The Cyber Resilience Act (Regulation (EU) 2024/2847, the CRA) enters its next implementation phase on 11 September 2026. From that date, the reporting obligations in respect of certain cybersecurity vulnerabilities and incidents affecting products with digital elements (PDEs) under Article 14 apply. PDEs are any software or hardware product and their remote data processing solutions, including software or hardware components placed on the EU market separately. Examples include connected home cameras, smart fridges and smart televisions.
Whilst this is EU legislation, this is relevant to UK manufacturers as the CRA and the imminent reporting requirements will apply to companies outside of the EU if they place products with digital elements on the EU market or make them available there. Organisations might also find the following guidance helpful: the European Commission's CRA implementation guidance, ENISA guidance regarding the SRP and German Federal Office for Information Security guidance.
The bulk of the CRA's substantive requirements (the Annex I essential requirements, conformity assessment and CE marking) apply from 11 December 2027 with further information available here: European Cyber Resilience Act - Stevens & Bolton LLP. The potential penalties for non-compliance under the CRA are significant and include fines of up to EUR15m or up to 2.5% of global annual turnover.
What must be reported?
Under Article 14 of the CRA, manufacturers of PDEs must report two categories of event:
- Actively exploited vulnerabilities contained in a PDE; a vulnerability is actively exploited where there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. Notably, public disclosure, a proof-of concept or a researcher demonstration is not sufficient – reliable evidence of exploitation is required.
- Severe incidents affecting the security of a PDE; an incident is severe (the criteria sit in Article 14(5)) if it affects, or could affect, the PDE's ability to protect sensitive or important data or functions, or if it has led (or could lead), to malicious code being introduced or executed in the PDE or a user's systems.
The reporting timeline
The below reporting periods begin when the manufacturer becomes aware of the relevant vulnerability or incident, which according to guidance occurs when an initial assessment provides a “reasonable degree of certainty” that a vulnerability is being actively exploited or that a severe incident has occurred and compromised the PDE’s security.
The reporting deadlines are structured in stages:
- Early warning within 24 hours of becoming aware of an actively exploited vulnerability or a serious security incident.
- Supplementary vulnerability or incident report within 72 hours.
- Final report for vulnerabilities no later than 14 days after a fix is provided. For a severe incident, within one month of the 72-hour report.
Manufacturers must also inform impacted users and, where appropriate, all users about the vulnerability or incident and any measures they can take to mitigate its impact. Where necessary, risk mitigation and corrective measures must also be communicated. It is also worth noting that as with other EU reporting regimes, the clock does not stop at weekends or on public holidays following the general rules on calculating EU time limits.
Where to report, and interaction with NIS2 and GDPR
Notification is to be made through the CRA's Single Reporting Platform (SRP), which ENISA (the EU agency dedicated to enhancing cybersecurity in Europe) is required to establish under Article 16. The platform is not yet live and is expected to become operational on 11 September 2026. The SRP operates on a "report once, share many" basis: a single notification is addressed to the Computer Security Incident Response Team (CSIRT) of the manufacturer's main establishment (identified under Article 14(7)) and, absent exceptional circumstances, made available simultaneously to ENISA, before onward dissemination to the CSIRTs of other Member States where the product is available.
The Article 14 reporting obligations duty may overlap with a manufacturer's obligations under the NIS2 Directive (to the extent applicable) and, where UK/EU personal data is affected, the UK/EU GDPR. The Commission's November 2025 Digital Omnibus proposals envisage a Single-Entry Point for incident reporting, however until these consolidations are enacted, the reporting channels remain distinct, and manufacturers must manage requirements in parallel.
Next steps
Manufacturers may wish to consider taking the following steps:
- Identify CRA-regulated products and assess which supporting back-end systems fall within scope, noting that the Article 14 reporting obligations also apply to products with digital elements placed on the EU market before 11 December 2027.
- Put in place a dedicated procedure for receiving, assessing and escalating information about potential vulnerabilities and incidents.
- Allocate clear internal ownership for determining whether the reporting threshold is met and map the procedures for notification submission through the SRP and communications with affected users as well as the relevant timeframes.
- Note and map the parallel relevant NIS2 and GDPR obligations whilst the EU Digital Omnibus consolidates the reporting channels to avoid inconsistent or late notifications.
- Familiarise relevant parties with the SRP now to avoid potential last-minute stress, establish any necessary EU accounts and monitor further guidance regarding registration and access requirements.