As of September 11, 2026, manufacturers of products with digital elements placed on the European Union market must report actively exploited vulnerabilities and significant security incidents affecting their products.
While the bulk of the Cyber Resilience Act (Regulation (EU) 2024/2847, or CRA) will not apply until December 11, 2027, these reporting obligations are mandatory effective immediately.
Which products and services are covered by the CRA ?
The scope of the CRA is very broad. It applies to all "products with digital elements" placed on the European Union market.
Some examples, though this list is not exhaustive:
- Standalone software and applications: operating systems, application software, mobile apps, password managers, web browsers, etc.
- Hardware and embedded components: microprocessors, microcontrollers, smart cards, embedded systems.
- Network equipment: routers, switches, modems, firewalls, VPNs, remote access systems.
- Internet of Things (IoT) & consumer goods: security cameras, smart locks, home automation devices, smartwatches, interactive toys with cameras/microphones/geolocation.
- Industrial systems, such as industrial control systems (ICS, SCADA).
- Remote data processing solutions integrated into a product or essential to its operation.
The CRA does not apply to products already covered by other regulations with equivalent requirements, such as:
- Medical devices;
- Civil aviation and automotive equipment;
- Products developed exclusively for defense or national security purposes;
- Non-profit open-source software, unless it is integrated into a commercial product.
CRA: what changes on September 11
Starting September 11, 2026, two categories of events must be reported to the authorities:
- Actively exploited vulnerabilities contained within a product, meaning those for which there is reliable evidence that a malicious actor has exploited them.
- Serious incidents that have an impact on the security of the product.
The notification timeline is tight and unfolds in three stages:
- When a manufacturer becomes aware of an actively exploited vulnerability or a serious incident, they must submit an early warning within a maximum of 24 hours.
- A more comprehensive notification must follow within 72 hours. It includes, in particular, available information on the nature of the event, its initial assessment, and any corrective or mitigation measures already taken or recommended to users.
- For an actively exploited vulnerability, A final report must be provided no later than 14 days after the implementation of a corrective measure. For a serious incident, the report describing the resolution procedures must be submitted within one month.
Reports are submitted via the CRA Single Reporting Platform, operated by ENISA and linked to national CSIRTs.
Failure to comply with the obligations set out in Article 14 may expose companies to administrative fines of up to 15 million euros or 2.5% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Operational impact: detect, qualify, and escalate
The challenge is organizational rather than regulatory. You can only report what you are capable of detecting, and detecting quickly. This requires having several building blocks in place:
- An accurate inventory of products, their components, and their versions. Without a reliable map of what is deployed and what makes up each product, it is impossible to determine within a few hours whether a vulnerability affects you.
- A capacity for rapid incident qualification : distinguishing between a theoretical vulnerability and one that is actually being exploited, and assessing the severity of an incident. This qualification determines whether or not the reporting obligation is triggered.
- A clearly established escalation chain: who detects, who analyzes, who decides to notify, and who transmits the information? With 24- and 72-hour deadlines, these responsibilities must be defined before an incident occurs. Furthermore, other potentially overlapping obligations must also be taken into account, such as NIS2 or GDPR, depending on the nature of the incident.
Equipping for continuous vulnerability exposure management
Beyond regulatory compliance, this obligation highlights an operational difficulty at a time when the number of vulnerabilities is exploding: it is impossible to quickly assess the impact of a vulnerability without knowing precisely which assets, software, and components are involved.
In practical terms, this calls for the implementation of solutions capable of:
- Mapping digital assets (products, components, versions) in a continuous and reliable manner, to know instantly what is exposed.
- Monitoring CVEs and correlating published vulnerabilities in real time with the digital assets being used and deployed.
- Prioritize vulnerability remediation based on business criticality to focus efforts where risk is highest, rather than addressing every alert.
- Automate patch management, where operational context allows, to shorten the time between vulnerability detection and remediation—the same timeframe that now triggers the final reporting obligation.
The CRA does more than just create a new obligation. It accelerates the transition from reactive vulnerability management to continuous vulnerability exposure management.
