5. August 2026
Reading Time: 4
Min.
news
From 11 September 2026, manufacturers of software, IoT products and other products with digital elements will become subject to the first obligations introduced by the Cyber Resilience Act (CRA). From that date, they will have 24 hours to submit an early warning and 72 hours to submit a complete notification of an actively exploited vulnerability or a severe incident.
At first glance, meeting these deadlines may appear to be the greatest challenge. In practice, however, the obligations arising under Article 14 of the CRA begin much earlier – at the moment a manufacturer becomes aware of an event that may trigger a reporting obligation. This is the point at which an organisation must be ready to activate the entire process required to fulfil its reporting obligations.
When does the reporting obligation arise?
The reporting obligations stem from Article 14 of Regulation (EU) 2024/2847 of the European Parliament and of the Council (Cyber Resilience Act).
Although most provisions of the CRA will not apply until 11 December 2027, the rules concerning the reporting of actively exploited vulnerabilities, severe incidents and the provision of information to users of products with digital elements will become applicable on 11 September 2026.
Who is subject to the new obligations?
The new requirements apply to manufacturers of products with digital elements, including manufacturers of:
- software (with the exception of non-commercial open-source software),
- computer hardware,
- IoT products, including smart devices,
- industrial automation equipment.
The Regulation does not apply, among others, to medical devices, motor vehicles, aviation products or marine equipment.
What are a manufacturer’s obligations once a vulnerability has been identified?
The process begins when a manufacturer becomes aware of an actively exploited vulnerability* or a severe incident ** affecting a product with digital elements.
From that moment, the obligations set out in Article 14 of the CRA are triggered. Manufacturers are required to report:
- every actively exploited vulnerability affecting a product with digital elements; and
- every severe incident affecting the security of a product with digital elements.
The notification must be submitted both to the relevant CSIRT and to the European Union Agency for Cybersecurity (ENISA).
The Regulation provides for very short deadlines:
- 24 hours – to submit an early warning;
- 72 hours – to submit the complete notification.
A manufacturer’s obligations do not end once the notification has been submitted. The Cyber Resilience Act also requires manufacturers to inform all users of products with digital elements affected by a severe incident. Where appropriate, this obligation also extends to informing users about an actively exploited vulnerability.
Where necessary, manufacturers should also provide information on mitigation measures and corrective actions that users can implement to reduce the impact of the vulnerability or incident.
Once a corrective or mitigation measure has been made available, manufacturers are also required to submit:
- a final report within 14 days in the case of an actively exploited vulnerability; and
- a final report within one month of reporting a severe incident.
What does the 24-hour deadline mean in practice?
Although the first obligations introduced by the Cyber Resilience Act formally concern the reporting of vulnerabilities and incidents, in practice they require manufacturers to establish a comprehensive product cybersecurity management process.
The 24-hour and 72-hour deadlines are merely the final stage of the manufacturer’s obligations. Since the Regulation requires an actively exploited vulnerability or severe incident to be reported promptly after the manufacturer becomes aware of it, organisations must already have appropriate procedures in place to enable them to complete this process.
In practice, this means:
- establishing a vulnerability reporting mechanism and defining the information required to assess reported vulnerabilities;
- implementing a process for verifying and assessing reports based on their impact on the security of the product and its users, including the practical exploitability of the vulnerability;
- preparing security patches or temporary mitigation measures to reduce the associated risks;
- implementing a reporting process for notifications to the competent CSIRT and ENISA; and
- establishing a communication process for users of products with digital elements.
Only a process of this kind will enable manufacturers to comply with the reporting obligations within the deadlines laid down in the CRA.
Manufacturers of software, computer hardware, IoT products and other products with digital elements should therefore not wait until 2027. They should already assess whether their organisations have the necessary procedures in place to receive and evaluate reports, notify the competent authorities and communicate effectively with users.
In practice, compliance with the 24-hour and 72-hour deadlines will only be possible if every element of this process is operational before Article 14 of the CRA becomes applicable.
Sanctions
Failure to comply with the obligations set out in Article 14 of the Cyber Resilience Act may result in an administrative fine of up to EUR 15 million or 2.5% of the undertaking’s total worldwide annual turnover, whichever is higher.
However, the provisions governing administrative fines will not apply until 11 December 2027, together with the remainder of the Regulation.
This does not mean that the obligations applicable from 11 September 2026 can be postponed. Although administrative fines will not yet be available, failure to implement appropriate procedures will still constitute a breach of the applicable regulatory requirements. This may have significant implications from an audit and corporate governance perspective and may also lead to infringements of consumer protection rules and personal data protection legislation.
* Actively exploited vulnerability – a weakness, susceptibility or flaw in a product with digital elements that can be exploited in the context of a cyber threat and for which there is reliable evidence that it has been exploited by a malicious actor without the authorisation of the system owner.
** Severe incident – an incident that affects or is capable of affecting the ability of a product with digital elements to ensure the availability, authenticity, integrity or confidentiality of data or product functions, or that results in or is capable of resulting in the introduction or execution of malicious code within the product or within the user’s networks and information systems.
Grzegorz Antonowicz
Partner