Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
01CRAnotify · Regulation (EU) 2024/2847

If your product connects to something, the CRA is talking to you

The Cyber Resilience Act is the European Union’s first horizontal law on the cybersecurity of connected products. It does not ask whether you are a security company. It asks whether you place a product with digital elements on the EU market — and then it hands you deadlines measured in hours. Read this page and you will know which side of the line you are on, and what changes for you on 11 September 2026.

In one minute
  • A regulation, directly applicable in every Member State — no national transposition.
  • Covers products with digital elements: connected hardware and software.
  • Reporting duties (Art. 14) apply from 11 September 2026.
  • Three deadlines: 24 hours, 72 hours, final report.
01The regulation

What the Cyber Resilience Act is

The Cyber Resilience Act is Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024, on horizontal cybersecurity requirements for products with digital elements. It was published in the Official Journal and entered into force on 10 December 2024. As a regulation it is directly applicable, without national transposition.

Its aim is twofold: to raise the baseline security of connected products throughout their lifecycle, and to give buyers clearer information to make secure choices. It introduces essential cybersecurity requirements, obligations to handle vulnerabilities, and — the part that bites first — duties to report exploited vulnerabilities and severe incidents to the authorities.

02Scope

Who it applies to

It applies to economic operators that make products with digital elements available on the EU market — manufacturers first of all, and then importers and distributors. A product with digital elements is any hardware or software whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.

Products already governed by specific sectoral rules — such as medical devices, motor vehicles, civil aviation and marine equipment — and genuinely non-commercial open source are outside its scope.

Art. 3(1)“Products with digital elements” means any software or hardware product and its remote data-processing solutions, including components placed on the market separately.
03Timeline

The timeline that matters

The regulation applies in stages. The reporting obligations arrive well before the product requirements — so a company can already be exposed to sanctions for a missed report long before it must show product conformity.

  • 10 December 2024 The regulation enters into force.
  • 11 September 2026 The reporting obligations of Art. 14 start to apply. 11 days to go
  • 11 December 2027 Essential requirements, technical documentation and CE marking apply.
04Article 14

The reporting obligations (Art. 14)

Article 14 requires the manufacturer to notify — simultaneously the coordinating CSIRT and ENISA — any actively exploited vulnerability contained in the product, and any severe incident having an impact on its security. Reporting runs through the single reporting platform. Each event follows a three-step chain, and the final deadline differs by type of event.

24h · Early warning

Within 24 hours of becoming aware, an early warning to the CSIRT and ENISA.

Rif.Art. 14(2)(a) · 14(4)(a)

72h · Notification

Within 72 hours, a fuller notification of the vulnerability or the incident.

Rif.Art. 14(2)(b) · 14(4)(b)

14d / 1m · Final report

For an exploited vulnerability, within 14 days of a corrective or mitigating measure becoming available; for a severe incident, within one month of the incident notification.

Rif.Art. 14(2)(c) · 14(4)(c)

Two related duties

After notifying the authorities, the manufacturer must inform the users of the product about the incident or vulnerability without undue delay and, where appropriate, about the mitigation measures.

Rif.Art. 14(8)

Coordinated disclosure (Art. 13)

Manufacturers must handle vulnerabilities throughout the support period, adopt a coordinated vulnerability disclosure policy, and — where a vulnerability sits in a third-party or open-source component — report it to the maintainer and cooperate. This is impossible without an up-to-date bill of materials.

Rif.Art. 13 · Art. 13(6) · Annex I, Part II
05The actors

The actors: ENISA and the CSIRT

The ENISA single reporting platform

ENISA — the EU Agency for Cybersecurity — establishes and operates a single reporting platform that receives the notifications required by Art. 14 and routes them to the relevant national authorities.

ENISA · official website

Rif.Art. 16

The coordinating CSIRT

Each Member State designates a CSIRT — the computer security incident response team from the NIS2 framework — as coordinator for the manufacturer’s notifications. In Italy that role sits with CSIRT Italia within the national cybersecurity agency (ACN).

Rif.Art. 14(1)

Each obligation, and how CRAnotify covers it

CRAnotify does not file on your behalf: it prepares the filing, records every decision, and runs the clock. Here is the mapping from the article to the part of the product that supports it.

Obligation What it requires How CRAnotify covers it
Qualify the event
Art. 14(1)
Decide whether it is an actively exploited vulnerability, a severe incident, or neither. Guided triage returns a verdict with the legal basis attached. Triage · Verdict
Hit the deadlines
Art. 14(2) · 14(4)
24 hours, 72 hours and the final report, counted from the moment of awareness. The clock starts on qualification, tracks each phase and sends reminders. Phases and deadlines
Draft the notification
Art. 14(2)(b) · 14(4)(b)
Produce the content of the notification within 72 hours. A pre-filled draft: the engine decides some fields, you complete the rest. Notification
File on the platform
Art. 16
Submit through the ENISA single reporting platform and keep the receipt. The app prepares the filing and records the mandatory receipt and protocol number. You submit. Filing
Inform the users
Art. 14(8)
Notify the product’s users without undue delay, with mitigation where appropriate. A user-notice task with a copy of what was circulated kept as evidence. Related duties
Report upstream
Art. 13(6)
Report a vulnerability in a third-party or open-source component to its maintainer. An upstream-chain task, backed by the software bill of materials. Bill of materials
Intake channel
Annex I, Part II
A coordinated disclosure policy and a channel to receive vulnerability reports. A public reporting form to embed, plus security.txt. Public form
Prove diligence
Accountability
Be able to reconstruct what was decided, when and why, before an authority. A tamper-evident activity registry and a defensive dossier to hand over. Registry · Dossier

Article references follow the numbering of Regulation (EU) 2024/2847. This page describes our reading of the text and is not legal advice.

02Frequently asked questions

Frequently asked questions

Find out if the CRA applies to you, then get ready for it.

Four steps to check your scope, and a guided flow to be ready before the first real report.

National authorities

Who receives your notification, country by country

Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.

Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.