EU manufacturers of products with digital elements must begin meeting Cyber Resilience Act (CRA) Article 14 reporting obligations on 11 September 2026, before the regulation becomes broadly applicable in December 2027. They must report reliably evidenced active exploitation of vulnerabilities affecting their products, as well as severe security incidents involving those products.
The process requires an early notification within 24 hours, a more detailed notification within 72 hours, and a final report within one month of the initial notice. Requirements extend to legacy products already on the EU market and to exploited vulnerabilities in third-party software or hardware components that affect a manufacturer’s product; organizations need current product and component inventories, defined escalation paths, and coordinated vulnerability-management, incident-response, and regulatory-reporting procedures.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
ENISA launched and began operating the Cyber Resilience Act Single Reporting Platform, a common electronic system for manufacturers to report actively exploited vulnerabilities and severe incidents. Notifications are sent to a designated coordinating CSIRT, made available to ENISA, and disseminated to relevant Member State CSIRTs.
The European Union Cyber Resilience Act entered into force, beginning the transition toward its phased application and manufacturer cybersecurity requirements for products with digital elements.
The European Parliament and the Council adopted Regulation (EU) 2024/2847, establishing the EU Cyber Resilience Act and its horizontal cybersecurity requirements for products with digital elements placed on the EU market.
The European Commission published new guidance intended to support timely implementation of the EU Cyber Resilience Act.
EU Cyber Resilience Act Article 14 reporting obligations begin for manufacturers of products with digital elements, requiring reporting of reliably evidenced active exploitation and severe product-security incidents through staged notifications.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
22 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcevulncheck.com
Open sourcedigital-strategy.ec.europa.eu
Open sourcetheregister.com
Open sourceeur-lex.europa.eu
Open sourceeur-lex.europa.eu
Open sourcedigital-strategy.ec.europa.eu
Open sourceec.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.