UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

EU Cyber Resilience Act 2026: The 24-Hour Reporting Rule

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

The EU Cyber Resilience Act's mandatory reporting rules took effect on 11 September 2026, starting a 24-hour clock for disclosing actively exploited vulnerabilities. For UK vendors selling products with digital elements into the EU — and MSPs that manufacture such products rather than offer pure SaaS or service offerings — the obligation applies regardless of where the company is based.

CRA obligations: from reporting duty to full regime
W0W12W24W36W48W60W70Article 14 reporting…65wSecurity-by-design & CE…5wTotal: 70 weeks end-to-end
View the data behind this chart
CRA obligations: from reporting duty to full regime
PhaseStarts (week)Duration (weeks)
Article 14 reporting duties…065
Security-by-design & CE…655

What actually changed on 11 September 2026

Article 14 of the Cyber Resilience Act became applicable, obliging manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents through ENISA's new Single Reporting Platform, according to The Register. An early warning is due within 24 hours of a manufacturer becoming aware of the issue, followed by a fuller notification within 72 hours.

For UK infrastructure buyers, the practical effect is immediate: manufacturers of in-scope products with digital elements made available in the EU now operate on a compressed disclosure timetable, and failure to comply with that core reporting duty carries the regulation's toughest penalty tier.

Who counts as a manufacturer — and why location doesn't matter

The reporting duty applies to manufacturers of products with digital elements made available in the EU market, irrespective of where those manufacturers are headquartered, per The Register's coverage. That scope is broader than many compliance teams assume. Experts at DLA Piper note that businesses still tend to associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements.

UK vendors and managed service providers exporting equipment, embedded systems or software into EU customers are therefore in scope even without an EU legal entity, with the coordinating national CSIRT determined by separate rules for non-EU manufacturers.

The reporting clock: 24 hours, 72 hours, and the final report

The same 24-hour and 72-hour deadlines apply to both actively exploited vulnerabilities and severe security incidents. Where the timelines diverge is the final report: for a vulnerability, this is due within 14 days of a corrective or mitigating measure becoming available, while for a serious incident it is due one month after the first report was filed.

Manufacturers must also notify affected users about available fixes or mitigations without undue delay. Failures against these core responsibilities can trigger the CRA's highest fine tier — up to €15 million or 2.5 percent of annual turnover, whichever is greater. Netscout's Darren Anstee argues the tight window is a net positive for defenders: "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."

Illustration: EU Cyber Resilience Act 2026: The 24-Hour Reporting Rule

Overlapping regulation: CRA meets NIS2 and the UK's own cyber bill

UK buyers evaluating vendor risk shouldn't treat the CRA in isolation. Experts at DLA Piper note that organisations are already navigating other EU cybersecurity regulations like NIS2, alongside DORA, the Data Act and the AI Act, and are now having to work out how these frameworks interact rather than treating each in isolation.

There's a domestic parallel too: the UK's own Cyber Security and Resilience Bill, currently progressing through Parliament, also proposes reporting obligations that extend to managed service providers, according to The Register's coverage of the bill. Under its current drafting, serious violations could attract daily fines of up to £100,000, separate from turnover-based fines of up to £10 million or 2 percent of worldwide turnover for standard breaches, rising to £17 million or 4 percent of worldwide turnover for the most serious failures — a separate but complementary pressure point for UK-based suppliers and MSPs.

What UK buyers and MSPs should be asking vendors now

In our assessment, the CRA's rules are designed not just to accelerate manufacturers' responses to security flaws, but to make proactive asset visibility a precondition of compliance: because the reporting clock starts the moment a manufacturer becomes aware of a flaw, vendors cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a standing, accurate map of what shipped where and when — which is exactly why vulnerability management solutions and understanding attack surface management matter more than ever for procurement due diligence.

Checkmarx's Eran Kinsbruner frames the underlying challenge well: modern products are assembled from proprietary code, open-source packages, third-party components and increasingly AI models, all interconnected, and organisations need visibility into those dependencies and the risks they introduce. UK buyers should be pressing suppliers on their incident response capabilities and asking directly how they'll prove, in an audit, exactly when they first learned of an exploited flaw.

Reporting clocks compared
CRA FlawCRA IncidentUK CSR BillInitial report24 hours24 hours24 hoursFull notification72 hours72 hours72 hoursFinal report14 days*1 monthTBCMax penalty€15m/2.5%€15m/2.5%£100k/day (+turnover…
View the data behind this chart
Reporting clocks compared
CRA FlawCRA IncidentUK CSR Bill
Initial report24 hours24 hours24 hours
Full notification72 hours72 hours72 hours
Final report14 days*1 monthTBC
Max penalty€15m/2.5%€15m/2.5%£100k/day (+turnover…

The road to December 2027

Today's reporting duties are only the first wave. Most remaining CRA provisions become applicable on 11 December 2027, when manufacturers of in-scope products must also embed security by design and default — no default passwords, and security updates that are no longer optional. In-scope products will additionally need to pass the applicable conformity assessment route before carrying a CE mark, and software bills of materials become a mandatory requirement for in-scope manufacturers rather than a best practice.

For UK infrastructure teams, this is the moment to get ahead rather than scramble later. Building the asset visibility, patching discipline and supplier questioning habits now — through IT compliance services and a properly resourced comprehensive cybersecurity services programme — will make the 2027 deadline far less disruptive than treating it as a fresh shock.

Share
Key takeaways
  • CRA Article 14 reporting duties took effect 11 September 2026, with 24-hour early warnings and 72-hour full notifications for exploited flaws and severe incidents.
  • Obligations apply to UK vendors and MSPs selling products with digital elements into the EU regardless of where they're based, filed via ENISA's Single Reporting Platform and routed to the relevant CSIRT.
  • Failing core reporting duties can trigger the CRA's top fine tier: up to €15 million or 2.5% of annual turnover.
  • The UK's parallel Cyber Security and Resilience Bill also proposes reporting obligations covering managed service providers, adding a domestic layer to the same compliance problem.
Frequently asked

FAQs — EU Cyber Resilience Act 2026

Does the CRA apply to UK vendors without an EU entity?

Yes. The reporting duty applies to manufacturers of products with digital elements made available in the EU market regardless of where the manufacturer is based, with a coordinating CSIRT determined by separate rules for non-EU firms.

What's the difference between the CRA deadline and the UK CSR Bill?

The CRA sets 24-hour initial and 72-hour full reporting deadlines for in-scope manufacturers. The UK's Cyber Security and Resilience Bill, still progressing through Parliament, also extends obligations to managed service providers and carries its own penalty structure — daily fines of up to £100,000, plus separate turnover-based fines of up to £10 million or 2% of worldwide turnover for standard breaches (rising to £17 million or 4% for the most serious failures) — distinct from the CRA's EU-based fines.

What happens if a manufacturer misses the 24-hour window?

The reporting duties are classed as core responsibilities under the CRA, so non-compliance can lead to the regulation's maximum fine tier of up to €15 million or 2.5% of annual turnover, whichever is higher.

When do the CRA's remaining requirements take effect?

Most other CRA provisions become applicable on 11 December 2027, introducing mandatory security-by-design defaults, a ban on default passwords, mandatory SBOMs, and conformity assessments before in-scope products can carry a CE mark.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111