Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority
AnnouncementCurrent

Reporting Vulnerabilities and Severe Incidents under the CRA from 11 September 2026

Published: For: Manufacturers

Ilustračná grafika k povinnému nahlasovaniu zraniteľností a závažných incidentov podľa CRA

Article 14 of the Cyber Resilience Act (CRA) applies from 11 September 2026. It introduces reporting obligations for actively exploited product vulnerabilities and severe incidents affecting product security.

Who must report

The obligation applies to manufacturers of products with digital elements. According to the announcement by the National Security Authority (NBÚ), it also applies to relevant products that have already been placed on the European Union market.

Deadlines to observe

First, check the correct reporting route

Mandatory reporting under the CRA, a voluntary security notification, a product-related submission and reporting under NIS2 are not interchangeable. The internal guide explains who must report and where to continue.

What to do now

Manufacturers should assign responsibility for assessing events, collecting the required information and meeting the deadlines. Before submitting a report, use the controlled CRA guide, which will direct you to the approved reporting service.