← Back to Blog
Cyber Resilience ActCRARegulation 2024/2847Incident ReportingArticle 14ComplianceDACH

If You Ship Digital Products, CRA Reporting Starts on 11 September 2026

Article 14 of the Cyber Resilience Act applies from 11 September 2026 — including to in-scope products placed on the Union market before 11 December 2027.

DS
Dr. Sait Yalazay, PhD / LLM / MBA
CISO — DPO — Author | CISM — CIPP — AAISM — LA 27001, 27701, 22301, 42001
Architect of Automated Compliance Systems for NIS2, GDPR, ISMS, BCM, DORA, Cloud Security (C5), Tisax & AI Act

Published on August 29, 2026

11 September 2026 is not a 2027 problem

Only days remain until the Cyber Resilience Act’s first manufacturer-facing reporting obligations begin to apply on 11 September 2026 — and they reach back to products placed on the Union market before 11 December 2027.

Most software firms have one date written down for the Cyber Resilience Act: 11 December 2027. That is when Regulation (EU) 2024/2847 applies generally. The main product-compliance requirements — CE marking, technical documentation, conformity assessment and the essential requirements — apply from then.

For one article that is wrong. And that one article reaches into the past.

What starts on 11 September

Article 71(2) says it in a sentence: the Regulation applies from 11 December 2027; however, Article 14 applies from 11 September 2026 and Chapter IV (Articles 35 to 51) from 11 June 2026.1

Article 14 is the manufacturer’s reporting duty. Two events must be reported, simultaneously to the CSIRT designated as coordinator and to ENISA.

The actively exploited vulnerability. Narrowly defined: a vulnerability “for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner” (Art. 3, point 42).2 A bare scanner alert, without reliable evidence of unauthorised exploitation, is not enough — though scan or log data can certainly evidence exploitation. A pentest under contract is not that.

The severe incident having an impact on the security of the product. Severe where it negatively affects — or is capable of negatively affecting — the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or where it has led or is capable of leading to the introduction or execution of malicious code (Art. 14(5)).3 The words “capable of” carry the clause: a manufacturer who waits for realised harm has misread it.

The deadline reads without undue delay and in any event within 24 hours for the early warning. Twenty-four hours is the ceiling, not the budget. Then the notification within 72 hours, then the final report — within 14 days of a corrective or mitigating measure becoming available, or, for a severe incident, within one month of the 72-hour notification.4

The paragraph almost nobody has read

Article 69(2) supports the comfortable reading at first: products placed on the market before 11 December 2027 are subject to the Regulation’s requirements only if, from that date, they undergo a substantial modification.5 That is the legacy shield, and it is real.

Then comes paragraph 3. By way of derogation from paragraph 2, the obligations laid down in Article 14 apply to all in-scope products with digital elements placed on the market before 11 December 2027.6

The shield has exactly one hole, and it is the shape of the reporting duty.

The Commission’s draft guidance goes one step further at point 210: unlike the vulnerability-handling obligations, which continue only for the length of a product’s support period, the reporting obligations continue to apply after a product is no longer supported.7 A product placed on the Union market in 2019 whose support you ended in 2023 is not outside this.

What that does not mean

Precision is worth something here, because a good deal of imprecision will be written in the coming weeks.

The 24 hours do not run because a product is old or contains a vulnerability. They run from the moment the manufacturer becomes aware — and the draft guidance describes that moment as the point at which, after assessing a suspicious event immediately, the manufacturer has a reasonable degree of certainty that a vulnerability contained in its product is being actively exploited, or that a severe incident has occurred and has compromised the product’s security (point 213).8

Nor does Article 14 require retroactive reporting: active exploitation of which the manufacturer had already become aware before 11 September 2026 does not have to be reported (point 217).9 That says nothing about duties under other law.

Both statements sit in guidance the Commission published on 27 July 2026 and itself calls non-binding. Read its covering Communication before leaning on it: the annexed guidance “will be formally adopted by the Commission at a later date, when all language versions are available. It is only from that moment that it will apply.10” As an interpretive aid it is the best thing currently available; check whether that adoption has happened before you rely on it.

What about the fines?

Article 64 sits in Chapter VII. Chapter VII is not among the parts Article 71(2) brings forward; it applies from 11 December 2027. So does the CRA’s own market-surveillance chapter.11

That is narrower than it sounds. It is not immunity: contractual consequences, product liability12, national law and sector-specific duties are untouched, and market surveillance under Regulation (EU) 2019/1020 does not disappear.13 It means only this — a missed Article 14 deadline in that period is not yet subject to the administrative-fine regime of Article 64.

One detail is worth particular attention for small software firms. Corrigendum 2025/90555 replaced “paragraphs 3 to 9” with “paragraphs 2 to 9” in Article 64(10).14 Only through that change does the exemption reach the paragraph under which Article 14 breaches are fined — paragraph 2. The consequence: microenterprises and small enterprises are outside the CRA’s administrative fines in so far as they miss only the early-warning deadline of Art. 14(2)(a) or 14(4)(a). The 72-hour notification and the final report are not covered.15

What should be standing before 11 September

Competence and access. The notification goes to the CSIRT of the Member State of the manufacturer’s main establishment in the Union (Art. 14(7)); without a main establishment, a cascade applies.16 ENISA states that the Single Reporting Platform will be used for mandatory reporting as of 11 September 2026.17 Create the accounts, name the deputies, rehearse the flow once — not on a Friday evening.

A named person and an out-of-hours path. “Without undue delay” does not know about weekends.

A defined assessment procedure. Who assesses a suspicious event, how quickly, and against what is reasonable certainty measured? That decision does not start the deadline — awareness does — but without it, valuable time is lost while the team works out whether the threshold has been met at all.

One duty runs alongside and is easy to miss: under Article 14(8) the manufacturer must inform the impacted users, and where appropriate all users, of the vulnerability or incident and of the measures they can deploy themselves.18

One caveat to close on

ENISA notes that the platform could also be used for voluntary reporting from 11 September.19 Article 15, which governs voluntary reporting, was not brought forward by Article 71(2). Anyone reporting voluntarily in 2026 should therefore not assume that the protection in Article 15(5) is already in force.20


The date most people have circled is 11 December 2027.

The date that belongs on the wall is 11 September 2026 — because it is the only one that reaches backwards.


Glossary of abbreviations

All abbreviations are spelled out in the text on first use. The following overview is provided for quick orientation.

AbbreviationMeaning
CRACyber Resilience Act (Regulation (EU) 2024/2847)
CSIRTComputer Security Incident Response Team
ENISAEuropean Union Agency for Cybersecurity
EUEuropean Union
OJOfficial Journal of the European Union
PLDProduct Liability Directive (Directive (EU) 2024/2853)
RDGRechtsdienstleistungsgesetz (German Legal Services Act)
SRPSingle Reporting Platform (CRA)

Bibliography

Sources are organised below by category. Full citations including access dates are provided in the footnotes. This article is built on primary text only: the Official Journal version of the Regulation, its two corrigenda, and the Commission’s and ENISA’s own documents. No secondary commentary was relied on for any statement of obligation.

Primary sources: legislation and official EU documents

Regulation (EU) 2024/2847 (Cyber Resilience Act): horizontal cybersecurity requirements for products with digital elements — Articles 3, 14, 15, 64, 69 and 71 https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng

Corrigendum, OJ L 2025/90555: Article 64(10), chapeau — “paragraphs 3 to 9” corrected to “paragraphs 2 to 9” https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2025-07-02/oj/eng

Corrigendum, OJ L 2024/90780: citation form in the title; no operative provision affected https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2024-12-05/oj/eng

Regulation (EU) 2019/1020: market surveillance and compliance of products https://eur-lex.europa.eu/eli/reg/2019/1020/oj/eng

Directive (EU) 2024/2853: liability for defective products; software treated as a product, applicable from 9 December 2026 https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng

Official guidance

European Commission: Communication C(2026) 5252 of 27 July 2026 and its annexed guidance on the application of the CRA — non-binding, and applicable only from formal adoption https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation

European Commission: Cyber Resilience Act — reporting obligations https://digital-strategy.ec.europa.eu/en/policies/cra-reporting

ENISA: CRA Single Reporting Platform — factsheet and platform guidance https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp

Legal notice: This article serves general information purposes and does not constitute legal advice within the meaning of the German Legal Services Act (Rechtsdienstleistungsgesetz, RDG). Whether and how Article 14 applies to a specific product and manufacturer should be determined on the individual circumstances, where appropriate with qualified legal counsel. As of: August 2026.

  1. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Art. 71(2). Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  2. Regulation (EU) 2024/2847, Art. 3, point (42) — definition of “actively exploited vulnerability”. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  3. Regulation (EU) 2024/2847, Art. 14(5) — the two limbs of a severe incident having an impact on the security of the product. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  4. Regulation (EU) 2024/2847, Art. 14(2), (3) and (4) — early warning, notification and final report, with the separate final-report clocks for the two tracks. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  5. Regulation (EU) 2024/2847, Art. 69(2) — products placed on the market before 11 December 2027 and the substantial-modification condition. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  6. Regulation (EU) 2024/2847, Art. 69(3) — derogation from Art. 69(2) for the obligations laid down in Art. 14. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  7. European Commission, Communication C(2026) 5252 of 27 July 2026, Annex — guidance on the application of Regulation (EU) 2024/2847, point 210. Non-binding. Available at: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (accessed August 2026). ↩

  8. C(2026) 5252, Annex, point 213 — the moment of becoming aware and the reasonable-degree-of-certainty standard. Non-binding. Available at: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (accessed August 2026). ↩

  9. C(2026) 5252, Annex, point 217 — no obligation to report active exploitation of which the manufacturer became aware before 11 September 2026. Non-binding. Available at: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (accessed August 2026). ↩

  10. European Commission, Communication C(2026) 5252 of 27 July 2026 (covering Communication to the annexed guidance): the guidance “will be formally adopted by the Commission at a later date, when all language versions are available. It is only from that moment that it will apply.” Formal adoption was still outstanding at the time of writing. Available at: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (accessed August 2026). ↩

  11. Regulation (EU) 2024/2847, Art. 64 (Chapter VII) read with Art. 71(2), which brings forward only Art. 14 and Chapter IV. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  12. Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products, which treats software as a product and applies from 9 December 2026. Available at: https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng (accessed August 2026). ↩

  13. Regulation (EU) 2019/1020 of 20 June 2019 on market surveillance and compliance of products. Available at: https://eur-lex.europa.eu/eli/reg/2019/1020/oj/eng (accessed August 2026). ↩

  14. Corrigendum to Regulation (EU) 2024/2847, OJ L, 2025/90555 of 2 July 2025, replacing “paragraphs 3 to 9” with “paragraphs 2 to 9” in the chapeau of Art. 64(10). Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2025-07-02/oj/eng (accessed August 2026). A second corrigendum, OJ L, 2024/90780 of 5 December 2024, corrects the citation form in the title and affects no operative provision: https://eur-lex.europa.eu/eli/reg/2024/2847/corrigendum/2024-12-05/oj/eng. ↩

  15. Regulation (EU) 2024/2847, Art. 64(10)(a) as corrected — the exemption is confined to the early-warning deadlines of Art. 14(2)(a) and 14(4)(a). Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  16. Regulation (EU) 2024/2847, Art. 14(7) — the CSIRT of the Member State of main establishment, and the cascade where there is none. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  17. ENISA, CRA Single Reporting Platform Factsheet v1.0 — how to report incidents and actively exploited vulnerabilities via the SRP. Available at: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp (accessed August 2026). See also European Commission, Cyber Resilience Act — reporting obligations: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting. ↩

  18. Regulation (EU) 2024/2847, Art. 14(8) — information to impacted users and, where appropriate, all users. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩

  19. ENISA, CRA Single Reporting Platform — platform pages and guidance, including its statement on voluntary use. ENISA marks its platform guidance as subject to change. Available at: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp (accessed August 2026). ↩

  20. Regulation (EU) 2024/2847, Art. 15 read with Art. 71(2): voluntary reporting and the protection in Art. 15(5) were not brought forward and apply from 11 December 2027. Available at: https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng (accessed August 2026). ↩