UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

EU Cyber Resilience Act 2026: The 24-Hour Reporting Clock

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

From 11 September 2026, manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities and severe security incidents within 24 hours of becoming aware of them. Manufacturers placing such products on the EU market are now in scope, regardless of where they are based, and cybersecurity compliance solutions now need to prove it.

CRA vulnerability reporting stages
Early WarningFollow-UpFinal ReportDeadline24 hours72 hours14 days or 1 monthTrigger eventManufacturer becomes…Manufacturer becomes…Corrective or mitigati…RecipientCoordinating CSIRTCoordinating CSIRTCoordinating CSIRT
View the data behind this chart
CRA vulnerability reporting stages
Early WarningFollow-UpFinal Report
Deadline24 hours72 hours14 days or 1 month
Trigger eventManufacturer becomes…Manufacturer becomes…Corrective or mitigati…
RecipientCoordinating CSIRTCoordinating CSIRTCoordinating CSIRT

Why 11 September 2026 matters for UK suppliers

The Cyber Resilience Act's Article 14 reporting duties became applicable on 11 September 2026, and they don't care where a manufacturer is headquartered. Any company placing products with digital elements on the EU market — hardware, software, connected devices — is now on the hook, subject to the regulation's exemptions, whether it's based in Frankfurt, Manchester or California.

For UK manufacturers and importers who sell into the single market, that means the 24-hour clock is already running on live products in the field, not just on future launches. There's no grace period tied to Brexit or UK headquarters status; if the product reaches an EU customer, the obligation follows it.

The 24/72/14-day reporting clock, explained

Once a manufacturer becomes aware that a vulnerability in its product is being actively exploited, it has 24 hours to file an early warning, followed by a more detailed notification within 72 hours. The same 24-hour and 72-hour steps apply to severe security incidents affecting the product, though the deadline for the final report differs between the two.

Where the timelines diverge is the final report. For an actively exploited vulnerability, that's due within 14 days of a corrective or mitigating measure being made available; for a serious incident, it's one month after the first report was filed. All of these notifications are filed through ENISA's Single Reporting Platform and sent to the coordinating CSIRT determined under the CRA, generally the CSIRT of the member state where the manufacturer has its main establishment, with separate rules determining the coordinator for manufacturers based outside the EU.

Darren Anstee, CTO for security at Netscout, said the structure is designed to force pace without sacrificing quality. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said, adding that faster information-sharing helps organisations put mitigating controls in place while risk is heightened.

Product liability and fines raise the stakes

These reporting duties are classified as core responsibilities under the CRA, which matters because failures to meet them can trigger the regulation's most severe tier of fines — up to €15 million or 2.5 percent of annual turnover, whichever is higher. That's not a slap on the wrist; it's the same ceiling reserved for the most serious breaches under the act.

This is only the opening stage. Most of the CRA's remaining provisions apply from 11 December 2027, including security by design and by default, a ban on default passwords, required security updates, and a conformity assessment before any covered product can carry a CE mark. UK exporters should treat today's reporting duty as the first checkpoint in a longer product liability compliance journey, not an isolated hurdle.

Illustration: EU Cyber Resilience Act 2026: The 24-Hour Reporting Clock

Auditing vendor SLAs before the next incident

The awkward reality for many UK buyers is that their own exposure often runs through a supplier, not a direct CE-marked product they manufacture. If a vendor's disclosure SLA doesn't align with the CRA's 24/72-hour windows, that gap becomes your problem the moment a flaw is exploited in the wild.

Now is the moment to pull existing vendor contracts and check whether notification clauses actually match the regulation's timing, not just general 'reasonable efforts' language. Buyers should understand service level agreements in CRA terms specifically, and route any renegotiation through IT procurement and vendor management rather than treating it as a legal afterthought.

Mapping the software supply chain now, not after a breach

Because the reporting clock starts the moment a manufacturer becomes aware of an issue, there's no time to begin mapping an affected product's components after the fact. Eran Kinsbruner, VP of product marketing at Checkmarx, put it plainly: modern applications are "assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected."

A software bill of materials created at launch is a start, and it becomes a mandatory requirement once most CRA provisions apply in December 2027. But the real work is maintaining that inventory across a product's lifecycle so a vulnerability can be traced to every affected variant within hours, not weeks. UK teams should stress-test their vulnerability management services against that exact scenario.

Navigating overlapping EU rules from the UK

The CRA doesn't arrive in isolation. Heidi Waem, data, privacy and cybersecurity partner at DLA Piper, noted that it lands as organisations are "already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act," turning compliance into a question of coordination across frameworks rather than mastering any single one.

Her colleague John Magee, global co-chair of data, privacy and cybersecurity at the firm, warned that many organisations still wrongly assume the CRA is mainly about consumer IoT gadgets, when its reach extends across a much broader range of products with digital elements. For UK compliance teams already stretched across multiple EU regimes, that miscalculation is exactly the kind of gap that turns into a missed 24-hour deadline — which is why coordinated incident response planning now needs a CRA-specific playbook alongside NIS2 and DORA procedures.

Share
Key takeaways
  • CRA Article 14 reporting duties are live as of 11 September 2026 — UK firms selling into the EU are already covered, regardless of Brexit status.
  • Manufacturers must file an early warning within 24 hours, a detailed notice within 72 hours, and a final report within 14 days (vulnerabilities) or one month (incidents).
  • Failing these core obligations can trigger fines up to €15 million or 2.5% of global turnover — the CRA's top penalty tier.
  • Full security-by-design, SBOM and CE-marking rules follow on 11 December 2027, giving buyers a defined runway to audit vendor SLAs now.
Frequently asked

FAQs — EU Cyber Resilience Act 2026

Does the CRA's 24-hour reporting rule apply to UK-only manufacturers?

It applies to any manufacturer placing products with digital elements on the EU market, regardless of where the company is based, so UK manufacturers and importers selling into the EU are in scope subject to the regulation's exemptions.

What has to be reported within 24 hours?

An early warning about an actively exploited vulnerability or a severe security incident affecting a product with digital elements, submitted via ENISA's Single Reporting Platform to the relevant coordinating CSIRT.

What comes after the 24-hour report?

A more detailed notification is due within 72 hours, and a final report follows within 14 days of a fix being made available for a vulnerability, or one month after the first report for a serious incident.

What changes for manufacturers in December 2027?

Most remaining CRA provisions apply from 11 December 2027, including mandatory SBOMs, a ban on default passwords, ongoing security updates, and conformity assessment before a product can carry a CE mark.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111