PartsProof

EU Cyber Resilience Act — reporting obligations start September 11, 2026

CRA reporting starts 11 September 2026 — and it covers products you already shipped

Most CRA planning is pointed at December 2027. The reporting duty lands fifteen months earlier, and it reaches back over everything already in the field.

Reporting obligations11 September 2026European Commission
Full obligations11 December 2027European Commission
Early warning24 hours from becoming awareEuropean Commission
Full notification72 hoursEuropean Commission
Final report14 days after a fix for exploited vulnerabilities; one month for severe incidentsEuropean Commission
Retroactive reportingNot required. Exploitation you already knew about before 11 September 2026 stays outside the duty (C(2026) 5252 Annex, para. 217)Commission guidance, 27 July 2026

The Cyber Resilience Act entered into force on 10 December 2024 and phases in on three dates. The one teams plan against is 11 December 2027 — essential requirements, conformity assessment, CE marking, technical documentation.

But the reporting obligations bite on 11 September 2026. That is the date that changes what you have to be able to do on a Tuesday afternoon, and it arrives well before any of the design-side work is due.

The clock is 24 hours, and it starts on awareness

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements:

  • Early warning within 24 hours of becoming aware.
  • Full notification within 72 hours.
  • Final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability, or within a month for a severe incident.

Twenty-four hours from awareness, not from triage completing or from a fix existing. If the path from “a researcher emailed us” to “someone authorised to notify has the facts” runs through a shared inbox and a weekly engineering sync, the deadline is gone before anyone has decided whether it applies.

Legacy products are in scope

This is the part that is underpublished, and it is the one that changes the size of the job: the reporting obligations are not limited to new launches or current development projects. They cover products already placed on the EU market before the CRA applies in full.

So the question is not what your next release does. It is whether you can respond, inside 24 hours, about a device you shipped in 2023 — which means knowing what is in it. That is the practical reason the SBOM is not a December-2027 deliverable you can defer: without it you cannot answer a September-2026 question.

The one thing you do not owe: a backlog

The Commission’s first guidance on the CRA, published 27 July 2026, draws a line that is easy to miss and worth a great deal on 11 September. Because the duty attaches to becoming aware of active exploitation, a manufacturer “is not required to report vulnerabilities of whose active exploitation it had already become aware before 11 September 2026”. The guidance states it flatly: the CRA does not require the retroactive reporting of such vulnerabilities. You do not spend the first week of September filing a year of history.

The reverse case is the one to plan for. If you knew about a vulnerability before 11 September but were not aware of any active exploitation of it, and exploitation then occurs or comes to your attention afterwards, it becomes an actively exploited vulnerability and the 24-hour clock runs. Old bugs are not grandfathered; only old knowledge of exploitation is.

The same guidance bounds the dependency problem. You report actively exploited vulnerabilities contained in your product. Where a third-party component carries a vulnerability that either cannot be exploited in your product — the guidance gives unreachable code as the example — or has not been exploited in it, that vulnerability is not subject to mandatory reporting by you. You may still report it voluntarily under Article 15, you still owe the Annex I Part II vulnerability handling, and you still owe the upstream report to whoever maintains the component under Article 13(6). This is a narrower duty than “anything in your SBOM that gets a CVE”, and it is the difference between a runbook you can staff and one you cannot.

Both points come from the guidance annex itself rather than from commentary about it, and both are non-binding: the guidance says so on its own terms, and only the Court of Justice can interpret the Regulation authoritatively.

Are you in scope?

The trigger is placing a product with digital elements on the EU market — it is not about where the company is based or how large it is. If the product contains software or firmware and has a direct or indirect data connection, it is very likely covered.

The main exceptions are narrower than people hope:

  • Sector-specific products already regulated elsewhere — medical devices, vehicles, aviation.
  • Non-commercial open source.

Obligations run across the lifecycle and attach to manufacturers, importers and distributors — so “we only sell through a distributor” relocates part of the duty rather than removing it.

Where PartsProof fits

PartsProof produces the readiness pack for teams without a dedicated product-security function: a gap checklist written against the product actually being shipped, the SBOM, and the reporting runbooks — so the 24-hour path exists before it is needed rather than being invented during an incident.

If you are still sizing the whole obligation rather than just this date, what CRA compliance actually costs a small maker covers the conformity assessment routes, which products need a notified body and which do not, and the reliefs Articles 32 and 33 write in for micro and small enterprises.

$349 for the Readiness Pack, $649 for Readiness Plus with SBOM and reporting runbooks, $899 with a retainer. See what the pack contains or contact us.

One caveat worth reading before you plan around the penalty: Article 64(10)(a) says manufacturers that qualify as microenterprises or small enterprises cannot be fined for missing the 24-hour deadline. The duty to file still applies on 11 September 2026 — the fine does not.

Dates verified on 29 July 2026 against Article 71 of Regulation (EU) 2024/2847 as published in the Official Journal. The retroactive-reporting and third-party-component points were read on 1 August 2026 in the annex to C(2026) 5252, the Commission guidance of 27 July 2026, at paragraphs 217 and 218. Nothing here is legal advice.