This website uses cookies

Read our Privacy policy and Terms of use for more information.

EU Cyber Resilience Act Reporting Goes Live Friday

The EU Cyber Resilience Act's Article 14 incident-reporting duties become binding on Friday, 11 September 2026 — hitting every manufacturer of a connected product sold in the EU, on a 24-hour clock.

Why It Matters

From Friday, 11 September, the Cyber Resilience Act (Regulation (EU) 2024/2847) turns Article 14 into a live obligation for every manufacturer of a product with digital elements made available on the EU market. An actively exploited vulnerability or severe incident triggers an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure (one month for a severe incident).

The practical catch is the plumbing. Reports are filed once through ENISA's Single Reporting Platform — which launches the same day the duty starts, as a web portal with no API at launch — addressed to the CSIRT of your main establishment and shared with ENISA. The obligation also reaches products already placed on the market. Compliance, security, and legal teams need a named owner, a workflow, and portal access in place before the clock can start on a first incident.

Action Items

  1. Confirm scope — Identify which of your EU-market products with digital elements fall under the CRA before 11 September.

  2. Get platform-ready — Register or prepare access to the ENISA Single Reporting Platform (web portal, no API) and map the CSIRT of your main establishment as the reporting destination.

  3. Assign the clock-owner — Name who files the 24-hour / 72-hour / 14-day reports and rehearse the timeline this week.

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk