What changed on 11 September
On 11 September 2026, the first binding obligations of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) took effect. Manufacturers of products with digital elements, a category that covers everything from smart doorbells to routers and standalone software, must now report two kinds of events. The first is an actively exploited vulnerability. The second is a severe incident affecting the product's security. The Commission's CRA reporting page sets out a three-stage clock. An early warning is due within 24 hours of the manufacturer becoming aware, and a fuller notification within 72 hours. A final report follows 14 days after a fix is available for vulnerabilities, or within a month of the incident notification for severe incidents.
The rest of the regulation, including secure-by-default design, security update duties and CE marking, applies from 11 December 2027, according to the Commission's CRA policy page. Reporting therefore runs about 15 months ahead of the product-design rules.
The strongest case for the rule
The case for early reporting is serious and deserves a fair statement. Connected devices are sold worldwide, are rarely patched by their owners, and are often the entry point for botnets and intrusions. When a vulnerability is being exploited in the wild, the interval between first exploitation and regulator awareness is exactly when defenders are blind. A single, mandatory channel means a national response team can warn other member states' teams and users before an attack spreads. Voluntary disclosure has worked for well-run vendors. It has not worked for the long tail of low-margin hardware makers who have no incentive to say anything.
The design also has features that a pro-innovation reading should credit. Under Article 14 of the regulation, as published on EUR-Lex, a manufacturer reports once, through ENISA's Single Reporting Platform. The notification goes to the national response team (CSIRT) where the manufacturer has its main establishment, and ENISA sees it at the same time. That avoids a patchwork of 27 separate filings. Disclosure to other national teams can also be delayed on justified cybersecurity grounds, which protects users from a vulnerability being broadcast before a patch exists.
Where the design deserves scrutiny
The clock starts at awareness, and the scope is broad. The 24-hour early warning is triggered when a manufacturer becomes aware of active exploitation. That is workable for a company with a security team on call. It is harder for a small firm whose entire engineering staff is in one time zone. Article 14 also defines a severe incident widely. It covers events that affect, or could affect, the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that could lead to malicious code running in the product or a user's network. The words 'could affect' invite over-reporting out of caution. Authorities would then receive a flood of low-value filings, which dilutes the signal the system is meant to create.
The penalty ceiling is large. Article 64(2) allows fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential requirements and of Articles 13 and 14. The regulation does soften the blow for the smallest players. Article 64(10)(a) exempts microenterprises and small enterprises from fines for missing the early-warning and notification deadlines. That is a sensible carve-out, and it shows the drafters understood the risk. Medium-sized firms and fast-growing startups get no such shelter.
The compliance burden compounds. As McCann FitzGerald notes, the CRA applies extraterritorially to any operator placing covered products on the EU market. Importers and distributors can become 'manufacturers' if they sell under their own name or substantially modify a product. Firms must also reconcile the CRA with notification duties under GDPR and NIS2. A company that ships one device worldwide may now run three clocks for a single event.
What proportionate implementation looks like
The goal of the reporting rule is faster fixes, not a paper trail. Three practices would keep it aligned with that goal.
- Enforce for outcomes first. A manufacturer that detected a flaw, warned users and shipped a patch, but filed its notification late, is a different case from one that hid an exploited flaw for months. Authorities should treat these differently, using warnings and corrective orders before maximum-tier penalties.
- Publish guidance on the 'severe incident' threshold. Clear examples reduce defensive over-reporting and let small teams focus on real threats.
- Keep the single-filing promise. The value of one platform is that it replaces other filings. If national authorities start requesting parallel reports, the efficiency gain disappears.
Open-source projects are the other test. The regulation gives open-source stewards a lighter regime. Article 24 requires a documented, verifiable cybersecurity policy, and the Commission's reporting page says stewards' reporting duties apply only from 11 December 2027. A regime that pushed volunteer maintainers out of the ecosystem would make the connected-device supply chain less secure, not more. The Commission should watch for any such chilling effect over the next year.
The bottom line
A 24-hour early warning for actively exploited flaws is a narrow, defensible duty. It targets a moment when speed matters and when the manufacturer is the only party who knows what is happening. The risk is not the rule itself but how it is enforced. If regulators use the headline penalty ceiling as a first resort, they will push firms toward silence and legal hedging. If they use the reporting data to coordinate fixes, the CRA could become a model that other jurisdictions copy for good reason. The 15 months before the design obligations bite are the time to set that tone.