Skip to main content

The EU Cyber Resilience Act has moved into a significant new phase.

Since 11 September 2026, manufacturers of products with digital elements covered by the CRA have been required to report actively exploited vulnerabilities and severe incidents affecting product security. For organisations affected, this is no longer simply a future compliance consideration: the reporting process is now operational, with an initial notification required within 24 hours and a fuller notification within 72 hours of becoming aware of a reportable event.

The change also matters to UK-based technology companies. The CRA applies to products made available on the EU market, rather than simply to organisations established within the EU. A UK manufacturer selling an in-scope software or hardware product into the EU can therefore have CRA obligations even though the business itself is based in the UK.

The reporting obligation is now live


The European Union Agency for Cybersecurity (ENISA) launched the CRA Single Reporting Platform (SRP) on 11 September 2026.

The platform provides a single mechanism through which manufacturers can report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. A notification is submitted through the platform and routed to the relevant national CSIRT, with the information also made available to ENISA subject to the CRA's provisions.

The immediate reporting requirements are:

  • Within 24 hours: an early warning after becoming aware of an actively exploited vulnerability or severe incident.

  • Within 72 hours: a more detailed notification.

  • Final report: for an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, within one month of the 72-hour notification.

These are deliberately compressed timescales. The practical challenge is therefore not simply knowing that a report must eventually be made. It is having the processes, people, information and communications infrastructure in place to determine whether an event is reportable and act within hours.

What counts as a product?


The CRA has a broad scope. "Products with digital elements" encompasses hardware and software products, as well as certain remote data processing solutions and separately marketed components.

The regulation is concerned with products made available on the EU market where their intended purpose or reasonably foreseeable use involves a direct or indirect logical or physical data connection to a device or network.

That means the implications extend well beyond traditional cybersecurity products. Software products, connected devices, components and other digitally enabled products can potentially fall within scope.

The CRA's broader cybersecurity requirements will become fully applicable on 11 December 2027, but the reporting obligations under Article 14 have already started. Importantly, the reporting provisions apply to products made available on the EU market, including products placed on the market before the CRA's full application date.

Why UK companies need to pay attention


For UK manufacturers and software companies, the important distinction is between where the company is based and where its product is placed on the market.

A UK business does not escape the CRA simply because it is outside the EU. If it manufactures an in-scope product and makes that product available on the EU market, the CRA can apply.

That has several practical consequences for UK organisations:

1. Incident response needs to include regulatory reporting

Existing incident response procedures may focus on containing an attack, investigating what happened, restoring services and communicating with customers. CRA compliance introduces another requirement: rapidly assessing whether a product vulnerability or incident meets the reporting threshold.

2. The 24-hour clock changes the operational requirement

Organisations need to be able to establish when they became sufficiently aware of a reportable event and retain evidence of the relevant assessment and decisions. ENISA's guidance makes clear that the reporting process involves successive stages rather than a single notification.

3. Technical, legal and communications teams need to work together

A report may require information from security, engineering, product, legal and incident-response teams. Those people may also be operating under pressure during an active cyber incident.

The challenge is therefore partly technical — but also organisational.

4. The requirement extends beyond the initial report

The process does not end when the 24-hour notification is submitted. Organisations need to maintain the incident record, provide the subsequent 72-hour notification and complete the relevant final reporting process.

The wider resilience implication


The CRA is ultimately about more than compliance paperwork.

It reflects a broader shift towards treating cybersecurity as an ongoing responsibility across the lifecycle of digital products. Manufacturers are expected to manage vulnerabilities effectively, maintain security support and respond when products are affected by serious security events.

The reporting mechanism also creates a more coordinated flow of information between manufacturers, national CSIRTs and ENISA. Once a notification is submitted, the coordinating CSIRT can disseminate relevant information to other Member States where the affected product has been made available.

That makes the quality and speed of the initial response increasingly important.

What should organisations be doing now?


For manufacturers potentially within scope, the immediate question should not simply be "Are we CRA compliant?"

It should be:

"If a serious vulnerability is discovered at 10am tomorrow, can we establish what happened, decide whether it is reportable, assemble the required information and communicate securely with the right people within 24 hours?"

That means reviewing:

  • Which products and components are within CRA scope.
  • Who is responsible for determining whether an event is reportable.
  • How the organisation defines and records the point at which it becomes aware of an incident or actively exploited vulnerability.
  • How technical, legal, product and communications teams coordinate during a major incident.
  • Who has responsibility for making the notification through the Single Reporting Platform.
  • How subsequent 72-hour and final reports will be managed.
  • How incident information and decisions will be securely documented and retained.

The CRA's main cybersecurity requirements do not become fully applicable until December 2027. But the reporting obligation has already arrived.

For organisations operating across the UK and EU, that makes incident response readiness a current operational requirement, not simply a future compliance project.

Edward Jones
Written byEdward Jones
17 Sep 2026
A digital marketing expert with 10+ years experience across the full range of disciplines. Edward has an extensive history as a writer, with more than 300+ published articles across the technology and digital publishing sectors.