The Cyber Resilience Act: Notification Obligations Become Applicable Today
Authors
The Regulatory Framework
Regulation (EU) 2024/2847 — known as the Cyber Resilience Act (“CRA”) — was adopted by the European Parliament and the Council on 23 October 2024 and introduces, for the first time, horizontal cybersecurity requirements for all products with digital elements placed on the European Union market.
The stated objective of the CRA is twofold: on the one hand, to reduce vulnerabilities in hardware and software products by ensuring that manufacturers give serious consideration to security throughout the entire product lifecycle; on the other, to improve transparency for users, for instance by providing clear information on the support period. The Regulation applies to all products with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. The notion of “product with digital elements,” as defined in Art. 3(1) of the CRA, is intentionally broad: it encompasses any software or hardware product and its related remote data processing solutions, including software or hardware components placed on the market separately. “Remote data processing” means any data processing at a distance for which the software has been designed and developed by the manufacturer or under its responsibility and without which the product would be unable to perform one of its functions — this includes, by way of example, cloud-enabled functionalities designed by the manufacturer itself, but excludes generic cloud services whose design falls outside the manufacturer’s responsibility. The scope of the Regulation therefore encompasses an extremely heterogeneous range of products: from IoT devices to operating systems, from routers and firewalls to consumer products such as connected toys, smart locks, baby monitoring systems and personal wearable health technologies.
The CRA is conceived as a “horizontal” regulation, filling a gap in the European legislative framework: prior to its adoption, no EU legislation established comprehensive and mandatory cybersecurity requirements for the entire range of products with digital elements. The Regulation also coordinates with the NIS 2 Directive and with medical device legislation, creating an integrated regulatory system.
Although the CRA has already entered into force, its substantive application is staggered across two distinct points in time. The first — effective as of today, 11 September 2026 — concerns the notification obligations under Art. 14. The remaining provisions will apply from 11 December 2027.
It should further be noted that, without prejudice to the provisions of Art. 14 — which also apply to products with digital elements placed on the market prior to 11 December 2027 — the remaining requirements under the Regulation apply exclusively to products placed on the market after that date, with the sole exception of products placed on the market beforehand that undergo substantial modifications within the meaning of Art. 69 of the Regulation.
The Notification Obligation — Art. 14
As of 11 September 2026, manufacturers of products with digital elements are required to simultaneously notify the CSIRT designated as coordinator and ENISA of the following:
- Actively exploited vulnerabilities: under the CRA, this refers to a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the authorisation of the system owner. Vulnerabilities identified and remediated by the manufacturer before any exploitation has occurred fall outside the notification obligation and remain subject to the ordinary vulnerability management process.
- Serious incidents: an incident is deemed serious within the meaning of Art. 14(5) of the CRA where it: (i) adversely affects, or is capable of adversely affecting, the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (ii) has led, or is capable of leading, to the introduction or execution of malicious code in the product or in the information and network systems of a user of the product.
The notification procedure is structured in three progressive phases, subject to mandatory deadlines running from the moment the manufacturer becomes aware of the event:
- Early warning — within 24 hours of becoming aware: the manufacturer submits an initial notification of the event, indicating, where applicable, the Member States in which the product has been made available and, in the case of incidents, whether the incident is suspected to result from unlawful or malicious acts.
- Full notification (vulnerability/incident notification) — within 72 hours of becoming aware: the manufacturer provides general information on the nature of the vulnerability or incident, an initial assessment, the corrective or mitigating measures already adopted, as well as the measures that users may in turn adopt, together with the degree of sensitivity attributed to the notified information.
- Final report — within 14 days of the availability of a corrective or mitigating measure for vulnerabilities, or within 1 month of the 72-hour notification for serious incidents: the manufacturer provides a comprehensive description of the vulnerability or incident, including severity, impact, detailed information on the security update, and, where available, information concerning the malicious actor.
It should be emphasised that the notification obligation is not retroactive: vulnerabilities whose active exploitation was already known to the manufacturer prior to 11 September 2026 are not subject to the reporting requirement.
Notifications are transmitted through the single reporting platform established by ENISA pursuant to Art. 16 of the CRA. The competent CSIRT is determined on the basis of the manufacturer’s main establishment in the EU, understood as the Member State in which the decisions relating to the cybersecurity of its products are predominantly taken.
ENISA FAQs and the Single Reporting Platform
Ahead of the entry into application of the notification obligations, ENISA has published a series of guidance materials — including the FAQs on the Single Reporting Platform (updated on 9 September 2026), the SRP Glossary and several operational guides — providing practical guidance on the use of the single reporting platform.
The platform, accessible at portal.cra-srp.enisa.europa.eu, requires authentication via an EU Login account with multi-factor authentication (MFA), which can be created in advance on the ecas.ec.europa.eu portal. Each manufacturer is required to designate a primary representative (AR Primary) and may appoint up to 20 secondary representatives (AR Secondary), who are equally authorised to submit and update notifications, albeit without the same administrative permissions as the primary representative. The association between the designated representative and the manufacturer is subject to validation by the competent CSIRT; however, this procedure runs in parallel with the reporting process and does not constitute a prerequisite for the submission of notifications, it being understood that a representative not yet validated may submit a maximum of 20 notifications before verification becomes mandatory.
It is also worth noting that the countdown timers displayed on the platform serve an exclusively informational function and in no way replace the legal deadlines set out in Art. 14: in the initial version of the platform, the 72-hour timer calculates the deadline as 48 hours from the submission of the early warning, rather than 72 hours from the moment of becoming aware, with the consequence that a notification may be erroneously flagged as overdue. Manufacturers are therefore recommended to independently document the exact time at which they became aware of the event, retaining a record in their incident log as the sole evidentiary element that may be relied upon in the event of a challenge. Finally, it should be noted that at launch the platform accepts exclusively mandatory notifications pursuant to Arts. 14 and 24 of the CRA; the voluntary reporting functionality provided for under Art. 15 will be introduced at a later stage, the timing of which is currently undefined.