8 September 2026
Share Print

CRA reporting obligations - Is your organisation ready for 11 September?

To The Point
(8 min read)

The EU Cyber Resilience Act (CRA) introduces a further layer of EU cybersecurity obligations, imposing requirements on manufacturers, importers and distributors of products with digital elements. The first obligations for manufacturers will start applying from 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents to the supervisory authorities. Read our overview of which businesses are caught by these new obligations, what must be reported and within what deadlines, and the steps in-scope organisations should be taking now.

The CRA obligations to report vulnerabilities and incidents become applicable on 11 September 2026, while the remainder of the CRA provisions become applicable on 11 December 2027. Most compliance programmes have been built around the later date, when the product-facing requirements – security by design, technical documentation, conformity assessment and CE marking – start to apply.

However, the CRA reporting obligations apply earlier and reach further than many manufacturers expect.

Who is caught
What must be reported
Products already on the market
Vulnerabilities in third-party components
The deadlines: 24 hours, 72 hours, 14 days and one month
How to report: the Single Reporting Platform
Overlapping reporting regimes
Penalties
What do in-scope organisations need to do?

Next steps

September 2026 is worth treating as the first stage of the CRA compliance journey. Mapping the CRA product portfolio, understanding the components within it and agreeing who decides internally are all steps the December 2027 requirements will build on.

We will shortly publish a short practical guide to what businesses need to know about the CRA, and – as the December 2027 deadline approaches – guidance on selecting the appropriate conformity assessment route and planning a compliance programme. If you would like to discuss how the CRA applies to your products, or would like help putting reporting procedures in place, please get in touch with a member of our Data Team.

Key contacts

Counsel, Head of TMT/IP (Poland)

Partner, IP/IT & Data Protection
France

Partner, Intellectual Property, Data Protection & IT, Commercial
Germany

Counsel, Head of IS and Technology, Data Protection and Intellectual Property
Madrid, Spain

Partner, IP/IT & Data Protection
Dublin, Ireland

Partner, Commercial and Data Protection & Head of Data
Edinburgh, UK

To the Point


Subscribe to receive legal insights and industry updates directly into your inbox

Sign up now