CRA4-minute read·Marcin Pajdzik·September 2026

Board Assurance over CRA Reporting Readiness

From 11 September 2026, Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting product security. Boards need assurance that management can meet these obligations, fifteen months before the CRA's main requirements apply in December 2027.

A reporting process can fail when responsibility is unclear or approval takes too long. The board should seek evidence that management can assess an event, authorise a notification and communicate with affected users while the technical investigation continues.

Establish who is responsible

The reporting duty also covers existing products within the CRA's scope. Management should identify the affected products and the legal entity responsible for each, including within groups where development, branding and sales sit in different companies.

Manufacturer responsibilities can extend to businesses selling products under their own name or trademark, or substantially modifying products and making them available on the market. The scope assessment should examine these arrangements and record any unresolved questions. This gives directors a basis for understanding which parts of the business need reporting capability and who is accountable for providing it.

Give management authority to act

For either reporting trigger, the manufacturer must submit an early warning without undue delay and within 24 hours of awareness, followed by a notification without undue delay and within 72 hours of awareness. Both deadlines run from the same starting point. Reports go through the CRA's single reporting platform, with final reports following the applicable timetable.

Management needs a way to assess incoming information promptly and decide whether the reporting threshold has been reached. A vulnerability report needs assessment for evidence of active exploitation; a severe incident requires assessment of its impact on product security. These decisions may involve engineering, security and legal teams working with incomplete information.

Delegated authority should allow the initial report to proceed as the investigation develops. Arrangements also need to cover communication with impacted users, whom the manufacturer must inform, and the provision of mitigation advice where necessary. Directors should understand whether any approval step depends on one person's availability.

Obtain evidence of readiness

Ownership
A named executive is accountable for readiness across the affected portfolio. Reporting personnel and deputies understand their responsibilities and have access to the reporting platform.
Execution
An incoming signal reaches the people who can assess it and authorise reporting, including outside normal working hours. The exercise should test whether the required information can be assembled within the reporting windows.
Decision records
The record captures what was known, when the reporting threshold was assessed as met, and why a notification was submitted or judged unnecessary. It should also identify delays and gaps in user communications.

A timed exercise gives the board a practical way to assess whether the arrangements work. Ask management to demonstrate three things.

How this affects your organisation

Ask management to present the exercise findings alongside the changes needed to address them. This gives the board a basis for deciding whether staffing, delegated authority or investment needs to change before management can demonstrate readiness.

Each unresolved gap should have an accountable owner, a completion date and interim arrangements. Agree when management will return with evidence that those actions have worked, so the board can track progress against the weaknesses the exercise exposed.

I can help establish your product scope and assess whether your reporting arrangements can meet the Article 14 deadlines.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

CRA Self-Assessment

If this briefing is relevant to your organisation, the self-assessment tool gives a fast, no-commitment view of where a specific product stands under the CRA.

Free, self-serve

Answer a short set of questions about the product and your role in the supply chain.

Output: An initial product classification, the obligations most likely to apply, and the questions worth raising internally before committing to a compliance programme.
Start the self-assessment