Cyber Resilience Act
CRA reporting is live. You may be the manufacturer.
CRA reporting went live on 11 September 2026: 24 hours to report an exploited vulnerability in something you sold. Manufacturer is a role, not an industry.

The Cyber Resilience Act switched on its first hard obligation for manufacturers on 11 September 2026, and ENISA opened the platform that receives the filings on the same day. Manufacturers of products with digital elements now have 24 hours to report an actively exploited vulnerability or a severe incident. Most organisations have filed this under “hardware vendors” and moved on. The CRA does not define manufacturer by industry — it defines it by what you do to a product, and four ordinary commercial arrangements put your company inside that definition without anyone ever calling themselves a manufacturer.
What actually switched on
The reporting clock in Article 14 has three stages, and it starts the moment you become aware. It binds manufacturers now; open-source software stewards come under the same duty on 11 December 2027.
An early warning within 24 hours. A full notification within 72 hours — general information on the vulnerability and the corrective measures taken, or, for an incident, an initial assessment. Then a final report: no later than 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability, or within one month of the 72-hour notification for a severe incident.
Two things are reportable. An actively exploited vulnerability — one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner’s permission. And a severe incident having an impact on the security of the product, against the criteria in Article 14(5).
You file once. Under Article 16, ENISA operates a Single Reporting Platform that routes your notification simultaneously to the CSIRT designated as coordinator in the Member State where you have your main establishment — Article 14(7) tells you which one, and a Member State may run several with only one designated — and to ENISA. That CSIRT then disseminates it to the CSIRTs of the Member States you have indicated the product is available in, and to market surveillance authorities as needed. In narrow, justified cases the receiving CSIRT can delay that dissemination; Delegated Regulation (EU) 2026/881, adopted 11 December 2025, sets the conditions.
Manufacturer is a role, not an industry
Here is the part that catches people. The hinge in Article 3(13) is not the factory — it is the trademark. You are the manufacturer if you develop the product and place it on the market under your own name or trademark — and equally if someone else designed and built it and you do the same. Note the and: developing a product someone else badges does not make you the manufacturer, because the duty follows the trademark. Two further routes. Under Article 21 an importer or distributor placing a product under their own name or trademark is treated as the manufacturer; under Article 22, so is anyone who substantially modifies a product already on the market. Either way, Articles 13 and 14 are yours.
Four routes into the CRA definition of manufacturer — and what genuinely stays out.
So: the industrial firm that commissions a white-label controller and ships it under its own badge. The equipment company that adds a connectivity module to a product line. The distributor that rebrands. None of them think of themselves as software businesses. All of them are manufacturers for CRA purposes.
Two limits, stated honestly. Software delivered purely as a service is generally outside the CRA, unless it is a remote data processing solution — processing carried out away from the product but essential to that product functioning, in software developed by or for the manufacturer. And a product you merely use creates no obligation for you at all; the duty sits with whoever made it.
One more thing that surprises people: the obligation reaches products already on the EU market. If you become aware, after the date, that a vulnerability in something you sold in 2023 is being exploited, the clock runs.
This is not the clock you already track
If your organisation has done NIS2, DORA or GDPR work, you have a reporting process. It will not carry you here, and the reason is the trigger.
NIS2’s 24 hours, DORA’s four — running from the moment you classify an incident as major, with an outer bound of 24 hours from awareness — and the GDPR’s 72 all start when something happens to you: your network, your systems, your data subjects. The CRA clock starts when a vulnerability in something you sold is exploited somewhere else entirely, at a customer you may never speak to. Different trigger, different evidence, different route to the knowledge. And a different owner inside the company: this is a product and engineering obligation before it is an IT or legal one. If your incident process routes everything through the same duty phone that handles the GDPR, it will not detect this.
We made a related point in One Incident, Three Regulators: the clocks that matter are not the longest ones you can recite, but the shortest one whose trigger you can actually observe. Where those regimes overlap, our NIS2 readiness work starts by mapping which obligation fires first, not by writing another policy.
The relief that stops at 50 employees
Article 64 sets the ceiling: non-compliance with Annex I and with the obligations in Articles 13 and 14 carries administrative fines up to €15 million, or 2.5% of total worldwide annual turnover, whichever is higher.
There is a derogation, and it is narrower than it first appears. Article 64(10)(a) removes the fine for micro and small enterprises that miss the deadline in Article 14(2)(a) or 14(4)(a) — that is, the 24-hour early warning. Not the 72-hour notification. Not the final report. Not the duty to report at all. One deadline, for the smallest firms. A small enterprise, under the EU definition, means fewer than 50 staff and turnover or a balance-sheet total of €10 million or less.
Two points on the reach of that relief. First, it does reach the fine. Article 64(10) as originally published derogated from “paragraphs 3 to 9”, while the Article 14 fines sit in paragraph 2 — which left it arguable whether the relief touched them at all. A corrigendum published on 2 July 2025 (OJ L, 2025/90555) replaced that wording with “paragraphs 2 to 9”, closing the gap. What the corrigendum does not do is widen the relief: it is still one deadline, for the smallest firms, and not the obligation. Second, Article 71 brings Article 14 forward to September 2026 but leaves the rest of the regulation, including Article 64, applying from 11 December 2027, and most Member States have not yet put national penalty rules in place. Whether a fine is legally available for a September 2026 reporting failure is therefore arguable. Do not plan around the argument: the obligation is not in doubt, and the contractual and reputational consequences of a missed filing arrive long before a regulator does.
What the platform does, and does not, do for you
The Single Reporting Platform is a portal, not an integration. ENISA opened it on 11 September as an initial operating capability — a first release, to be extended as manufacturers use it. The link, the assigned-representative user manual, tutorial material and a help desk aimed particularly at smaller firms all sit on ENISA’s Single Reporting Platform page.
Four facts decide how your first filing goes. Only an assigned representative can submit — one primary per manufacturer, up to twenty secondary — each on an EU Login account with multi-factor authentication, a general Commission credential you can create today. There is no API in this release: filing is manual portal entry, so any plan that assumed system-to-system reporting needs a person and a fallback. The platform is English only for now. And only mandatory notifications can be filed; voluntary reporting is not available yet.
The verification mechanic is the one that changes behaviour. A representative whose link to the manufacturer is not yet verified may still file — up to twenty notifications before verification becomes mandatory — so validation never blocks a report. ENISA’s advice follows: register only when you have a notification to submit, not pre-emptively. “Get registered early” was never the preparation. What you rehearse is everything either side of the portal: who decides, who drafts, who has the authority to send.
The Commission’s implementation guidance, published 27 July 2026 and expressly non-binding, works through reporting in detail.
Eight things to settle before your first filing — none of them bought.
What to do before your first filing
The duty is live, so this is no longer a countdown — it is the state you are in, or are not, on the morning a customer calls. None of it is a purchase. It is four decisions and a rehearsal: determine whether you are a manufacturer for any product you sell, name the person who files, create the EU Login and identify your CSIRT under Article 14(7), and run one tabletop where the trigger is a customer telling you your product is being exploited. If that exercise takes more than 24 hours to reach a decision, you have found the gap before a real notification does. Our Cyber Resilience Act page sets out the full obligation set and what changes again in December 2027; an independent readiness review is the fastest way to establish scope if the answer is genuinely unclear.
Take the next step
Talk to a security practitioner, not a salesperson.
Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.
