Grandfathering stops at reporting
Everyone knows 11 December 2027 for the Cyber Resilience Act. The date that matters is 11 September 2026: that is the day the manufacturers' reporting obligations begin. And unlike the rest of the regulation, they come with no grandfathering.
Whenever the Cyber Resilience Act comes up, one date is named: 11 December 2027. That is when the regulation applies in full, and when a product with digital elements needs CE marking for cybersecurity.
The date that matters now is a different one. On 11 September 2026 the reporting obligations under Article 14 begin. Fifteen months ahead of everything else.
Two triggers
Two things must be reported. First, any actively exploited vulnerability in your own product. Second, any severe incident having an impact on the security of the product.
What counts as severe is defined in Article 14(5), and the definition is broader than it first appears: an incident is severe if it negatively affects the product's ability to protect availability, authenticity, integrity or confidentiality, or if it leads or is capable of leading to the introduction of malicious code.
Capable of leading. Damage having occurred is not a precondition.
Three stages, two different clocks
Reporting runs in three stages: early warning within 24 hours of the manufacturer becoming aware, full notification within 72 hours, then the final report (paragraphs 2 and 4).
At the final report the two cases part ways, and this is where deadlines get missed. For a vulnerability it is no later than 14 days after a corrective measure is available. For an incident, one month after the full notification.
So the 14 days do not run from awareness but from the patch. Count them from awareness and you report too early and incompletely; apply the one-month deadline to a vulnerability and you report too late.
The addressee is the CSIRT of the member state of the main establishment, and the same information goes to ENISA simultaneously: one platform, one submission. There is also an obligation that tends to get lost in the discussion. Under paragraph 8, the impacted users of the product must be informed about the vulnerability or incident and, where necessary, about corrective and mitigating measures. Reporting to the authority does not cover that.
And now the part that gets missed
Article 69(2) contains the transitional rule many are relying on:
"Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements of this Regulation only if, from that date, those products are subject to substantial modifications."
Anyone concluding from this that the installed base is out of scope stopped reading one paragraph too early. Paragraph 3 carves Article 14 back out of that exemption: the reporting obligations apply to all products with digital elements, regardless of when they were placed on the market.
In plain terms: the version shipped in 2019 and never touched since needs no CE marking for cybersecurity. If a vulnerability in it is actively exploited, the 24-hour clock runs all the same.
Who it hits, and what still fits into today
Article 14 binds manufacturers, not operators. That lets most people relax too early: a manufacturer is whoever places a product with digital elements on the market under their own name, without necessarily seeing themselves as a software house. Those who only purchase do not have the obligation, but they have the other side of it: for suppliers, what used to be voluntary communication is now a deadline with an authority at the other end.
Twenty-four hours is not organised while it runs. Three things should be settled before the first event: who decides whether a vulnerability is actively exploited. Who files the report, with access to the platform rather than responsibility on paper. And which event starts the clock, because it starts with awareness, not with confirmation.
The deadlines and legal references for this and the coming dates are in the compliance calendar. How we keep the product file, the vulnerability report and the user notification in the module is described on the Cyber Resilience Act module page.
Sources
Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14 and 69. On the application date and the single reporting platform, the European Commission's own account: CRA reporting obligations.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.