In short: The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies in full only from 11 December 2027. The reporting obligations under Article 14, however, have applied since 11 September 2026, including for products already on the market. Reports go through ENISA's Single Reporting Platform and, for manufacturers based in Germany, to CERT-Bund at the BSI. The first early warning is due within 24 hours.
What the Cyber Resilience Act covers
The CRA is an EU regulation. It applies directly in all Member States without national transposition. It was published in the Official Journal on 20 November 2024 and entered into force on 10 December 2024. It covers products with digital elements: under Article 3(1), software and hardware products including their remote data processing solutions. Examples are an industrial controller with a cloud connection, a router, firmware or standalone software.
The CRA mainly addresses manufacturers: companies that develop or have such products made and place them on the EU market under their own name. Importers and distributors have their own, lighter duties. The regulation applies in stages (Article 71(2)):
- 11 June 2026: Chapter IV, the rules on notified conformity assessment bodies. These are test bodies that assess certain products before market access.
- 11 September 2026: Article 14, the manufacturers' reporting obligations.
- 11 December 2027: all remaining obligations, in particular the cybersecurity requirements for products and CE marking under the CRA.
What must be reported since 11 September 2026
Article 14 defines two triggers:
- Actively exploited vulnerability. A vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). A purely theoretical flaw found in an internal test does not qualify.
- Severe incident affecting the security of the product. Under Article 14(5), an incident is severe if it negatively affects, or is capable of affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or if it has led or is capable of leading to the introduction or execution of malicious code in the product or in the user's network. A compromised update server is a typical example.
Under Article 69(3), the obligation expressly applies to products placed on the market before 11 December 2027. If you have been shipping devices or software for years, you already report for your entire installed base.
The deadlines: 24 hours, 72 hours, 14 days or one month
Deadlines run from the moment the manufacturer becomes aware.
For an actively exploited vulnerability (Article 14(2)):
- Early warning without undue delay, at the latest within 24 hours.
- Notification with general information on the product, the nature of the exploit and measures taken, at the latest within 72 hours.
- Final report no later than 14 days after a corrective or mitigating measure is available.
For a severe incident (Article 14(4)):
- Early warning without undue delay, at the latest within 24 hours.
- Notification at the latest within 72 hours.
- Final report within one month after the 72-hour notification.
Under Article 14(8), the manufacturer also informs the affected users about the vulnerability or incident and, where necessary, about mitigation measures. If it fails to do so in time, the competent CSIRT may inform users itself. A CSIRT (Computer Security Incident Response Team) is a public team that handles security incidents.
Where to report: the Single Reporting Platform
Reports are submitted through the Single Reporting Platform (SRP) under Article 16. ENISA, the EU Agency for Cybersecurity, developed and operates it. According to ENISA, it has been operational since 11 September 2026. Each notification goes simultaneously to ENISA and to the coordinating CSIRT of the Member State where the manufacturer has its main establishment, meaning where cybersecurity decisions are predominantly taken.
For Germany, CERT-Bund at the BSI is the coordinating CSIRT. The BSI points out three practical details: access requires an EU Login account, reports must be written in English, and only if the platform is unavailable should the mandatory report be sent to CERT-Bund by email. Create the EU Login accounts before the first case occurs. Otherwise you lose hours during the incident.
What follows until December 2027
From 11 December 2027, the product requirements apply. The key points:
- Essential cybersecurity requirements under Annex I Part I, such as secure default configuration, protection against unauthorised access and security updates.
- Vulnerability handling under Annex I Part II, including a software bill of materials (SBOM) in a commonly used, machine-readable format. An SBOM lists the software components of a product, at least the top-level dependencies.
- Support period of in principle at least five years during which security updates are provided (Article 13(8)). If the expected period of use is shorter, that period applies.
- Conformity assessment and CE marking. Important products under Annex III are subject to stricter procedures. For critical products under Annex IV, a European cybersecurity certificate can be made mandatory.
Fines are set out in Article 64: up to EUR 15 million or 2.5 percent of worldwide annual turnover for breaches of the essential requirements, Article 13 or Article 14, whichever is higher. The reporting obligation therefore sits in the highest fine tier.
On 27 July 2026, the European Commission published guidance on applying the CRA, covering scope, support period and reporting, among other topics. It does not change the deadlines in the regulation. In Germany, the BSI is set to become the market surveillance authority for the CRA. The federal government presented the draft implementation act on 26 May 2026 (Bundestag printed paper 21/6134).
Checklist for manufacturers of connected products
- Clarify scope. Which of your products are products with digital elements, and are you acting as manufacturer, importer or distributor?
- Build a product inventory. All products and versions on the market, including legacy stock, with an owner per product.
- Set up platform access. EU Login accounts for at least two named people, with deputies defined.
- Define the reporting process. Who decides whether a vulnerability is actively exploited? Who writes the early warning in English? Who approves it? The 24-hour deadline also runs at weekends.
- Ensure detection. Signals from customer support, security researchers, threat intelligence and your own monitoring must reach one place.
- Publish a disclosure policy. A contact point through which third parties can report vulnerabilities (coordinated vulnerability disclosure).
- Prepare user communication. Templates and distribution lists to inform affected customers quickly and in a structured way.
- Introduce SBOMs. Generate and maintain a software bill of materials per product. Without one, the question "are we affected?" after a new library vulnerability is hard to answer quickly.
- Gap analysis against Annex I. Which requirements does your product not meet today, and what must change in development and support by December 2027?
- Run an exercise. A tabletop exercise with a realistic case shows whether the early warning really goes out within 24 hours.
How the CRA relates to NIS 2
The NIS 2 Directive and the German BSI Act require entities to report significant incidents in their own operations. The CRA requires manufacturers to report vulnerabilities and incidents in their products. A company can be subject to both regimes and must then serve both reporting channels. The deadlines are similar, the recipients and contents are not fully the same.
How GermanAI Defense supports you
We run the gap analysis against the CRA, set up the reporting and vulnerability handling process and document it in an audit-ready way. With penetration testing, we check your products for exploitable vulnerabilities before others do. Our 24/7 SOC helps detect signs of active exploitation early, so the 24-hour clock does not start only when a customer calls.
→ More on our GRC and compliance consulting: germanaidefense.com/grc
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex, Articles 3, 13, 14, 16, 64, 69, 71, Annex I
- ENISA: The CRA Single Reporting Platform is launched
- European Commission: CRA reporting obligations
- BSI: Single Reporting Platform CRA
- European Commission: CRA guidance, 27 July 2026
- BSI press release of 7 October 2025 on market surveillance (German)
- Bundestag printed paper 21/6134 (German)
As of 29 September 2026. This article is a professional overview and does not replace legal advice in individual cases.