Status note — checked 12 August 2026. The Cyber Resilience Act (CRA) is in force. Its Article 14 reporting obligations start on 11 September 2026; most principal obligations start on 11 December 2027. The reporting date is less than a month from this page’s evidence review.
The owner-level surprise is that a 24-hour clock can begin before a business has decided whether the event is “material” in the everyday sense. Product role, event definition and awareness need to be resolved in the incident process, not improvised after a vulnerability report arrives.
Fact: the first operational deadline is reporting
The CRA, Regulation (EU) 2024/2847, entered into force on 10 December 2024. The Commission’s legislative summary states:
- Chapter IV provisions concerning notification of conformity-assessment bodies applied from 11 June 2026;
- Article 14 reporting obligations apply from 11 September 2026; and
- the main provisions apply from 11 December 2027.
The CRA concerns products with digital elements made available on the EU market, with duties allocated among manufacturers, importers, distributors and, in a different way, open-source software stewards. Sector exclusions, special regimes and the Act’s treatment of remote data-processing solutions can change the answer; “we sell software” is not enough to determine scope.
What the September 2026 clock requires
The Commission’s CRA reporting page says manufacturers must notify actively exploited vulnerabilities and severe incidents affecting the security of a product with digital elements through the CRA Single Reporting Platform:
- an early warning within 24 hours after awareness;
- a full notification within 72 hours;
- for an actively exploited vulnerability, a final report no later than 14 days after a corrective or mitigating measure is available; and
- for a severe incident, a final report within one month after the 72-hour submission.
The statutory criteria—not an ordinary severity label or customer complaint count—determine whether an event is reportable. The Commission says the platform will be operational by 11 September 2026.
Reporting reaches products already made available on the Union market before 11 December 2027. By contrast, the Commission summary says products placed on the market before that date generally become subject to the CRA’s main product obligations only if they undergo a substantial modification from that date. Do not merge those transition rules.
The Commission published non-binding implementation guidance on 27 July 2026. It may help interpretation, but it does not replace the regulation.
Signal: the incident process stops at the company boundary
PARAVEILUX judgment. The recurring risk is an incident plan built for internal networks, while CRA facts arrive through product-support inboxes, vulnerability researchers, open-source dependencies, resellers or contract manufacturers.
Investigate when:
- no one has recorded which legal entity is the manufacturer for each product or release;
- customer support, security and engineering use different definitions of “awareness” or do not share a clock;
- a supplier promises security patches but has no contractual duty to notify exploited component vulnerabilities promptly;
- the product inventory cannot connect deployed versions to components, customers, support periods and update channels;
- a vulnerability intake form exists but there is no authenticated path for researchers or no anti-retaliation/escalation protocol;
- incident communications cannot distinguish a security event, an actively exploited vulnerability and a severe incident; or
- a pre-2027 product is assumed to be irrelevant even though Article 14 reporting can still apply.
Counter-signals
- Every product has a named economic-operator role, responsible entity, supported-version register and security contact.
- A cross-functional triage exercise can start the legal clock, preserve evidence, decide the reporting pathway and send an early warning within 24 hours.
- Component and supplier records allow a vulnerable dependency to be mapped to affected releases quickly.
- Product updates are authenticated, delivered securely and supported for a defined period.
Action: rehearse the 24-hour path before 11 September
Implementation checkpoints
- Confirm scope and role. Identify products with digital elements, relevant remote processing, manufacturer/importer/distributor status, exceptions and the responsible legal entity.
- Create one intake clock. Route researcher, supplier, customer, monitoring and employee reports into a recorded triage process with an explicit time of awareness.
- Define the decision evidence. Preserve version, exploit evidence, impact, affected markets, containment, component lineage and who approved the classification.
- Prepare platform access. Assign credentials and alternates for the Single Reporting Platform and rehearse the 24-hour and 72-hour submissions without inserting speculative facts.
- Flow down supplier duties. Require prompt vulnerability and incident notice, component/version information, remediation support, change notice and evidence retention.
- Build toward 11 December 2027. Map Annex I essential requirements, vulnerability handling, technical documentation, conformity assessment, CE-marking, user information and support-period work into the product roadmap.
An early warning is not the final investigation. Design the first submission to be timely and bounded, then update it through the required stages.
Limitations: this is not a product classification
This page does not decide whether a particular device, software service, component, open-source project or remote-processing function falls within the CRA. It also does not cover every exception, reporting criterion, conformity route or interaction with NIS2, data-protection, product-safety and sector rules. Commission guidance is non-binding and may be updated.
The CRA includes proportionality measures, including a stated penalty protection for qualifying micro and small manufacturers missing the 24-hour deadline, but that is not an exemption from reporting or a reason to delay preparation. This is general information, not legal, cybersecurity or professional advice.
Regulation (EU) 2024/2847 — Cyber Resilience Act. This source supports the identified facts; Paraveilux signals and recommendations remain interpretation.