CRA4-minute read·Marcin Pajdzik·September 2026

CRA Reporting Starts This Month. Confirm Your Organisation Is Ready.

Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents from 11 September 2026, fifteen months before the CRA's essential requirements and CE marking obligations apply from 11 December 2027.

The reporting duty applies to any in-scope product with digital elements, including one already placed on the market before December 2027. A board that treats 2027 as its only CRA date is missing an earlier, active obligation.

What Article 14 requires

Article 14 distinguishes between two triggers. An actively exploited vulnerability requires an early warning within 24 hours of the manufacturer becoming aware, a fuller notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. A severe incident follows the same 24-hour and 72-hour sequence, with a final report due within one month of the notification. Reports are submitted through the CRA's single reporting platform.

Article 14 is a manufacturer obligation, but manufacturer status under the CRA is broader than the label suggests. An importer, distributor or other party can assume manufacturer obligations where, for example, it markets a product under its own name or trademark or substantially modifies it. Ordinary importers and distributors have separate CRA obligations, but do not normally carry the Article 14 reporting duty.

The practical consequence is that reporting capability needs to be operational before the wider CRA compliance programme is complete.

What management needs to demonstrate

The board's role is to confirm that management has already built a process capable of meeting the statutory reporting deadlines, evidenced across three capabilities.

Detection
management should be able to show how the organisation identifies active exploitation of a vulnerability or a severe incident affecting a product. Without effective monitoring and detection, the organisation may not recognise a reportable event quickly enough to meet the statutory timetable.
Escalation
management should be able to show a documented path from wherever awareness first arises, whether engineering, a customer report or a security researcher, to whoever is authorised to submit the report. The reporting timetable begins when the manufacturer becomes aware of the reportable event, potentially before its full nature or impact is understood.
Documentation
management should be able to produce the record of each report and the reasoning behind timing and severity decisions. That record provides evidence of what the organisation knew, when it knew it, how it assessed the event and whether it followed its reporting process.

How this affects your organisation

For organisations that manufacture products with digital elements, or may assume manufacturer obligations under the CRA, the immediate question is narrower than full compliance: does a specific product carry the Article 14 reporting duty, and would the current process meet the 24-hour and 72-hour windows if triggered tomorrow. Both depend first on whether the product falls within the CRA's scope.

Ask management to demonstrate that the reporting process has actually been exercised against the clock. The first time the organisation tests its 24-hour reporting capability should not be during a reportable event.

If you need to confirm whether the Article 14 reporting obligation already applies to your products, an advisory call is a useful next step.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

CRA Self-Assessment

If this briefing is relevant to your organisation, the self-assessment tool gives a fast, no-commitment view of where a specific product stands under the CRA.

Free, self-serve

Answer a short set of questions about the product and your role in the supply chain.

Output: An initial product classification, the obligations most likely to apply, and the questions worth raising internally before committing to a compliance programme.
Start the self-assessment