Regulation

The Cyber Resilience Act starts reporting on 11 September 2026

The Cyber Resilience Act applies from December 2027 — except Article 14, live from 11 September 2026. Who it binds, the clocks, and the legacy trap.

In short
Article 14 of the EU Cyber Resilience Act, Regulation (EU) 2024/2847, applies from 11 September 2026 — the rest of the Regulation only from 11 December 2027. It requires any manufacturer placing a product with digital elements on the EU market to report an actively exploited vulnerability or severe incident to ENISA and a CSIRT within 24 hours, and it binds non-EU companies directly.

The date almost nobody has in their calendar

Most summaries of the Cyber Resilience Act give one date: 11 December 2027. That is when the Regulation applies in general, and it is why the CRA has been filed away as a 2027 problem.

Article 71(2) says something else. After setting the December 2027 date it continues: “However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”

Chapter IV — the machinery for notifying conformity assessment bodies — has been in force since June. Article 14 is the reporting duty, and it starts on 11 September 2026.

Article 14 is not the part you can defer

It requires a manufacturer to notify, simultaneously to the coordinating CSIRT and to ENISA, two things: an actively exploited vulnerability in its product, and a severe incident affecting the product’s security.

An actively exploited vulnerability is defined narrowly — one “for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner.” This is not your vulnerability backlog. It is the subset someone is already using.

A severe incident is one that negatively affects, or is capable of affecting, the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions — or that has led, or could lead, to malicious code being introduced or executed in the product or in a user’s network.

StageVulnerabilitySevere incident
Early warning24 hours from becoming aware24 hours from becoming aware
Notification72 hours from becoming aware72 hours from becoming aware
Final report14 days after a corrective or mitigating measure is availableone month after the 72-hour notification
The three stages of an Article 14 notification, and the moment each one is measured from.

Note where the final report’s clock starts. For a vulnerability it runs from the availability of a fix, not from discovery — so a vulnerability you cannot fix does not start it. For an incident it runs from your own 72-hour notification, not from awareness.

It binds you, not only your customers

A manufacturer is “a natural or legal person who develops or manufactures products with digital elements… and markets them under its name or trademark, whether for payment, monetisation or free of charge.”

There is no establishment test in that definition. The territorial hook is the product being made available on the Union market. An Indian software company selling — or giving away — a product under its own name to users in the EU is a manufacturer for CRA purposes.

This is the sharpest difference between the CRA and the instruments in our companion piece on NIS2, DORA and Reg S-P. Those reach an Indian supplier through its clients’ contracts. The CRA reaches it directly.

The trap: it applies to what you shipped years ago

Article 69(2) looks like relief. Products placed on the market before 11 December 2027 are subject to the Regulation only if they undergo a substantial modification after that date.

Article 69(3) takes it straight back for this one duty:

Every in-scope product you have ever shipped into the EU and still support is inside Article 14 from 11 September 2026. “Our product predates the CRA” is true, and it does not help here.

Which CSIRT, when you have no EU office

Article 14(7) sets a cascade. If you have no main establishment in the Union, you report through the end-point of the coordinating CSIRT in the Member State determined by the first of these that applies:

  • where your authorised representative for the most products is established;
  • failing that, where the importer placing the most of your products is established;
  • failing that, where the distributor making the most available is established;
  • failing that, where you have the most users.

For a firm selling direct with no representative and no importer, the answer usually falls to the last limb — the Member State with the most users — which is a number you should be able to produce before you need it, rather than during an incident.

Notifications go through the single reporting platform ENISA builds under Article 16. ENISA’s own guidance says the platform is operational from 11 September 2026 for exactly these mandatory Article 14 notifications; voluntary reporting under Article 15 is not available at launch. If the platform is down, ENISA’s position is to wait and file when it returns — you may contact your CSIRT directly if the situation demands it, but the notification must still go through the platform afterwards.

What the penalty position actually is

Article 64 puts failures under Articles 13 and 14 in the top band: administrative fines up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher.

There is a wrinkle worth stating precisely, because it is easy to misread in both directions. Article 64 is not among the articles that apply early — so on the face of Article 71(2), the Regulation’s penalty framework arrives with the rest on 11 December 2027, while the Article 14 duty is live from 11 September 2026.

That is not a grace period, and treating it as one would be a mistake. The obligation is legally applicable from 11 September, every notification is logged by a CSIRT and by ENISA, and a manufacturer’s reporting record from 2026 is exactly what a market surveillance authority will look at in 2028. Take your own legal advice on the sanction question; do not take it as licence to skip the filing.

What to have in place

  • Decide whether you are a manufacturer. Do you market a product with digital elements, under your own name, to anyone in the EU — paid or free?
  • Know your CSIRT before you need it. Walk the Article 14(7) cascade now and write the answer down.
  • Separate “actively exploited” from the rest of the backlog. The 24-hour clock starts on evidence of exploitation, so someone has to be able to make that call at speed.
  • Check your legacy inventory. Article 69(3) means every supported product counts, not only what you ship after 2027.
  • Rehearse 24 hours. An early warning is a short notification, but it is very short notice.

Articles 3, 14, 64, 69 and 71 read from the text of Regulation (EU) 2024/2847 on EUR-Lex. Platform scope at launch from ENISA’s Single Reporting Platform guidance.

Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

When does the EU Cyber Resilience Act start applying?
Regulation (EU) 2024/2847 applies in general from 11 December 2027. Two parts apply earlier: Chapter IV, on conformity assessment bodies, from 11 June 2026, and Article 14, the reporting obligation, from 11 September 2026.
Does the Cyber Resilience Act apply to a company outside the EU?
Yes. The Cyber Resilience Act defines a manufacturer by what it markets under its own name and where the product is made available, not by where the company is established. A non-EU company placing a product with digital elements on the EU market — for payment, for monetisation, or free of charge — is a manufacturer under the Regulation.
What must a manufacturer report under Article 14, and how fast?
An early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident, a fuller notification within 72 hours, and a final report either 14 days after a corrective or mitigating measure becomes available (for a vulnerability) or one month after the 72-hour notification (for an incident). All go simultaneously to the coordinating CSIRT and to ENISA through the single reporting platform established under Article 16.
Does Article 14 apply to products sold before the CRA takes effect?
Yes. Article 69(2) exempts products placed on the market before 11 December 2027 from the Regulation’s requirements unless they undergo a substantial modification, but Article 69(3) expressly disapplies that exemption for Article 14. The reporting obligation covers every in-scope product already on the market.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating