed for timely reporting.
Readiness of the reporting process itself. Who is authorised to decide that a particular incident requires reporting, who drafts and approves the report, and whether this process functions outside normal working hours.
What should be done right now?
Given that Article 14 of the CRA has already come into force, there is no point in waiting for the final form of the system interconnection. It makes sense to focus on what is fully under the organisation’s control:
- Identify which products in the portfolio fall within the scope of the CRA – including those that have been on the market for several years.
- Verify registration and access to the JISKB and determine who within the organisation is authorised to submit and approve reports.
- Have a list ready of the Member States where individual products are available – this information is required for every report submitted.
- Have templates and an approval process prepared in advance for 24-hour and 72hour notifications, so that when an actual incident occurs, time is not wasted searching for the person responsible or drafting the text.
- Verify the functionality of the entire process through a drill scenario that simulates real-life time pressure – ideally outside standard working hours.
Until 11 September 2026, an organisation does not need to be fully compliant with the entire vulnerability management system as set out by the CRA – this is only required once the Regulation becomes fully applicable in December 2027. However, what must be in place now is the ability to quickly identify a relevant incident and submit the initial report within the statutory deadline.
Links to NIS2
The obligations under Article 14 of the CRA do not stand alone. They complement and partly overlap with the reporting obligations under the NIS2 Directive, which applies to operators of critical and significant services, whilst the CRA targets manufacturers of products with digital elements as such. Both sets of regulations share an emphasis on promptly informing national authorities of ongoing misuse, but differ in terms of the scope of entities subject to the obligations and the technical details of the reporting process.