
Article 14 of the Cyber Resilience Act (CRA) applies from 11 September 2026. It introduces reporting obligations for actively exploited product vulnerabilities and severe incidents affecting product security.
Who must report
The obligation applies to manufacturers of products with digital elements. According to the announcement by the National Security Authority (NBÚ), it also applies to relevant products that have already been placed on the European Union market.
Deadlines to observe
- Within 24 hours of becoming aware, an early warning must be submitted.
- Within 72 hours of becoming aware, a more detailed notification must be submitted.
First, check the correct reporting route
Mandatory reporting under the CRA, a voluntary security notification, a product-related submission and reporting under NIS2 are not interchangeable. The internal guide explains who must report and where to continue.
What to do now
Manufacturers should assign responsibility for assessing events, collecting the required information and meeting the deadlines. Before submitting a report, use the controlled CRA guide, which will direct you to the approved reporting service.