Cyber Resilience Act: New Reporting Obligations Now in Force
The EU Cyber Resilience Act (“CRA”), Regulation (EU) 2024/2847, introduces a new horizontal regulatory framework establishing cybersecurity requirements for products with digital elements made available on the Union market.
While the CRA will apply generally from 11 December 2027, an important part of the regulatory framework has already become applicable. Since 11 September 2026, manufacturers of products with digital elements falling within the scope of the CRA are subject to the mandatory reporting obligations under Article 14 in relation to actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements.
What must be reported?
Manufacturers are required to notify:
The reporting framework operates on a staged basis. An early warning must be submitted without undue delay and, in any event, within 24 hours of the manufacturer becoming aware of the relevant actively exploited vulnerability or severe incident. A further notification must be submitted without undue delay and, in any event, within 72 hours of becoming aware of the relevant vulnerability or incident.
Further reporting requirements apply thereafter. In the case of an actively exploited vulnerability, a final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. In the case of a severe incident, the final report must be submitted within one month after the 72-hour notification.
A new EU-wide reporting mechanism
The required notifications must be submitted through the Cyber Resilience Act Single Reporting Platform, established and operated by the European Union Agency for Cybersecurity (“ENISA”), which became operational on 11 September 2026.
Manufacturers report once through the Single Reporting Platform. The notification is addressed to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment and, unless particularly exceptional circumstances provided for under the CRA apply, is made available simultaneously to ENISA. The CSIRT initially receiving the notification disseminates it without delay to the relevant CSIRTs in other Member States where the product with digital elements has been made available.
Which businesses should be considering the CRA?
The CRA applies broadly to hardware and software products with digital elements made available on the Union market, subject to the specific scope and exclusions provided for in the Regulation. While the CRA establishes obligations for different economic operators, the Article 14 reporting obligations applicable since 11 September 2026 apply to manufacturers.
Importantly, the Article 14 reporting obligations are not limited to newly marketed products. They apply to all products with digital elements falling within the scope of the CRA that have been made available on the Union market, including products already placed on the market before 11 December 2027.
The position in Cyprus
The CRA framework also involves responsibilities at national level.
In Cyprus, the Office of the Commissioner of Communications, through the Digital Security Authority, has assumed responsibilities under the CRA. The Digital Security Authority has stated that it acts as the Notifying Authority in relation to conformity assessment bodies and as the Market Surveillance Authority, with responsibilities relating to monitoring the market, assessing product compliance and requiring corrective measures where non-compliance is identified.
Cyprus’ national CSIRT is designated as coordinator for the purposes of the CRA reporting framework.
What should businesses be doing now?
For businesses potentially affected by the CRA, an initial step is to determine whether their products fall within the Regulation’s definition of products with digital elements and to identify their role under the CRA. Manufacturers subject to Article 14 should, in particular, assess the reporting obligations that have applied since 11 September 2026.
Businesses subject to those reporting obligations should also consider whether appropriate internal processes are in place to identify and escalate potentially reportable vulnerabilities and incidents promptly. Given the short statutory reporting periods, cybersecurity incident management, internal reporting procedures and allocation of responsibility within the organisation should be considered in advance rather than after an incident occurs.
More broadly, businesses potentially affected by the CRA should use the period before its general application on 11 December 2027 to assess their readiness for the wider cybersecurity, vulnerability-handling, conformity and product compliance requirements introduced by the Regulation. On 27 July 2026, the European Commission published guidance on the implementation of the CRA to assist stakeholders in preparing for its application.
The practical takeaway
The commencement of the CRA’s Article 14 reporting obligations represents an important step in the implementation of the EU’s new cybersecurity framework for products with digital elements.
For manufacturers of products with digital elements falling within the scope of the CRA, the reporting obligations are already applicable. Other economic operators should consider the obligations applicable to their respective role under the Regulation as the CRA moves towards general application on 11 December 2027.
Early consideration of the applicable requirements can assist businesses in establishing appropriate governance and reporting processes ahead of the CRA’s wider application.
Mylonas Law advises businesses and corporate groups on corporate and commercial law, regulatory compliance, technology-related matters and cross-border business activities in Cyprus and the European Union.
This publication is intended for general information purposes only and does not constitute legal advice. The application of the Cyber Resilience Act should be assessed by reference to the particular product, business activities and circumstances concerned.