Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

EU Cyber Resilience Act Reporting Requirements Take Effect

EU Cyber Resilience Act Reporting Requirements Take Effect

By
Key Takeaways
  • Reporting Rules Take Effect: Manufacturers must now report actively exploited vulnerabilities and severe security incidents affecting products with digital elements made available in the EU.
  • The First Deadline Is 24 Hours: Manufacturers must submit an early warning within 24 hours, followed by a full notification within 72 hours.
  • Final Reports Follow Different Timelines: Final reports are due within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, and within one month for a severe incident.
  • Existing Products Are Covered: The reporting obligations apply to all products with digital elements made available in the EU, including those already on the market.
Deep Dive

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.

The reporting timetable is deliberately short. Manufacturers must submit an early warning within 24 hours, followed by a full notification within 72 hours. What happens next depends on what triggered the report. For an actively exploited vulnerability, a final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, manufacturers have one month to submit the final report.

The rules are meant to shorten the distance between discovering that something has gone wrong and doing something about it. For consumers, the European Commission argues, that should mean faster notifications and stronger protection when connected products are caught up in a cyberattack. A compromised door-locking system is one example the Commission gives. The principle extends much further.

Existing Products Are Included

The September 11 deadline is easy to confuse with the CRA’s broader compliance timetable. Most of the Act’s main obligations will not apply until December 11, 2027. The reporting requirements have arrived 15 months earlier. Their reach is not confined to products introduced after that date. According to the Commission, the reporting obligations apply to all products with digital elements made available in the EU, including those already on the market.

That leaves manufacturers with an immediate compliance responsibility even while much of the wider CRA remains ahead of them. Companies may still have time to prepare products and processes for the requirements coming in 2027. They do not have that same luxury when an actively exploited vulnerability or severe security incident occurs today. The first reporting deadline is measured in hours.

Notifications will be submitted through the CRA Single Reporting Platform, which has been established and is maintained by the European Union Agency for Cybersecurity, or ENISA.

The Commission has also published practical guidance intended to help manufacturers, developers and businesses meet their obligations. Enforcement will fall to national market surveillance authorities.

A Broader Product Security Regime Is Still Coming

The reporting regime is only the first substantial piece of a much larger change in how the EU regulates the cybersecurity of digital products. The CRA is intended to strengthen cybersecurity requirements for products with digital elements throughout their lifecycle. Under the broader rules, products will have to be designed, updated and maintained in ways that protect users from security risks. CE marking will provide consumers and businesses with a way to identify products that comply with CRA requirements.

Those obligations take effect December 11, 2027. The Act itself sits within the EU’s broader cybersecurity and security strategies, but its importance for manufacturers is more concrete than the policy language might suggest. Cybersecurity is being attached directly to the obligations that follow a product onto the European market, including what manufacturers must do when vulnerabilities are discovered after that product is already in use.

September 11 is where that framework begins to acquire operational consequences. Manufacturers now need reporting processes capable of moving from awareness to an initial regulatory notification within 24 hours, and then to the more detailed notification required a day later.

The rest of the CRA still gives companies time to prepare. Its reporting clock is already running.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong