11 September 2026 is not a preparatory date for the Cyber Resilience Act (CRA): it is the first operational obligation that begins to apply. Starting tomorrow, manufacturers of products with digital elements within the scope of Regulation (EU) 2024/2847 must be capable of detecting, assessing and reporting certain security events within deadlines that start at just 24 hours. The most common mistake we are observing is continuing to treat the CRA as a project for December 2027. For incident reporting, that timeline has already ended.
What exactly changes on 11 September
Article 14 requires the notification of two categories: actively exploited vulnerabilities of which the manufacturer becomes aware, and severe incidents that impact the security of the product. An actively exploited vulnerability requires reliable evidence that a malicious actor has used it without authorization. An incident is considered severe, among other situations, when it affects or may affect the availability, authenticity, integrity or confidentiality of sensitive/important data or functions, or when it may introduce or execute malicious code in the product or in a user's systems.
The obligation also applies to products already sold. Article 69.3 expressly establishes that the incident reporting requirements of Article 14 apply to all products with digital elements within scope, even if they were placed on the market before 11 December 2027. Therefore, it is not enough to prepare new products: manufacturers must know which products remain deployed, which versions are active, which components they contain, and how to contact their users when necessary.
The real issue: the clock starts when the organization “becomes aware”
The deadline does not begin when Legal finishes reviewing the case or when the crisis committee meets. The early warning must be issued without undue delay and, in any case, within 24 hours from the moment the manufacturer becomes aware. This is followed by the 72-hour notification and, finally, the final report: for an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, within one month following the 72-hour notification.
What should be ready today? Product and version inventory; Clearly designated CRA/PSIRT lead; Escalation criteria for AEVs and severe incidents; Integration with the SOC, vulnerability management and incident response processes; Third-party dependencies and components; Access and representatives configured in the Single Reporting Platform (SRP); Templates for 24-hour, 72-hour and final reports; Procedures for informing users; Evidence of all decisions, including justified decisions not to report; |
Reporting is performed only once through ENISA’s Single Reporting Platform. The platform is expected to be operational on 11 September and uses EU Login. The manufacturer selects the CSIRT designated as coordinator; in Spain, the list published by ENISA identifies INCIBE for incident handling and vulnerability coordination.
Fines: the CRA places reporting non-compliance in the highest penalty tier
The economic message of the Regulation is unequivocal. Article 64 places non-compliance with the essential requirements and the obligations of Articles 13 and 14 at the maximum sanction level: up to €15 million or, for a company, up to 2.5% of its total worldwide annual turnover from the previous financial year, whichever is higher. Other obligations may result in penalties of up to €10 million or 2%, and providing incorrect, incomplete or misleading information to certain authorities or bodies may result in fines of up to €5 million or 1%.
| Non-compliance |
Maximum limit |
| Essential requirements in Annex I and obligations under Articles 13 and 14 |
€15M or 2.5% |
| Other obligations listed in Article 64.4 |
€10M or 2% |
| Incorrect, incomplete or misleading information provided to notified bodies or market surveillance authorities |
€5M or 1% |
Legal clarification regarding the dates Article 14 is applicable from 11/09/2026, whereas Article 71 establishes the general application of the Regulation on 11/12/2027 and does not list Article 64 among the provisions subject to early application. As a matter of legal prudence, it should not be stated that the general penalty regime of Article 64 is already fully applicable on 11/09/2026. It should, however, be highlighted that the CRA itself classifies breaches of Articles 13 and 14 within its highest sanctioning tier. The temporal applicability and the national enforcement regime must be assessed on a case-by-case basis. |
And fines are not the only consequence. Within the broader CRA framework, market surveillance authorities may require corrective measures and, in cases of non-compliance, restrict or prohibit commercialization, withdraw products from the market, or recall them. In addition, for certain incidents, the manufacturer must inform affected users and provide mitigation measures. The reputational and contractual cost of explaining to customers that no process exists to detect and manage an exploited vulnerability may exceed the cost of the compliance project itself.
If you cannot report within 24 hours today, the problem is probably bigger than the form
Complying with Article 14 is not simply a matter of knowing ENISA’s URL. To determine within a few hours whether an event is reportable, an organization needs visibility over its product and its supply chain: a technical inventory, an SBOM or equivalent component information, vulnerability management, telemetry, disclosure channels, impact analysis, accountable personnel with decision-making authority, and coordination with suppliers. Incident reporting acts as a stress test for the product security program.
For that reason, my recommendation to manufacturers that have not yet started is to separate the work into two parallel tracks, while managing them together: First, establish an immediate incident reporting capability compliant with Article 14.
Second, conduct a complete CRA gap assessment leading up to December 2027, covering risk assessment, secure-by-design and secure-by-default principles, vulnerability handling, secure updates, support period management, technical documentation, conformity assessment, and CE marking preparation. Waiting until 2027 increases the risk of discovering too late that the problem is not documentary in nature, but rather one of architecture, processes, or product lifecycle management.
Turning the CRA into a manageable project
11 September should serve as a turning point. Companies manufacturing software, hardware, IoT products, components, or connected solutions should immediately validate the scope of their portfolio and test their notification process through a tabletop exercise: "We have confirmed the active exploitation of a critical vulnerability in a deployed version. Who knows about it, who makes the decision, and what information can we submit within the next 24 hours?" If answering these questions requires improvisation, the process is not yet ready.
At Internet Security Auditors, we can support this process through our CRA services from both a technical and audit perspective: scope determination and product classification, CRA gap analysis, incident reporting procedure design, vulnerability management and PSIRT reviews, SDLC security assessments, SBOM and supply chain reviews, technical testing, conformity documentation, and action plans leading to the full application of the Regulation.
The objective should not be simply to “have the paperwork ready for 2027,” but to demonstrate that security is managed throughout the entire product lifecycle.
Conclusions
From 11 September 2026, the CRA ceases to be only a future compliance date.
For manufacturers, the ability to respond to actively exploited vulnerabilities and severe incidents becomes a regulatory obligation with its own timeline. And when that timeline is measured in 24 hours, preparation cannot begin after the incident occurs.
If you would like to determine whether the CRA applies to your organization, you can complete the CRA (EU) 2024/2847 Applicability Self-Assessment Questionnaire.
References
🔗Regulation (EU) 2024/2847 (Cyber Resilience Act), official text in EUR-Lex. Articles 14, 16, 64, 69 and 71
🔗European Commission - Cyber Resilience Act: Reporting Obligations (updated 31/07/2026).
🔗European Commission - Cyber Resilience Act Implementation: Frequently Asked Questions (updated 04/09/2026).
🔗European Commission - Guidance to Support Timely CRA Implementation (27/07/2026).
🔗ENISA - CRA Single Reporting Platform: Frequently Asked Questions (updated 08/09/2026).
🔗ENISA - CRA SRP Guidance: Assigned Representative Registration (updated 09/09/2026).
🔗ENISA — List of CSIRTs Designated as Coordinators (actualizado 04/09/2026).