From 11 September 2026, manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities and severe security incidents within 24 hours of becoming aware of them. Manufacturers placing such products on the EU market are now in scope, regardless of where they are based, and cybersecurity compliance solutions now need to prove it.
View the data behind this chart
| Early Warning | Follow-Up | Final Report | |
|---|---|---|---|
| Deadline | 24 hours | 72 hours | 14 days or 1 month |
| Trigger event | Manufacturer becomes… | Manufacturer becomes… | Corrective or mitigati… |
| Recipient | Coordinating CSIRT | Coordinating CSIRT | Coordinating CSIRT |
Why 11 September 2026 matters for UK suppliers
The Cyber Resilience Act's Article 14 reporting duties became applicable on 11 September 2026, and they don't care where a manufacturer is headquartered. Any company placing products with digital elements on the EU market — hardware, software, connected devices — is now on the hook, subject to the regulation's exemptions, whether it's based in Frankfurt, Manchester or California.
For UK manufacturers and importers who sell into the single market, that means the 24-hour clock is already running on live products in the field, not just on future launches. There's no grace period tied to Brexit or UK headquarters status; if the product reaches an EU customer, the obligation follows it.
The 24/72/14-day reporting clock, explained
Once a manufacturer becomes aware that a vulnerability in its product is being actively exploited, it has 24 hours to file an early warning, followed by a more detailed notification within 72 hours. The same 24-hour and 72-hour steps apply to severe security incidents affecting the product, though the deadline for the final report differs between the two.
Where the timelines diverge is the final report. For an actively exploited vulnerability, that's due within 14 days of a corrective or mitigating measure being made available; for a serious incident, it's one month after the first report was filed. All of these notifications are filed through ENISA's Single Reporting Platform and sent to the coordinating CSIRT determined under the CRA, generally the CSIRT of the member state where the manufacturer has its main establishment, with separate rules determining the coordinator for manufacturers based outside the EU.
Darren Anstee, CTO for security at Netscout, said the structure is designed to force pace without sacrificing quality. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said, adding that faster information-sharing helps organisations put mitigating controls in place while risk is heightened.
Product liability and fines raise the stakes
These reporting duties are classified as core responsibilities under the CRA, which matters because failures to meet them can trigger the regulation's most severe tier of fines — up to €15 million or 2.5 percent of annual turnover, whichever is higher. That's not a slap on the wrist; it's the same ceiling reserved for the most serious breaches under the act.
This is only the opening stage. Most of the CRA's remaining provisions apply from 11 December 2027, including security by design and by default, a ban on default passwords, required security updates, and a conformity assessment before any covered product can carry a CE mark. UK exporters should treat today's reporting duty as the first checkpoint in a longer product liability compliance journey, not an isolated hurdle.

Auditing vendor SLAs before the next incident
The awkward reality for many UK buyers is that their own exposure often runs through a supplier, not a direct CE-marked product they manufacture. If a vendor's disclosure SLA doesn't align with the CRA's 24/72-hour windows, that gap becomes your problem the moment a flaw is exploited in the wild.
Now is the moment to pull existing vendor contracts and check whether notification clauses actually match the regulation's timing, not just general 'reasonable efforts' language. Buyers should understand service level agreements in CRA terms specifically, and route any renegotiation through IT procurement and vendor management rather than treating it as a legal afterthought.
Mapping the software supply chain now, not after a breach
Because the reporting clock starts the moment a manufacturer becomes aware of an issue, there's no time to begin mapping an affected product's components after the fact. Eran Kinsbruner, VP of product marketing at Checkmarx, put it plainly: modern applications are "assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected."
A software bill of materials created at launch is a start, and it becomes a mandatory requirement once most CRA provisions apply in December 2027. But the real work is maintaining that inventory across a product's lifecycle so a vulnerability can be traced to every affected variant within hours, not weeks. UK teams should stress-test their vulnerability management services against that exact scenario.
Navigating overlapping EU rules from the UK
The CRA doesn't arrive in isolation. Heidi Waem, data, privacy and cybersecurity partner at DLA Piper, noted that it lands as organisations are "already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act," turning compliance into a question of coordination across frameworks rather than mastering any single one.
Her colleague John Magee, global co-chair of data, privacy and cybersecurity at the firm, warned that many organisations still wrongly assume the CRA is mainly about consumer IoT gadgets, when its reach extends across a much broader range of products with digital elements. For UK compliance teams already stretched across multiple EU regimes, that miscalculation is exactly the kind of gap that turns into a missed 24-hour deadline — which is why coordinated incident response planning now needs a CRA-specific playbook alongside NIS2 and DORA procedures.
- 01The Register — EU's Cyber Resilience Act starts the 24-hour vulnerability clock · 11 September 2026
- 02The Hacker News — The EU will make you report what it wants to know · 1 August 2026
- 03BleepingComputer — The EU CRA's real question: what shipped, and did you know? · 1 September 2026
- 04Cisco — EU CRA Framework Foundations · 1 September 2026
- 05The Register — EU lawmakers finalize tough cybersecurity rules · 4 December 2023
