The EU Cyber Resilience Act's mandatory reporting rules took effect on 11 September 2026, starting a 24-hour clock for disclosing actively exploited vulnerabilities. For UK vendors selling products with digital elements into the EU — and MSPs that manufacture such products rather than offer pure SaaS or service offerings — the obligation applies regardless of where the company is based.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Article 14 reporting duties… | 0 | 65 |
| Security-by-design & CE… | 65 | 5 |
What actually changed on 11 September 2026
Article 14 of the Cyber Resilience Act became applicable, obliging manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents through ENISA's new Single Reporting Platform, according to The Register. An early warning is due within 24 hours of a manufacturer becoming aware of the issue, followed by a fuller notification within 72 hours.
For UK infrastructure buyers, the practical effect is immediate: manufacturers of in-scope products with digital elements made available in the EU now operate on a compressed disclosure timetable, and failure to comply with that core reporting duty carries the regulation's toughest penalty tier.
Who counts as a manufacturer — and why location doesn't matter
The reporting duty applies to manufacturers of products with digital elements made available in the EU market, irrespective of where those manufacturers are headquartered, per The Register's coverage. That scope is broader than many compliance teams assume. Experts at DLA Piper note that businesses still tend to associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements.
UK vendors and managed service providers exporting equipment, embedded systems or software into EU customers are therefore in scope even without an EU legal entity, with the coordinating national CSIRT determined by separate rules for non-EU manufacturers.
The reporting clock: 24 hours, 72 hours, and the final report
The same 24-hour and 72-hour deadlines apply to both actively exploited vulnerabilities and severe security incidents. Where the timelines diverge is the final report: for a vulnerability, this is due within 14 days of a corrective or mitigating measure becoming available, while for a serious incident it is due one month after the first report was filed.
Manufacturers must also notify affected users about available fixes or mitigations without undue delay. Failures against these core responsibilities can trigger the CRA's highest fine tier — up to €15 million or 2.5 percent of annual turnover, whichever is greater. Netscout's Darren Anstee argues the tight window is a net positive for defenders: "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."

Overlapping regulation: CRA meets NIS2 and the UK's own cyber bill
UK buyers evaluating vendor risk shouldn't treat the CRA in isolation. Experts at DLA Piper note that organisations are already navigating other EU cybersecurity regulations like NIS2, alongside DORA, the Data Act and the AI Act, and are now having to work out how these frameworks interact rather than treating each in isolation.
There's a domestic parallel too: the UK's own Cyber Security and Resilience Bill, currently progressing through Parliament, also proposes reporting obligations that extend to managed service providers, according to The Register's coverage of the bill. Under its current drafting, serious violations could attract daily fines of up to £100,000, separate from turnover-based fines of up to £10 million or 2 percent of worldwide turnover for standard breaches, rising to £17 million or 4 percent of worldwide turnover for the most serious failures — a separate but complementary pressure point for UK-based suppliers and MSPs.
What UK buyers and MSPs should be asking vendors now
In our assessment, the CRA's rules are designed not just to accelerate manufacturers' responses to security flaws, but to make proactive asset visibility a precondition of compliance: because the reporting clock starts the moment a manufacturer becomes aware of a flaw, vendors cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a standing, accurate map of what shipped where and when — which is exactly why vulnerability management solutions and understanding attack surface management matter more than ever for procurement due diligence.
Checkmarx's Eran Kinsbruner frames the underlying challenge well: modern products are assembled from proprietary code, open-source packages, third-party components and increasingly AI models, all interconnected, and organisations need visibility into those dependencies and the risks they introduce. UK buyers should be pressing suppliers on their incident response capabilities and asking directly how they'll prove, in an audit, exactly when they first learned of an exploited flaw.
View the data behind this chart
| CRA Flaw | CRA Incident | UK CSR Bill | |
|---|---|---|---|
| Initial report | 24 hours | 24 hours | 24 hours |
| Full notification | 72 hours | 72 hours | 72 hours |
| Final report | 14 days* | 1 month | TBC |
| Max penalty | €15m/2.5% | €15m/2.5% | £100k/day (+turnover… |
The road to December 2027
Today's reporting duties are only the first wave. Most remaining CRA provisions become applicable on 11 December 2027, when manufacturers of in-scope products must also embed security by design and default — no default passwords, and security updates that are no longer optional. In-scope products will additionally need to pass the applicable conformity assessment route before carrying a CE mark, and software bills of materials become a mandatory requirement for in-scope manufacturers rather than a best practice.
For UK infrastructure teams, this is the moment to get ahead rather than scramble later. Building the asset visibility, patching discipline and supplier questioning habits now — through IT compliance services and a properly resourced comprehensive cybersecurity services programme — will make the 2027 deadline far less disruptive than treating it as a fresh shock.
- 01The Register — EU's Cyber Resilience Act starts the 24-hour vulnerability clock · 11 September 2026
- 02BleepingComputer — The EU CRA's real question: what shipped, and when did you know · 11 September 2026
- 03The Register — Peers ask why UK cyber bill leaves execs off the personal liability hook · 7 September 2026
- 04bleepingcomputer.com
- 05theregister.com
- 06bleepingcomputer.com
- 07bleepingcomputer.com
