CRA Reporting from 11 September: What Must Be in Place

On 11 September 2026 Article 14 CRA takes effect – for the entire installed base too. Who it hits, what starts the 24-hour clock, and what must be ready.

In five days the first obligation of the Cyber Resilience Act that directly binds manufacturers takes effect. Article 14 of Regulation (EU) 2024/2847 applies from 11 September 2026 – roughly 15 months before all the product requirements, which only follow on 11 December 2027. We described the essentials at the end of July; this article asks what actually has to be in place by the deadline.

Readiness is modest. In a survey by the security vendor ONEKEY among 200 German industrial companies, 45 percent barely know the requirements or do not know them at all; 62 percent name the reporting duty itself as an obstacle, and 30 percent call it a serious problem. Internationally the picture is no better: in a June 2026 study by the Linux Foundation (843 respondents), 66 percent said they were not at all or only superficially familiar with the CRA.

The installed base is explicitly included

The single most important provision for mid-sized companies sits in the transitional rules. Article 69(2) protects products placed on the market before 11 December 2027 – but paragraph 3 explicitly exempts Article 14 from that protection: the reporting obligations apply “to all products with digital elements that fall within the scope of this Regulation and were placed on the market before 11 December 2027”.

For the reporting duties there is therefore no legacy protection and no grace period – unlike the remaining CRA requirements, which Article 69(2) exempts for existing products as long as they are not substantially modified. Machines that have been in the field for years, and software versions shipped long ago, fall under it from 11 September. The BSI puts it the same way in its Technical Guideline TR-03183-1: Article 14 is the exception to the legacy rule.

Who is meant – and who becomes a manufacturer involuntarily

The obligation binds the manufacturer. What matters, though, is Article 21: an importer or distributor counts as a manufacturer and is subject to the Article 14 duties if it places a product on the market under its own name or trademark, or substantially modifies it.

For trade and procurement this is the most expensive design decision in the process. Whoever leaves the third-party brand in place is an importer and owes comparatively light duties. Whoever puts their own logo on it is a manufacturer in full – including the 24-hour report. Mechanical engineering is similar: the Machinery Regulation does not displace the CRA, both apply side by side. Pure SaaS without a shipped product does not fall under the CRA; whether NIS2 applies instead depends on sector and company size.

What actually starts the 24-hour clock

Precision pays here, because the Regulation distinguishes three tiers. A “vulnerability” (Art. 3(40)) and an “exploitable vulnerability” (Art. 3(41)) trigger nothing. Only the “actively exploited vulnerability” (Art. 3(42)) is reportable – defined as one “for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner”.

A CVE in your own product, a pentest finding or a theoretically exploitable flaw therefore do not start the clock. A confirmed exploit in the wild does.

The second reporting track is broader than its name suggests. Under Article 14(5), a security incident already counts as severe if it negatively affects, “or is capable of affecting”, the product’s ability to protect. The yardstick is the security of the shipped product, not your own company’s ability to operate – an incident that barely disturbs you can still be reportable under the CRA.

The deadlines

  • 24 hours from awareness: early warning. For a vulnerability this includes naming the Member States in which the product was made available.
  • 72 hours from awareness: the notification proper, with product details, the nature of the exploitation and the measures already taken.
  • Final report: for a vulnerability, no later than 14 days after a corrective or mitigating measure is available – not from awareness. For an incident, one month after the 72-hour notification.

Reporting goes simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform under Article 16. For German manufacturers that is CERT-Bund at the BSI. The market surveillance authority is explicitly not an addressee – the CSIRTs inform it in turn.

Paragraph 8 is easily overlooked: you must also inform the affected users. The Regulation names no numeric deadline for this, only “without undue delay” – and if the manufacturer stays inactive, the CSIRT may inform the users itself.

What it costs if it is left undone

Breaches of Article 14 sit in the highest fine category of Article 64: up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. For micro and small enterprises, Article 64(10)(a) provides an exception: no fines are imposed on them for missing the 24-hour deadline, and recital 120 additionally urges Member States not to impose other financial penalties on them for it either. The exception concerns that deadline alone – the reporting duty itself and all other deadlines apply unchanged.

Do not expect relief elsewhere: the reporting duties under the CRA, NIS2 and the GDPR stand side by side, the same incident can trigger all three, and none replaces another. NIS2 at least provides for a single point of contact that Member States should also use for notifications under other Union law – that simplifies the route, not the obligation.

What must be in place by 11 September

  • A reporting process that holds for 24 hours. Who notices, who assesses, who decides, who reports – named, with deputies, on a Friday evening and through company holidays as well.
  • Access to the ENISA platform. Registration runs through an EU Login with multi-factor authentication. Note that ENISA explicitly advises against registering pre-emptively, while making clear that validation is not a prerequisite for fulfilling the reporting obligation. Plan for more than one authorised reporter.
  • A product inventory with market reference. Without knowing in which Member States a product was made available, the early warning cannot be given completely.
  • A channel for informing users under paragraph 8 – a distribution list or an advisory page.
  • An internal definition of when “awareness” begins. The Regulation does not define the term, even though the deadline hangs on it.

Do not count on a period of leniency. The sizing is worth noting, though: the German draft implementing act budgets for an average of 2,000 notifications per year, while the ZVEI, in its statement on the ministerial draft, counters that the BSI itself points to more than 42,000 vulnerabilities annually in its 2025 situation report. How well the reporting route holds in its first year remains to be seen – that changes nothing about your obligation.

How sector7 supports you

We build the reporting process with you so that it holds under time pressure: responsibilities and deputies, reachability, a product inventory with market reference, and the channel for informing users. The legal classification of your role under Article 21 is one for your legal advisors – we implement the technical and organisational requirements that follow from it. More under regulatory compliance and cyber security.

Sources

Let's talk about your situation.