Back

Cyber Resilience Act Sets New Reporting Rules for Manufacturers

At a glance

  • The Cyber Resilience Act entered into force on 10 December 2024.
  • Reporting obligations for manufacturers begin on 11 September 2026.
  • ENISA manages the CRA Single Reporting Platform for incident submissions.

The Cyber Resilience Act (CRA) introduces mandatory reporting procedures for manufacturers of products with digital elements, with requirements taking effect in September 2026. These measures are designed to support coordinated response efforts for cybersecurity incidents in the European Union.

Manufacturers will be required to report certain cybersecurity events through the CRA Single Reporting Platform (SRP), which became operational on 11 September 2026. The platform is operated by the European Union Agency for Cybersecurity (ENISA) and serves as the main channel for submitting relevant notifications.

Under the CRA, manufacturers must notify authorities about actively exploited vulnerabilities and severe security incidents affecting their products. The reporting process is structured in several steps, with specific deadlines for each stage to ensure timely communication.

According to the published guidance, an early warning must be submitted within 24 hours after a manufacturer becomes aware of a qualifying incident or vulnerability. A full notification is required within 72 hours, followed by a final report within 14 days for vulnerabilities or within one month for severe incidents.

What the numbers show

  • Reporting obligations start on 11 September 2026.
  • Early warnings must be submitted within 24 hours of awareness.
  • Final reports are due within 14 days for vulnerabilities and one month for severe incidents.

ENISA is responsible for maintaining the CRA SRP and also prepares technical reports every two years on cybersecurity risks in products with digital elements. This ongoing analysis supports the implementation and monitoring of the CRA’s objectives.

To help businesses comply with the new obligations, the European Commission published guidance on 27 July 2026. The guidance outlines the steps manufacturers should take to meet the CRA’s reporting requirements and clarifies the procedures for using the SRP.

The CRA’s reporting framework applies to all manufacturers of products with digital elements that are made available in the EU market. The obligations are intended to enhance the detection and management of cybersecurity risks across the sector.

By establishing clear timelines and a dedicated reporting platform, the CRA aims to streamline the process for handling cybersecurity incidents and vulnerabilities in digital products. The new rules are part of a broader effort to strengthen digital security within the European Union.

* This article is based on publicly available information at the time of writing.