On 11 September 2026 the reporting obligations in the Cyber Resilience Act take effect. It’s the regulation’s first hard deadline, and it applies to every product with digital elements already on the market, not just new ones. In July the European Commission published practical guidance to help manufacturers get there. Here we walk through what applies and how to prepare.
What the CRA is
The Cyber Resilience Act (EU Regulation 2024/2847) introduces cybersecurity requirements for products with digital elements placed on the European market. The regulation entered into force in December 2024 but applies in stages. The requirements on notified bodies began in June 2026, the reporting obligations apply from 11 September 2026, and the regulation’s broader requirements apply in full from 11 December 2027.
The CRA addresses manufacturers, importers and distributors of everything from industrial control systems and connected consumer products to pure software. At its core sit security by design, vulnerability handling across the entire product lifecycle, security updates over a defined support period, and CE marking as proof that the requirements are met.
A common misconception is that the CRA is something that only starts to apply in December 2027. That holds for the bulk of the requirements. But the reporting obligation comes first, and it’s closer than many think.
The reporting obligation from 11 September 2026
From 11 September, Article 14 of the regulation applies. Manufacturers of products with digital elements must then report two kinds of event: actively exploited vulnerabilities in their products, and severe incidents affecting the security of those products.
Reporting follows a three-step chain.
- An early warning within 24 hours of the manufacturer becoming aware of the event.
- A more detailed notification within 72 hours, with an assessment of the event and any corrective measures.
- A final report, within 14 days for actively exploited vulnerabilities and within one month for severe incidents.
Reporting goes through a single European platform to ENISA and the national CSIRTs. The pattern is familiar from NIS2 and the Swedish Cybersecurity Act, but note that the deadlines and recipients differ. An organisation covered by several frameworks needs an incident process that can handle parallel reporting paths without staff having to look up the rules in the middle of a live incident.
And the obligation applies to every product with digital elements on the market on 11 September, not just products released after that date. If you have connected products out with customers today, they are covered. That makes the date genuinely hard for many manufacturers who had otherwise planned their CRA adaptation for 2027.
The Commission’s new guidance
On 27 July 2026 the European Commission published guidance to support implementation of the CRA. It consists of a communication and an extensive annex with 67 practical examples, use cases and flowcharts, with particular focus on making the regulation manageable for small and medium-sized enterprises.
The guidance clarifies several questions that had created uncertainty in the industry. It draws a clearer line for when open source software is covered and how responsibility is distributed between developers, maintainers and commercial actors that build on open code. Substantial modification gets a sharper definition: when an existing product is changed so much that it must be treated as new and therefore falls under the full requirements. The guidance also describes how the support period for security updates should be determined, and when cloud-based remote data processing belonging to the product is covered by the requirements.
For anyone building their compliance, the guidance is a good starting point, because it translates the regulatory text into concrete situations.
How to prepare
Six weeks is short for anyone who hasn’t started, but the reporting capability is a bounded part of the CRA that you can put in place with focused effort.
- Inventory the product portfolio. Which of your products have digital elements and are on the EU market today? Don’t forget older products still in service with customers.
- Define what triggers a report. Set criteria for an actively exploited vulnerability and a severe incident in your own terms, with examples your organisation recognises.
- Assign responsibility and rehearse the chain. Who detects, who assesses, who reports? A 24-hour deadline demands readiness even over weekends and holidays.
- Register with the reporting platform and make sure you know the practical way in before you need it under time pressure.
- Connect it to existing vulnerability handling. Reporting assumes you actually learn about vulnerabilities in your products, through your own monitoring, customer channels and a working process for coordinated vulnerability disclosure.
- Plan ahead towards December 2027. Reporting is the first step. Security by design, technical documentation, an SBOM and conformity assessment need a considerably longer run-up.
For many Swedish manufacturers this is a shift in perspective rather than a technical question. A company that has seen itself as a hardware maker for twenty years is, in the eyes of the legislator, now a software company, with everything that entails in lifecycle responsibility. The sooner that lands with the leadership, the more manageable the journey becomes.
Need help getting the reporting capability in place before 11 September? At VER&IT we help manufacturers interpret the CRA and build an incident process that holds when it counts. Get in touch, and we’ll talk through your readiness.
Sources
- The European Commission’s guidance on CRA implementation
- The European Commission on the CRA reporting obligations
- Cyber Resilience Act, Regulation (EU) 2024/2847
More insights
Related articles
Stop chasing CRA. Start building securely.
The Cyber Resilience Act is already in force, with major obligations phasing in through 2027. The most common mistake is starting from the regulation. Flip the order — build securely with OWASP as your reference, and compliance becomes a by-product.
Compliance cost isn't a technology problem. It's governance debt.
European companies spend ~€150 billion a year on regulatory compliance. AI won't speed that up if governance is missing.
Your supply chain is your biggest cybersecurity risk – not your size
42 percent of Swedish organisations have low supply chain maturity. Being small doesn't protect you – it makes you the weakest link.