Asia-Pacific hardware and software companies that make products with digital elements available on the European Union market are now required to report actively exploited vulnerabilities and severe incidents impacting product security under the bloc’s Cyber Resilience Act (CRA).
The reporting obligations took effect on Sept. 11, 2026, more than a year before the CRA becomes fully applicable on Dec. 11, 2027.
The CRA requires manufacturers to notify actively exploited vulnerabilities and severe incidents having an impact on the security of their products with digital elements.
Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, followed by a full notification within 72 hours.
A final report must be submitted no later than 14 days after a corrective measure is available for actively exploited vulnerabilities. For severe incidents, the final report is due within one month from the 72-hour notification.
Manufacturers are required to report only once through the CRA Single Reporting Platform (SRP), established by the European Union Agency for Cybersecurity (ENISA) in close cooperation with the CSIRT Network.
The SRP became operational on Sept. 11, 2026.
The notification is addressed to the Computer Security Incident Response Team (CSIRT) where the manufacturer has its main establishment and, unless particularly exceptional circumstances apply, the information is made available simultaneously to ENISA.
The CSIRT initially receiving the notification will share the notification without delay with all other CSIRTs in countries where the product with digital elements has been made available.
In exceptional circumstances and based on justified cybersecurity-related grounds, the CSIRT may decide to delay dissemination to other CSIRTs.
The European Commission adopted a delegated act on Dec. 11, 2025, further specifying the terms and conditions for applying those cybersecurity-related grounds.
The reporting provisions apply to products with digital elements made available on the Union market, including products placed on the market before the CRA becomes fully applicable.
The broader CRA covers hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network, subject to exclusions and specific rules under the regulation.
The CRA entered into force on Dec. 10, 2024 and becomes fully applicable on Dec. 11, 2027. The vulnerability and incident reporting obligations were scheduled to apply earlier.
Open-source software stewards will also be subject to reporting obligations under Article 24(3) of the CRA. In accordance with Article 71(2), those obligations will apply from Dec. 11, 2027.
ENISA has published resources on how to use the CRA SRP, including frequently asked questions, user guidance, a CRA SRP glossary and training materials.
Further information on the reporting obligations is contained in the European Commission’s guidance on the CRA and its frequently asked questions on CRA implementation.