If your product connects to something, the CRA is talking to you
The Cyber Resilience Act is the European Union’s first horizontal law on the cybersecurity of connected products. It does not ask whether you are a security company. It asks whether you place a product with digital elements on the EU market — and then it hands you deadlines measured in hours. Read this page and you will know which side of the line you are on, and what changes for you on 11 September 2026.
- A regulation, directly applicable in every Member State — no national transposition.
- Covers products with digital elements: connected hardware and software.
- Reporting duties (Art. 14) apply from 11 September 2026.
- Three deadlines: 24 hours, 72 hours, final report.
What the Cyber Resilience Act is
The Cyber Resilience Act is Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024, on horizontal cybersecurity requirements for products with digital elements. It was published in the Official Journal and entered into force on 10 December 2024. As a regulation it is directly applicable, without national transposition.
Its aim is twofold: to raise the baseline security of connected products throughout their lifecycle, and to give buyers clearer information to make secure choices. It introduces essential cybersecurity requirements, obligations to handle vulnerabilities, and — the part that bites first — duties to report exploited vulnerabilities and severe incidents to the authorities.
Who it applies to
It applies to economic operators that make products with digital elements available on the EU market — manufacturers first of all, and then importers and distributors. A product with digital elements is any hardware or software whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.
Products already governed by specific sectoral rules — such as medical devices, motor vehicles, civil aviation and marine equipment — and genuinely non-commercial open source are outside its scope.
The timeline that matters
The regulation applies in stages. The reporting obligations arrive well before the product requirements — so a company can already be exposed to sanctions for a missed report long before it must show product conformity.
- 10 December 2024 The regulation enters into force.
- 11 September 2026 The reporting obligations of Art. 14 start to apply. 11 days to go
- 11 December 2027 Essential requirements, technical documentation and CE marking apply.
The reporting obligations (Art. 14)
Article 14 requires the manufacturer to notify — simultaneously the coordinating CSIRT and ENISA — any actively exploited vulnerability contained in the product, and any severe incident having an impact on its security. Reporting runs through the single reporting platform. Each event follows a three-step chain, and the final deadline differs by type of event.
24h · Early warning
Within 24 hours of becoming aware, an early warning to the CSIRT and ENISA.
72h · Notification
Within 72 hours, a fuller notification of the vulnerability or the incident.
14d / 1m · Final report
For an exploited vulnerability, within 14 days of a corrective or mitigating measure becoming available; for a severe incident, within one month of the incident notification.
Two related duties
After notifying the authorities, the manufacturer must inform the users of the product about the incident or vulnerability without undue delay and, where appropriate, about the mitigation measures.
Coordinated disclosure (Art. 13)
Manufacturers must handle vulnerabilities throughout the support period, adopt a coordinated vulnerability disclosure policy, and — where a vulnerability sits in a third-party or open-source component — report it to the maintainer and cooperate. This is impossible without an up-to-date bill of materials.
The actors: ENISA and the CSIRT
The ENISA single reporting platform
ENISA — the EU Agency for Cybersecurity — establishes and operates a single reporting platform that receives the notifications required by Art. 14 and routes them to the relevant national authorities.
The coordinating CSIRT
Each Member State designates a CSIRT — the computer security incident response team from the NIS2 framework — as coordinator for the manufacturer’s notifications. In Italy that role sits with CSIRT Italia within the national cybersecurity agency (ACN).
Each obligation, and how CRAnotify covers it
CRAnotify does not file on your behalf: it prepares the filing, records every decision, and runs the clock. Here is the mapping from the article to the part of the product that supports it.
| Obligation | What it requires | How CRAnotify covers it |
|---|---|---|
| Qualify the event Art. 14(1) |
Decide whether it is an actively exploited vulnerability, a severe incident, or neither. | Guided triage returns a verdict with the legal basis attached. Triage · Verdict |
| Hit the deadlines Art. 14(2) · 14(4) |
24 hours, 72 hours and the final report, counted from the moment of awareness. | The clock starts on qualification, tracks each phase and sends reminders. Phases and deadlines |
| Draft the notification Art. 14(2)(b) · 14(4)(b) |
Produce the content of the notification within 72 hours. | A pre-filled draft: the engine decides some fields, you complete the rest. Notification |
| File on the platform Art. 16 |
Submit through the ENISA single reporting platform and keep the receipt. | The app prepares the filing and records the mandatory receipt and protocol number. You submit. Filing |
| Inform the users Art. 14(8) |
Notify the product’s users without undue delay, with mitigation where appropriate. | A user-notice task with a copy of what was circulated kept as evidence. Related duties |
| Report upstream Art. 13(6) |
Report a vulnerability in a third-party or open-source component to its maintainer. | An upstream-chain task, backed by the software bill of materials. Bill of materials |
| Intake channel Annex I, Part II |
A coordinated disclosure policy and a channel to receive vulnerability reports. | A public reporting form to embed, plus security.txt. Public form |
| Prove diligence Accountability |
Be able to reconstruct what was decided, when and why, before an authority. | A tamper-evident activity registry and a defensive dossier to hand over. Registry · Dossier |
Article references follow the numbering of Regulation (EU) 2024/2847. This page describes our reading of the text and is not legal advice.
Frequently asked questions
Find out if the CRA applies to you, then get ready for it.
Four steps to check your scope, and a guided flow to be ready before the first real report.
Who receives your notification, country by country
Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.
- ItalyCSIRT Italia
- GermanyCERT-Bund
- AustriaCERT.at
- FranceCERT-FR
- BelgiumCERT.be
- LuxembourgCIRCL
- SpainINCIBE-CERT
- NetherlandsNCSC-NL
- PolandCSIRT NASK
Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.