On 11 September 2026, the first operational obligations under the EU Cyber Resilience Act ("CRA") began to apply. While the bulk of the CRA will only apply from 11 December 2027, manufacturers of products with digital elements ("PDEs") must already comply with new cyber incident and vulnerability reporting obligations.
What is a product with digital elements?
A PDE is any software or hardware product and its remote data processing solutions, including components placed on the market separately, that is made available on the EU market in the course of a commercial activity. Examples include IoT devices, laptops, network printers, smartphone apps, desktop software, and software drivers. Note that certain products are excluded from the CRA’s scope, including medical devices, vehicles and certain open-source software already covered by other EU frameworks. If your organisation manufactures such products for the EU market, the CRA reporting obligations apply to you from 11 September 2026 – including in respect of products already on the market before the CRA's entry into force.
What and when must be reported?
Manufacturers must report two categories of events to the computer security incident response team (CSIRT) designated as coordinator and to ENISA (the European Union Agency for Cybersecurity), via ENISA's new Single Reporting Platform:
- Actively exploited vulnerabilities (AEVs) contained in the PDE, i.e. vulnerabilities for which there is reliable evidence that a malicious actor has exploited them in a system without the system owner’s permission. Vulnerabilities discovered without malicious intent for the purposes of good-faith testing, investigation, correction or disclosure are not subject to this obligation.
- Severe incidents having an impact on the security of the PDE, i.e. incidents that negatively affect (or are capable of negatively affecting) the PDE’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that have led (or are capable of leading) to the introduction or execution of malicious code.
The reporting timeline is strict:
- Early warning: within 24 hours of becoming aware.
- Full notification: within 72 hours.
- Final report: within 14 days after a corrective measure is available (for vulnerabilities/AEVs) or within 1 month after the 72-hour notification (for severe incidents).
Manufacturers must also inform affected users of the vulnerability or incident and, where necessary, of the corrective measures they can deploy.
With the full CRA obligations applying from 11 December 2027, the reporting rules are only the beginning.
The data team at Eubelius is closely monitoring the CRA's implementation and is ready to assist your organisation in navigating these new obligations.