The Cyber Resilience Act (Regulation (EU) 2024/2847) has been in force since December 2024. Since 11 September 2026 the first duties apply: manufacturers must report certain vulnerabilities and security incidents. To my knowledge, the remaining requirements, such as those for development and conformity assessment, apply from 11 December 2027.

What has applied since September

Manufacturers must report actively exploited vulnerabilities and severe security incidents that affect a product's security. That is narrower than "every vulnerability found" — some summaries online oversimplify this. When in doubt, the regulation's text governs.

The reporting deadlines at a glance

  • 24 hours: early warning after becoming aware of active exploitation
  • 72 hours: notification with further details on the product, the nature of the attack and first mitigations
  • Final report: for vulnerabilities, within 14 days of a corrective measure becoming available; for incidents, within one month

Reports go through a single reporting platform to the competent CSIRT and ENISA. Violations of the core requirements can be fined up to EUR 15 million or 2.5% of worldwide annual turnover.

Who is affected

The CRA covers "products with digital elements" on the EU market: hardware and software connected directly or indirectly to other devices or networks. Duties apply to manufacturers, but also to importers and distributors. Pure online services (SaaS) are generally out of scope, while remote data processing tied to a product is in scope. Borderline cases should be assessed legally.

If you cannot triage a vulnerability within 24 hours, you do not have vulnerability management — you have a time problem.

What manufacturers should do now

  • Maintain an inventory of all components, including third-party ones (software bill of materials, SBOM)
  • Define responsibilities and deputies for reporting
  • Provide a contact route for external security researchers, for example a security.txt
  • Have products tested regularly by independent penetration tests before third parties find the flaw

Conclusion

The CRA turns security from an option into an obligation — with deadlines only a prepared process can meet. Anyone selling hardware or software in the EU should clarify now whether they are affected and who acts within 24 hours when it matters.

Note: This article is not legal advice. The text of the regulation is authoritative.