Data Privacy Alerts

EU Cyber Resilience Act Reporting Obligations Begin September 2026

Prepare for the EU Cyber Resilience Act (CRA) mandatory 24-hour incident reporting obligations starting September 11, 2026. Discover key deadlines, compliance requirements, enforcement risks, and expert cybersecurity insights.

Why The EU Cyber Resilience Act Matters

The EU Cyber Resilience Act (CRA) introduces mandatory 24-hour reporting for exploited vulnerabilities and severe incidents starting September 11, 2026. For organizations creating hardware or software, accelerating compliance readiness is critical to avoiding severe fines and maintaining access to the European Union market.

Overview of the EU Cyber Resilience Act

While the EU Cyber Resilience Act (CRA) will not take full effect until December 11, 2027, a critical early deadline is rapidly approaching. Beginning September 11, 2026, manufacturers of products with digital elements must comply with new reporting obligations under Article 14 of the CRA. This applies to hardware and software whose foreseeable use involves a data connection to a device or network, ranging from consumer IoT devices and smartphones to industrial control systems and commercially supplied open-source software.

Manufacturers will be required to report actively exploited vulnerabilities and severe security incidents to the European Union Agency for Cybersecurity (ENISA) and their national Computer Security Incident Response Team (CSIRT). The CRA mandates a staged timeline through a Single Reporting Platform (SRP). Manufacturers must submit an early warning within 24 hours of becoming aware of a reportable event. This is followed by a detailed notification within 72 hours, and a final report within 14 days of mitigating an exploited vulnerability, or within one month of the 72-hour notification for severe incidents. Manufacturers must also inform impacted users about the incident and provide mitigation steps.

Key Implications or Developments of the EU Cyber Resilience Act

‍The early rollout of these reporting obligations means organizations have a limited window to prepare and must ensure robust internal identification, escalation, and reporting processes are established. This compliance effort is not merely a box-ticking exercise; non-compliance can result in fines of up to €15 million or 2.5% of a company's total worldwide annual turnover, whichever is higher.

Organizations must immediately assess whether their digital products fall within the CRA’s scope and identify which national CSIRT will act as their coordinator. Crucially, companies need to set up an EU login account to access the CRA Single Reporting Platform ahead of time. Because the 24-hour reporting window is so tight, security, engineering, and compliance teams must work in lockstep to identify and evaluate severe incidents without delay. Furthermore, because reporting obligations continue to apply even after a product is no longer supported, organizations must maintain long-term visibility into legacy products and third-party software components originating in their supply chain. Finally, since the CRA applies to any company placing in-scope products on the EU market, non-EU businesses must also comply to maintain market access.

Expert Analysis by Robert Bond, Senior Product Marketing Manager, Digital Forensics, Exterro

The CRA places more emphasis on a part of incident response that often receives less attention: the investigation. Detecting suspicious activity is the starting point. Manufacturers then need to understand how the product was affected and what the evidence supports. With a short reporting window, delays in getting those answers can leave the reporting team working with an incomplete picture.

This is where digital forensics matters. Teams need to collect relevant evidence quickly and preserve it as they contain the incident. Logs can be overwritten, and remediation can change the systems investigators need to examine. Planning evidence collection alongside containment gives the team a better chance of establishing what happened without holding up the response.

The handoff between security, product engineering, and legal deserves just as much attention. Before an incident, manufacturers should agree on who assesses the findings, who makes the reporting decision, and who submits the notification. Investigators need to distinguish confirmed facts from open questions so the reporting team can act on what is known while the investigation continues.

Finally, I would put more emphasis on that investigative work. Data mapping helps organizations understand where information resides. Digital forensics helps them determine what happened to it and assess the impact on affected systems and products. The practical takeaway is to have the tools and people ready to produce findings the business can explain and support with evidence.

Data Governance Tip

To meet tight reporting deadlines, organizations need comprehensive visibility into their digital assets. Use Exterro’s automated data mapping solution, Exterro OptiX360, to inventory your data ecosystem and streamline compliance workflows.

‍