If your company has been treating the EU Cyber Resilience Act as a “2027 problem,” the
calendar says otherwise. The CRA’s vulnerability and incident reporting obligations under
Article 14 are already applicable from
11 September 2026. The remaining
requirements, including essential cybersecurity requirements and CE marking, apply from
11 December 2027.
If you build software, firmware, connected devices, or digital components that are available
on the EU market, the reporting clock is already running. The key deadlines are an
early warning within 24 hours, a fuller notification within
72 hours, and a final report within
14 days for actively
exploited vulnerabilities.
At Aspect, we put it simply: compliance is the lock, and security is the key. You need both.
01. The CRA is not one deadline—it is phased
The Cyber Resilience Act is being introduced in stages. The reporting obligation arrived well
before the majority of the Act becomes applicable.
| Date |
What it means for you |
| 10 December 2024 |
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, enters into force.
|
| 11 June 2026 |
Rules concerning conformity assessment bodies begin to apply.
|
| 11 September 2026 |
Article 14 reporting obligations become applicable. Manufacturers must
report actively exploited vulnerabilities and severe incidents affecting product security.
|
| 11 December 2027 |
The remaining CRA obligations become applicable, including essential cybersecurity
requirements and CE marking.
|
A word of caution: December 2027 is not the first CRA deadline. If your
product is already available on the EU market, your vulnerability and incident reporting
process should already be operational.
02. Who must report under the CRA?
The reporting duty primarily sits with the
manufacturer—an organisation
that develops or manufactures a product with digital elements, or has one made, and markets
it under its own name or trademark.
In practice, this can include:
- Software vendors selling on-premise, desktop, mobile, or embedded software in the EU.
- Hardware and IoT manufacturers, including consumer smart devices and industrial equipment.
- Component vendors when a component is placed on the EU market independently.
- Importers and distributors that sell a product under their own brand or substantially modify it.
- Non-EU companies whose products with digital elements are available on the EU market.
The location of your headquarters does not automatically remove the obligation. For Indian
companies exporting software, firmware, IoT products, or other digital products to Europe,
the CRA can therefore become directly relevant.
Is SaaS covered?
Pure software-as-a-service is generally outside the CRA where it falls under other EU
cybersecurity regimes. However, cloud functionality that is essential to the core function
of an installed product can potentially fall within scope.
SaaS and cloud providers should therefore assess their products on a case-by-case basis
rather than assuming that every cloud service is automatically exempt.
03. What actually triggers a CRA report?
Not every vulnerability or security update is automatically reportable. Article 14 focuses
on two specific situations:
-
Actively exploited vulnerability: there is reliable evidence that a
malicious actor has exploited a vulnerability in the product.
-
Severe incident: a cybersecurity incident affects the development,
production, or maintenance processes of a product in a way that could increase risk for
users.
A vulnerability discovered during internal testing or security research does not by itself
trigger mandatory reporting if there is no evidence that it is being maliciously exploited.
The European Commission has also clarified that third-party component vulnerabilities can
require reporting where the vulnerability is exploitable and has been exploited in the
manufacturer’s own product.
Affected users must also be informed where required. In certain circumstances, the relevant
national CSIRT may communicate with affected users directly.
04. The CRA reporting clock: 24 hours, 72 hours, 14 days
The biggest operational change for affected manufacturers is the speed at which they must
respond after becoming aware of a qualifying event.
| Stage |
Actively Exploited Vulnerability |
Severe Incident |
| Early warning |
Within 24 hours of becoming aware.
|
Within 24 hours, including whether malicious or unlawful activity is suspected.
|
| Notification |
Within 72 hours, including product details, the nature of the exploit,
and corrective or mitigating measures.
|
Within 72 hours, including product details, the nature of the incident,
initial assessment, and mitigations.
|
| Final report |
Within 14 days after a fix or mitigation becomes available.
|
Within one month of the notification.
|
The 24-hour clock starts when the manufacturer becomes aware of the qualifying event after
an initial assessment provides a reasonable degree of certainty that the product is being
exploited or its security has been compromised.
This makes fast detection, triage, escalation, and incident ownership critical.
05. Where do CRA reports go?
CRA reports are submitted through ENISA’s
CRA Single Reporting Platform (SRP).
The platform routes the report to the relevant CSIRT coordinator and other appropriate
member-state authorities.
This means manufacturers should not rely on simply emailing a national CSIRT as a substitute
for the required reporting process.
Your organisation should have:
- A designated person responsible for CRA reporting.
- A backup person who can submit reports when the primary contact is unavailable.
- EU Login access with appropriate authentication.
- Accurate legal entity and product information.
- A documented escalation process for incidents discovered outside business hours.
06. CRA reporting and other cyber regulations
One cybersecurity incident can potentially trigger obligations under multiple regulatory
frameworks.
For an Indian company selling products or services into Europe, the same event may involve
CRA reporting alongside CERT-In, GDPR, NIS2, or India’s DPDP requirements.
A CRA notification does not automatically satisfy the obligations of these other regimes.
| Regime |
Who it applies to |
First deadline |
| CERT-In Directions |
Organisations operating in India for specified cyber incidents |
6 hours |
| EU Cyber Resilience Act |
Manufacturers of products with digital elements on the EU market |
24 hours |
| NIS2 Directive |
Essential and important entities in the EU |
24 hours |
| GDPR |
Controllers processing EU personal data |
72 hours |
| DPDP Act and Rules |
Data fiduciaries processing digital personal data in India |
Without delay / detailed report within 72 hours |
The practical approach is to maintain one integrated incident response playbook that
identifies every regulatory obligation when an incident is detected.
07. What are the penalties for missing a CRA report?
The CRA uses a three-tier fine structure. Breaches involving essential requirements and core
manufacturer obligations, including Article 14 reporting, sit within the highest tier.
| Type of breach |
Maximum fine |
| Essential requirements and core manufacturer obligations |
€15 million or 2.5% of worldwide annual turnover, whichever is higher.
|
| Other obligations, including certain importer and distributor duties |
€10 million or 2% of worldwide annual turnover.
|
| Incorrect, incomplete, or misleading information |
€5 million or 1% of worldwide annual turnover.
|
Market surveillance authorities can also require documentation, demand corrective action,
or order products to be withdrawn or recalled from the EU market.
08. Your 7-step CRA reporting readiness plan
Step 1: Inventory your products
- List every product with digital elements available in the EU.
- Include legacy products and supported versions.
- Document third-party components and dependencies.
- Identify products that are white-labelled or sold under another company’s brand.
Step 2: Confirm who the manufacturer is
- Identify the legal entity responsible for each product.
- Review arrangements involving IP owners, development companies, distributors, and white-label partners.
- Document which organisation holds the manufacturer role.
Step 3: Identify your CSIRT coordinator
- Determine the relevant EU establishment and CSIRT coordination route.
- If you have no EU establishment, map the applicable route through your authorised representative, importer, or relevant EU presence.
Step 4: Prepare access to the Single Reporting Platform
- Set up the necessary EU Login accounts.
- Use multi-factor authentication.
- Assign a primary and backup reporting representative.
- Standardise legal entity and product information.
Step 5: Define your incident triage process
- Define what constitutes active exploitation.
- Define what constitutes a severe incident.
- Identify who makes the reporting decision.
- Create an escalation path for incidents discovered outside working hours.
- Ensure the organisation can act within the 24-hour reporting window.
Step 6: Pre-draft your notifications
- Create an early-warning template.
- Prepare the 72-hour notification template.
- Prepare final-report documentation.
- Create customer advisory templates.
Step 7: Map and rehearse your regulatory obligations
- Map CRA requirements against CERT-In, GDPR, NIS2, and DPDP obligations.
- Run a tabletop incident-response exercise.
- Test the process from initial detection through regulatory filing.
09. Common CRA reporting mistakes
- Treating December 2027 as the first CRA deadline.
- Assuming all SaaS and cloud components are automatically outside the CRA.
- Emailing a national CSIRT instead of using the Single Reporting Platform.
- Forgetting white-label and OEM products.
- Leaving reporting access with only one employee.
- Failing to maintain a 24/7 escalation process.
- Not rehearsing the reporting process before an actual incident occurs.
10. How Aspect Tech Knowledge IES can help
At Aspect Tech Knowledge IES, we believe
compliance is the lock and security is the
key.
Our team helps product companies translate regulations such as the Cyber Resilience Act
into practical and repeatable security processes—from product scoping and CSIRT mapping to
incident-response playbooks aligned with CERT-In, GDPR, NIS2, and DPDP requirements.
If you want to understand whether your products fall within the CRA and whether your team
could meet a 24-hour reporting deadline, speak with our team about a
CRA reporting readiness review.
Talk to us at
connect@aspect-tech-knowledge-ies.com
.
11. Frequently asked questions
When did the Cyber Resilience Act reporting obligations start?
The CRA reporting obligations under Article 14 started on
11 September 2026. Most other CRA requirements, including essential
cybersecurity requirements and CE marking, apply from
11 December 2027.
What is the 24-hour rule under the CRA?
Manufacturers must submit an early warning within
24 hours of becoming
aware of an actively exploited vulnerability or a severe incident affecting their product.
A fuller notification follows within 72 hours.
Does the CRA apply to companies outside the EU?
Yes. The CRA applies to manufacturers whose products with digital elements are available on
the EU market, regardless of where the company is headquartered. This can include Indian,
US, and other non-EU manufacturers.
Where are CRA reports submitted?
Reports are submitted through ENISA’s
CRA Single Reporting Platform,
which routes the information to the relevant CSIRT coordinator.
Do products sold before September 2026 need to be considered?
Yes. The reporting obligations apply to in-scope products already available on the EU
market, including products placed on the market before 11 September 2026.
What is the maximum CRA penalty?
For breaches involving essential requirements and core manufacturer obligations, fines can
reach
€15 million or 2.5% of worldwide annual turnover, whichever is higher.
What happens if a company misses a CRA reporting deadline?
In addition to financial penalties, market surveillance authorities can require corrective
action and may order products to be withdrawn or recalled from the EU market.
12. Start preparing before the 24-hour clock starts
The organisations that can respond calmly to CRA reporting obligations are the ones that
prepare before an incident occurs.
Product inventories, incident ownership, vulnerability monitoring, reporting access,
pre-drafted notifications, and rehearsed response procedures all take time to establish.
The 24-hour reporting window is too short to build the process after an incident has already
been detected.
Aspect Tech Knowledge IES helps organisations understand their CRA exposure and build the
security and incident-response foundation needed to respond quickly.
Talk to us at
connect@aspect-tech-knowledge-ies.com
.
Deeper Understanding. Better Solutions.
Sources
This article is for general information and is not legal advice. Please confirm your
specific obligations with qualified advisers.