The EU Cyber Resilience Act (Regulation (EU) 2024/2847) mostly applies from 11 December 2027, but its reporting duty for manufacturers has applied since 11 September 2026. It covers products with digital elements on the EU market, including products placed on the market before 2027. This page summarises what the published legal commentary says; it is not legal advice, so check the regulation and ENISA's guidance for your case.
What must be reported
- Actively exploited vulnerabilities in your product: there is reliable evidence that a malicious actor has used the vulnerability without the system owner's permission. A vulnerability found through good-faith research is not reportable on that basis alone.
- Severe incidents that affect the security of your product.
Commentary also notes there is no duty to report, retroactively, exploitation you already knew about before 11 September 2026.
The clock
- 24 hours: early warning, counted from when you become aware, meaning an initial assessment gives you reasonable certainty that exploitation is happening.
- 72 hours: the notification with more detail.
- 14 days after a fix or mitigation is available, for an exploited vulnerability; one month after the 72-hour notification, for a severe incident: the final report.
Where to report
ENISA's Single Reporting Platform went live for these duties. One submission reaches ENISA and the CSIRT designated as coordinator, normally the one where your main EU establishment is; manufacturers outside the EU report through their EU authorised representative. Secondary sources describe access through EU Login with multi-factor authentication. Register before you need it: a 24-hour deadline leaves no time to set up accounts.
A practical setup for a small team
-
A reporting inbox and a contact point. Annex I of the regulation expects a published way for outsiders to report vulnerabilities and a process to fix them. A
/.well-known/security.txtfile (RFC 9116) with a monitored address is the common way to publish the contact; practitioners recommend it, the regulation does not name it. - A written coordinated vulnerability disclosure policy that says how reports are received, acknowledged and fixed.
- An on-call rule for the 24-hour clock: who decides that exploitation is "reasonably certain", and who files.
- A component list (SBOM) for each product, so you can tell within hours whether a newly exploited library is inside it.
- Watch exploitation signals for the components you ship, such as known-exploited vulnerability catalogues, so awareness does not depend on a customer telling you.
Penalties
Fines under the regulation can reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher, for the most serious breaches of the essential requirements.
Sources
- ENISA: the CRA Single Reporting Platform is launched
- McCann FitzGerald: reporting obligations apply from 11 September 2026
- Jones Day: 24-hour reporting duties start 11 September 2026
- Matheson: recap of the reporting obligations
Kept current at https://tanod.dev/learn/cyber-resilience-act-reporting-small-vendors.html. Not legal advice; the regulation and ENISA's guidance prevail.
Top comments (0)