Operational notes Security

Cyber Resilience Act: the reporting clock starts on 11 September

4 min read

Close-up of an electronic circuit board
Every connected product now comes with a reporting duty attached. Stopwatch included.

The Cyber Resilience Act — Regulation (EU) 2024/2847 on the cybersecurity of products with digital elements — applies in full from 11 December 2027. But one part starts much earlier, and less than two months remain: from 11 September 2026, the reporting obligations of Article 14 kick in. From that day, manufacturers of products with digital elements must notify actively exploited vulnerabilities and severe incidents affecting the security of their products. Against the clock. And — the point almost no one has picked up on — for products already on the market as well.

Who is covered

“Products with digital elements” is a deliberately broad definition: hardware and software that is connected or connectable — machinery with an on-board controller, IoT devices, equipment, gateways, applications. For the Emilia manufacturing fabric, the implication is direct: anyone producing connected machinery, on-board electronics, biomedical devices, automation systems is a manufacturer under the CRA. And anyone integrating third-party digital components into their own products is still accountable to their customers: the supply chain is no excuse — as with the NIS2 Directive, it is part of the perimeter.

What Article 14 actually requires

From the moment a manufacturer becomes aware of an actively exploited vulnerability or a severe incident:

  • within 24 hours: an early warning;
  • within 72 hours: a full notification, with the information available;
  • within 14 days of the corrective measure (vulnerabilities) or within one month (severe incidents): a final report.

Reports go through the single European platform, due to become operational by that same date of 11 September 2026. Note the wording “becomes aware”: the clock does not start when you decide it does — it starts when you should have known. Which shifts the problem to where it actually lies.

The real requirement: noticing it

As with the NIS2 Directive, the visible compliance step — notification — is the easy part. The hard part is the ability to notice: knowing which software components sit inside every product sold (the software bill of materials), receiving and triaging vulnerability reports, working out in hours — not weeks — whether a vulnerability is present in your products and whether it is being exploited. A manufacturer with no vulnerability management process will not meet the 24-hour deadline even if it wants to: not through negligence in reporting, but through blindness further upstream.

It is the same pattern we have been describing for months: before compliance comes visibility over your own systems and your own data — the inventory, continuous monitoring, a response process with clear roles. Build it once and you reuse it for the NIS2 Directive, the CRA and the EU AI Act together: three regulations, one single piece of groundwork. And this is where operational AI pays off most: agents that read vulnerability feeds and product telemetry and bring to human attention only what genuinely concerns your own code and your own versions.

Between now and 11 September: the realistic checklist

  1. Check whether you are a manufacturer under the CRA: hardware or software products, connected or connectable, sold in the EU. If in doubt, the answer is almost always yes.
  2. Build (or complete) the software bill of materials for your products: without knowing what is inside, no report can be filed on time.
  3. Set up a vulnerability intake channel (a mailbox and a coordinated-disclosure policy are enough to start) and a triage process with a named owner.
  4. Run the process once as a test: simulate an exploited vulnerability on a product and time it: awareness → assessment → early warning. If it takes more than 24 hours, you now know with enough runway to fix it.
  5. Put the rest of the CRA on the calendar: security-by-design requirements, vulnerability management across the whole life cycle, CE marking — December 2027 will arrive fast, and manufacturers producing connected equipment are first in line.

Do you manufacture or integrate connected products and want to know whether the 24-hour deadline is within reach? Half an hour with one of our experts to find out before September.

Sources