In brief

From 11 September 2026, manufacturers of in-scope connected products on the EU market must file an early warning about an actively exploited vulnerability or a severe incident within 24 hours of becoming aware of it. Most of the CRA’s manufacturer obligations do not start until December 2027. This article explains what the September reporting duty involves, who must comply, and what organisations should establish when procuring connected equipment.

Importantly, the reporting duty is not limited to new products. It can be triggered by a vulnerability or incident affecting a product placed on the EU market years earlier. The reporting clock starts when the manufacturer becomes aware that a vulnerability in one of its products is being actively exploited, or that a severe incident has occurred. A severe incident is one that negatively affects, or could negatively affect, the product’s ability to protect sensitive or important data or functions. It also includes an incident that has led, or could lead, to malicious code being introduced or run in the product or in a user’s network.

The duty also applies to manufacturers outside the EU that place products on the EU market. The main product-security and vulnerability-handling obligations do not apply until 11 December 2027. For manufacturers, September brings both the reporting duty and the associated duty to inform affected users.

Does the law cover equipment that is already installed?

For reporting, it does. Broadly, the Regulation covers hardware and software whose intended or reasonably foreseeable use includes a connection to a device or network. Some products governed by specified sectoral EU legislation are excluded, including certain medical devices, motor-vehicle products, certified aviation equipment and marine equipment.

Products placed on the EU market before 11 December 2027 stay outside most of the law. They come inside it only if they are later changed in a way that affects their security or their purpose. Reporting, however, is the exception. It applies to every covered product on the EU market, whenever it was placed there. A heating controller first placed on the EU market in 2019 does not require a new conformity assessment or CE marking under the CRA solely because the reporting duty has begun. From 11 September, however, its manufacturer must report an actively exploited vulnerability or a severe incident affecting it.

Who has to do the reporting?

The manufacturer files the report. Under the Regulation, that is the person or organisation that develops or manufactures the product, or has it designed, developed or manufactured, and markets it under its own name or trademark. This applies whether the product is supplied for payment, monetisation or free of charge. Installing, running or maintaining the product does not by itself make an organisation the manufacturer.

The duty depends on where the product is placed on the market, not on where the manufacturer is based. A UK manufacturer placing products on the EU market remains responsible for them. The UK has its own product security law on its own timetable, and the two are separate.

What does reporting involve?

Within 24 hours of becoming aware of the vulnerability or incident, the manufacturer files an early warning, naming the EU countries where it knows the product has been made available and, for an incident, whether unlawful or malicious acts are suspected. Within 72 hours it files a fuller notification: what the product is, what the problem is, what the manufacturer has done and what users can do. For a vulnerability, a final report follows no later than 14 days after a corrective or mitigating measure becomes available. For an incident, it follows within one month of the 72-hour notification. The receiving incident response team can also request an interim report before the final report is due. The manufacturer must also tell the users affected.

Reports will be submitted through a single online platform established by ENISA, the EU’s cybersecurity agency. The European Commission says the platform will be operational by 11 September 2026. The notifications go to the national incident response team in the EU country where the manufacturer mainly makes its product-security decisions. Where the manufacturer has no EU establishment, Article 14 sets a separate order for determining which country receives them.

What changes in December 2027?

From 11 December 2027, a manufacturer must state the support period for each new product. That support period must be at least five years, unless the product is expected to be in use for less. Its end date must be given at the time of purchase. During the support period, once a security update exists it must be distributed without delay and, by default, free of charge.

For remotely managed equipment, distributing that update may depend on continuing to reach the product. Five years is long enough for the mobile networks that connection uses to change. Across Europe, published 2G closure dates show that the networks available during a product’s support period may differ from those available when it is first supplied. If the management route disappears while the product is still within its support period, the manufacturer needs another way to deliver the update.

What should a procurement record show?

An organisation does not acquire an Article 14 reporting duty simply by buying or operating connected equipment. It still depends on manufacturers that can meet that duty and on products that remain reachable when a security update is needed. Four answers, therefore, belong on file before a contract is signed. Together they establish the support period, the network dependencies, the update route and the reporting responsibility.

  1. How long is the support period for this product, and what continues when it ends? The answer should give the end date, at least the month and year, and state plainly what continues afterwards and what stops.
  2. Which mobile networks can the product use, and what core-network dependencies remain across those routes? Access to several radio networks may still depend on a single operator core.
  3. How does a security update reach a unit in the field, and does it ever need an engineer to visit? If the answer is a visit, the cost of that visit, multiplied by the number of units, belongs in the comparison.
  4. Who reports under the Regulation for this product, and who is the contact when a security problem is found? The answer should name a firm and a person or team.

CSL designs and manages multi-network and independent-core connectivity for critical connected equipment across Europe. To discuss the connectivity requirements of a specific product or estate, speak to our team.

Sources

  • Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 2, 3, 13, 14, 69 and 71, Official Journal of the European Union.
  • European Commission (2026), “Cyber Resilience Act: reporting obligations”, page last updated 31 July 2026.
Published on: 7th September, 2026
Sectors: Infrastructure, Public Sector, Retail & Hospitality, Transport & Logistics, Utilities
Applications: Agriculture & Farming, Building Automation/Smart Building, Construction, Critical Resilience & Multi-Site Operations, Emergency Lighting, Emergency Services, Energy Efficiency Monitoring, EV Charging & Parking solutions, Renewable Energy, Retail & Payment Systems