started · updated
EU Cyber Resilience Act reporting mandates take effect
On September 11, 2026, the European Union’s Cyber Resilience Act (CRA) entered its first operational phase, mandating strict reporting requirements for manufacturers of products with digital elements. This includes software, connected hardware, and IoT devices such as smart home equipment and industrial controllers.
Under Article 14, manufacturers must report actively exploited vulnerabilities or severe security incidents through ENISA’s Single Reporting Platform (SRP). The reporting timeline is highly compressed: an initial early warning must be issued within 24 hours of discovery, a detailed notification within 72 hours, and a final report within 14 days of a mitigation becoming available. For severe incidents, the final report is due within one month.
Non-compliance carries significant financial penalties, with fines reaching up to 15 million Euros or 2.5% of a company’s total global annual turnover. While these immediate reporting obligations are now in effect, the broader set of CRA requirements, including full compliance for CE marking, is scheduled for implementation by December 11, 2027.
Entities
Bitkom · ENISA · European Commission · European Union · European Union · European Union Agency for Cybersecurity · Genetec Inc. · Mathieu Chevalier · NORD DRIVESYSTEMS · NewTec
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] The reporting obligation for the EU Cyber Resilience Act (CRA) takes effect on September 11, 2026. www.artikel-presse.de · www.presseschleuder.com · www.automationmagazine.co.uk · www.blogdumoderateur.com · www.computerworld.dk · +2 more
- [● 7 SOURCES] The CRA establishes cybersecurity requirements for products with digital elements sold in the European Union. www.artikel-presse.de · www.presseschleuder.com · www.automationmagazine.co.uk · www.blogdumoderateur.com · www.computerworld.dk · +2 more
- [● 4 SOURCES] CRA requirements include secure product development, vulnerability management, and continuous product support. www.artikel-presse.de · www.presseschleuder.com · www.blogdumoderateur.com · www.computerworld.dk
- [○ 1 SOURCE] Railway manufacturers and suppliers must comply with NIS-2 and the Cyber Resilience Act. www.presse-board.de
- [○ 1 SOURCE] NewTec provides Public Key Infrastructure (PKI) services to help manufacturers meet regulatory security requirements. www.presse-board.de
- [● 2 SOURCES] The EU Cyber Resilience Act (CRA) reinforces principles of ‘Secure-by-Design’ and lifecycle management. www.artikel-presse.de · www.presseschleuder.com
- [● 3 SOURCES] Non-compliance with the CRA can result in fines of up to 15 million Euros or 2.5% of global annual turnover. itopstimes.com · www.computerworld.dk · ethnews.com
- [● 8 SOURCES] Manufacturers must provide an early warning within 24 hours of an actively exploited vulnerability, a full notification within 72 hours, and a final report within 14 days. www.automationmagazine.co.uk · www.security-insider.de · thecyberexpress.com · cybernoz.com · www.batista70phone.com · +3 more
- [● 7 SOURCES] Manufacturers must provide an early warning of an actively exploited vulnerability or severe incident within 24 hours. cybernoz.com · www.esteval.fr · crn.pl · ethnews.com · techround.co.uk · +2 more
- [○ 1 SOURCE] Non-compliance can result in fines of up to €15 million or 2.5% of global annual turnover. ethnews.com
- [● 18 SOURCES] The EU Cyber Resilience Act (CRA) reporting obligations for digital products took effect on September 11, 2026. cybernoz.com · www.esteval.fr · crn.pl · ethnews.com · techround.co.uk · +13 more
- [● 5 SOURCES] Reports must be submitted via ENISA’s Single Reporting Platform (SRP). cybernoz.com · crn.pl · www.viva.co.id · samsik.dk · thecyberexpress.com