Cyber Resilience Act reporting duties have applied since 11 September 2026, including to qualifying products placed on the market before December 2027. Manufacturers need to be ready to assess and report certain events affecting those products.
The reporting duty has an earlier deadline
Many manufacturers are planning towards 11 December 2027, when the Cyber Resilience Act generally becomes applicable, subject to its transitional provisions. However, the reporting duties in Article 14 of Regulation (EU) 2024/2847 applied from 11 September 2026.
This creates an important practical distinction. Requirements such as the wider product cybersecurity obligations and conformity assessment timetable have their own application rules. Article 14 reporting is already an operational duty for manufacturers of products with digital elements that fall within the Regulation's scope.
What Article 14 covers
Article 14 concerns two defined types of event:
- actively exploited vulnerabilities in products with digital elements
- severe incidents having an impact on the security of products with digital elements
An actively exploited vulnerability is not simply a known vulnerability, a CVE or a proof of concept. The Regulation requires reliable evidence that a malicious actor exploited the vulnerability in a system without the system owner's permission.
The first notification is an early warning, due without undue delay and in any event within 24 hours after the manufacturer becomes aware of the event. A fuller notification follows within 72 hours. Later reporting stages have different content and deadlines.
Manufacturers currently submit mandatory Article 14 notifications through ENISA's Single Reporting Platform, which ENISA states became operational on 11 September 2026. Its current FAQ guidance should be consulted for the current operational process.
Why existing products are included
Article 69(3) provides the specific legal basis for this earlier reach. It makes the Article 14 reporting obligations applicable to products with digital elements within the Cyber Resilience Act's scope that were placed on the market before 11 December 2027.
That is not a general rule making every Cyber Resilience Act obligation retrospective for every older product. Nor does it mean that every installed or connected product is automatically in scope. The product and manufacturer must fall within the Regulation's scope, and the event must meet the Article 14 threshold.
For manufacturers, though, the consequence can be substantial. A qualifying product placed on the market before December 2027 may still generate an Article 14 reporting duty from September 2026, even though other Cyber Resilience Act requirements follow a different transitional timetable.
Awareness matters
The reporting clock is tied to awareness of the reportable event. It does not begin merely because a vulnerability was published or because a product contains a vulnerable component.
Current Commission and ENISA guidance explains that manufacturers do not retrospectively report active exploitation of which they were already aware before 11 September 2026. Where awareness of active exploitation arises after that date, however, the reporting duty can apply even if the underlying vulnerability existed, or was known, earlier. This guidance helps explain the transition, but it does not amend the Regulation.
Preparing for the 24-hour clock
The legal deadlines leave little room to establish basic arrangements only after an event emerges. A practical preparation programme for existing products can include:
- identifying in-scope products placed on the market before 11 December 2027
- recording product identity, support status and accountable ownership
- maintaining channels through which vulnerability and exploitation information can reach the right team
- defining an initial assessment route for deciding whether an event may meet the Article 14 threshold
- assigning escalation and reporting responsibilities
This is a practical preparation list, not a statutory checklist or a determination that a particular product or event is reportable.
Keep reporting regimes distinct
Article 14 reporting may sit alongside other reporting duties that apply to an organisation or event. A Cyber Resilience Act notification should not be treated as automatically discharging obligations under NIS 2, sector-specific rules or national law.
The immediate question for manufacturers is therefore not only what changes in December 2027. It is whether their product-security arrangements can identify, assess and escalate a potentially reportable event affecting an in-scope existing product within an awareness-based 24-hour timeframe.