Back to the journal
IT-Sicherheit August 2026

Cyber Resilience Act: Reporting Obligations from September 2026

From September 11, 2026, the reporting obligations of the Cyber Resilience Act apply. We explain the deadlines, who is affected, and how to prepare now.

September 11, 2026, is the key date for the Cyber Resilience Act reporting obligations.

Imagine you manufacture a smart device, an app, or software and sell it in the EU. Until now, there were hardly any EU-wide rules on what you must do when security problems arise. That changes in September 2026: The Cyber Resilience Act (CRA) comes into force, an EU regulation requiring manufacturers of digital products to report actively exploited vulnerabilities and incidents within 24 hours.

The Cyber Resilience Act (CRA), roughly translated as "Law on Cyber Resilience," is EU Regulation 2024/2847. It sets EU-wide uniform cybersecurity requirements for products with digital functions such as routers, smart home devices, or software. The regulation entered into force on December 10, 2024. Most obligations apply only from December 2027. However, the reporting obligations under Article 14 start earlier: they apply from September 11, 2026. This affects manufacturers of digital products across the EU, including many small and medium-sized enterprises that have not yet established comparable processes.

The European Commission published initial guidelines with 67 practical examples on July 27, 2026. These help with interpretation but do not answer, for example, whether contract processors in the supply chain count as manufacturers. For companies, a new regulatory reality begins now, extending beyond previous obligations under the NIS Directive (2016/1148) and the Radio Equipment Directive.

Article 14 requires reporting of actively exploited vulnerabilities and severe incidents.

The reporting obligations under Article 14 CRA cover two cases: actively exploited vulnerabilities and severe incidents (referred to as "severe incidents" in the regulation). A manufacturer must report a vulnerability if it exists in their product and is actually exploited by attackers. A severe incident is an event that significantly compromises the security of the product or its users.

The deadlines are calculated in hours. For actively exploited vulnerabilities, the initial report must be submitted within 24 hours of becoming aware. For severe incidents, the deadline is also 24 hours. Interim reports and a final report follow. The exact deadlines for subsequent reports are detailed in the Commission's guidelines.

Reports are submitted through a central reporting platform. In Germany, the Federal Office for Information Security (BSI) is setting up this platform, expected to be active from August 2026. Manufacturers must register and submit their reports there.

The obligations apply to manufacturers, importers, and distributors of digital products.

The CRA covers products with digital elements. This includes hardware such as routers and smart home devices, software such as operating systems and applications, as well as products with embedded software. Most products, from household appliances to computer games, undergo a conformity assessment, an official check to verify that the product meets the EU's security requirements.

The manufacturer is primarily responsible. Importers and distributors have obligations when they bring products into the EU or distribute them. They must ensure that the manufacturer fulfills their reporting duties. For small and medium-sized enterprises, this means: if you manufacture or import digital products, you must address Article 14.

The distinction from NIS-2 is important. The CRA regulates products, while NIS-2 concerns operators of critical infrastructures and essential entities. A company can be covered by both regimes. A machinery manufacturer that falls under NIS-2 as an operator and also produces machines with control software must comply with both frameworks.

RegulationScopeAddresseesExampleEntry into force
CRAProducts with digital elementsManufacturers, importers, distributorsRouters, smart home devicesSince 10.12.2024, reporting obligations from 11.09.2026
NIS-2Operators of critical infrastructures and essential entitiesOperatorsMachinery manufacturer as operatorSector-dependent since 2024

The Commission's guidelines with 67 examples are a practical compass.

The guidelines published on July 27, 2026, concerning Article 14 CRA contain 67 practical examples. They show how the Commission classifies various cases. This helps manufacturers assess their own situations and make the right decisions.

The examples cover typical questions: When is a vulnerability actively exploited? What counts as a severe incident? How are deadlines calculated? The guidelines provide answers to many everyday questions that arise during implementation.

We consider the guidelines a good starting point, but not a definitive answer. Some interpretation questions remain open, particularly regarding complex supply chains or collaboration with external service providers. Companies should use the guidelines as a foundation and seek legal advice where uncertainties remain.

Practical steps: build processes, clarify responsibilities, use tools.

The practical steps for the CRA reporting obligations from September 11, 2026, include: (1) taking stock of affected products, (2) building detection, assessment, and reporting processes with clear roles, (3) introducing a vulnerability management system and an incident response plan, (4) clarifying the responsible notified body, (5) registering on the BSI platform.

  1. Inventory: Which products fall under the CRA? Which vulnerabilities and incidents must be reported? Answer these questions now, not in September 2026.
  2. Build processes: You need a clear workflow for detecting, assessing, and reporting vulnerabilities and incidents. Define responsibilities: who detects a vulnerability? Who assesses it? Who reports it? These roles must be assigned and trained.
  3. Use tools: A vulnerability management system helps capture and prioritize vulnerabilities, essentially a continuously maintained inventory of known security gaps. An incident response plan describes how your team reacts to incidents, essentially an emergency plan for the worst case. Automated reporting workflows ensure deadlines are met.
  4. Clarify notified body: Collaboration with notified bodies is required for many products. These are independent testing bodies officially designated by the EU that assess whether a product meets security requirements. Clarify early which body is responsible for your products and which documents are needed.
  5. Register on the BSI platform: Once the platform is available, register to be able to report quickly in an emergency.

Act now, do not wait: an early start pays off.

The reporting obligations under Article 14 CRA are not a distant prospect. They apply from September 2026 and affect even small and medium-sized manufacturers. Building your processes now not only helps avoid fines but also strengthens trust in your products and relieves your team in the long run.

An early start offers several advantages. You can test and improve processes calmly before deadlines apply. You avoid the rush and errors that occur under time pressure. And you show customers and partners that you take security seriously.

The combination of CRA and NIS-2 requires a coordinated approach. Many companies are affected both as manufacturers and as operators. Check which obligations apply to your company and align your processes accordingly. Standards such as ISO 27001 are not legally mandatory but can offer synergies during implementation.

We recommend studying the Commission's guidelines and aligning your processes with them. The 67 examples are a practical compass that answers many questions. For open interpretation issues, seek legal advice and exchange ideas with industry associations.

The Cyber Resilience Act fundamentally changes the requirements for product security. Companies that act now are well prepared. Those who wait risk fines and loss of trust. The decision is yours.

Frequently asked questions

What obligations arise from Article 14 CRA from September 2026?

Manufacturers of digital products must report actively exploited vulnerabilities and security incidents. The initial report must be submitted within 24 hours of becoming aware, followed by interim and final reports.

What deadlines apply for reporting vulnerabilities and security incidents?

The initial report must be submitted within 24 hours of becoming aware. Subsequently, interim reports and a final report must be submitted within the deadlines set out in the European Commission's guidelines.

Which products fall under the Cyber Resilience Act?

The CRA covers products with digital elements, including hardware such as routers and smart home devices, software such as operating systems and applications, and products with embedded software. Most products are subject to conformity assessment.

How do the reporting obligations under CRA and NIS-2 differ?

The CRA regulates products with digital elements and addresses manufacturers, importers, and distributors. NIS-2 concerns operators of critical infrastructures and essential entities. A company can be covered by both regimes.