CRA · Deadline imminent
Reporting obligations begin — actively exploited vulnerabilities must be notified to the CSIRT of your main establishment and to ENISA.
CRA readiness serviceWhat the Cyber Resilience Act is
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is a horizontal product-safety regulation for hardware and software with digital elements placed on the EU market. It entered into force on 10 December 2024. It sits alongside the AI Act and existing sectoral rules: a product with digital elements that is also an AI system may have to comply with both.
The Act's aim is to ensure that products with digital elements are placed on the market with fewer vulnerabilities, that vulnerabilities are handled throughout the product lifecycle, and that users receive clear information about security updates and support periods.
Who it catches
The scope is wider than many organisations assume. It catches:
- Connected industrial equipment, consumer IoT devices and their embedded software.
- Operating systems, web browsers, mobile applications and development tools.
- Commercial software that the maker may not think of as a "product" but is placed on the EU market for a price or as part of a service contract.
- Remote data processing solutions and software provided as a product even if delivered via the cloud.
Manufacturers hold the obligations directly. Importers and distributors carry verification duties before placing products on the market. Component and software suppliers may receive their customers' obligations as contractual requirements downstream.
What the September 2026 obligation requires
From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements must notify the CSIRT of its main establishment. The same information must be made available simultaneously to ENISA. The reporting runs through the CRA Single Reporting Platform — once, not to each Member State separately.
The timeline is tight:
- Early warning: within 24 hours of becoming aware of the actively exploited vulnerability.
- Full notification: within 72 hours of becoming aware.
- Final report: no later than 14 days after the corrective measure has become available.
Severe incidents carry a parallel notification obligation with a one-month deadline for the final report. The distinction between a "regular" vulnerability notification and a "severe incident" notification depends on the criteria set out in the regulation, including scope and impact.
Full application: 11 December 2027
By 11 December 2027 the regulation applies in full. This includes the essential cybersecurity requirements for products with digital elements, the conformity-assessment procedures, internal risk-management processes, the need for technical documentation, and CE marking where required. Products that were already on the market before that date may still need to comply with the vulnerability-handling and reporting obligations after it.
What most organisations are missing
How CYBERVETTER helps
We treat CRA readiness as a product-lifecycle and governance exercise, not a one-off gap assessment. Our work typically covers:
- Mapping the product and software portfolio against CRA scope, including products that are currently miscategorised.
- Designing the vulnerability-intake, triage and reporting workflow so it can meet the 24/72/14-day clock.
- Building the technical documentation and internal risk-management evidence required for conformity assessment.
- Reviewing supplier and customer contracts to place obligations correctly on importers, distributors and upstream component suppliers.
- Preparing the board and engineering leadership for what personal accountability and market-surveillance scrutiny look like under the Act.