Elodie Weber
Elodie Weber Senior legal counsel, independent
EU digital regulation and resilience

Cyber Resilience Act · Regulation (EU) 2024/2847

From 11 September 2026, who files, and on which clock

Article 14 reporting applies from 11 September 2026, and it reaches products already on the market. Every provision below is quoted from the text published in the Official Journal.

Written by Elodie Weber, independent legal and compliance consultant. A question on a specific product line comes straight to me.

Write to meelodie.weber@ew-legal.com

PRODUCE — the twenty things a European buyer will ask you to produce, each one quoted from the Official Journal.

The shorthand everyone repeats is half wrong

Almost every summary of the Cyber Resilience Act gives three numbers: 24 hours, 72 hours, 14 days. That is correct for an actively exploited vulnerability. It is wrong for a severe incident.

There are two tracks, with different deadlines and different starting points.

Actively exploited vulnerabilityARTICLE 14(1) AND (2)
Early warning
24 hours from becoming aware
Notification
72 hours from becoming aware
Final report Art. 14(2)(c)
14 days after a corrective or mitigating measure is available.
Not 14 days after you became aware.
Severe incidentARTICLE 14(3) AND (4)
Early warning
24 hours from becoming aware, including whether it is suspected of being caused by unlawful or malicious acts
Notification
72 hours from becoming aware
Final report Art. 14(4)(c)
One month after the 72-hour notification was submitted.
Not 14 days, and not counted from awareness.

A relief most readers miss

Each of the 72-hour and final-report obligations is prefaced by “unless the relevant information has already been provided”. If everything was said at 24 hours, there is no duty to repeat it on a schedule.

Who receives the notification

Notification goes to the CSIRT designated as coordinator of the Member State of your main establishment in the Union. The Regulation defines that as the Member State where “the decisions related to the cybersecurity of its products with digital elements are predominantly taken”. It is a decision-making test, not a headquarters test.

If you have no main establishment in the Union, the third subparagraph of Article 14(7) sets an order. Each step carries a qualifier that summaries usually drop:

  1. the Member State where the “the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer” is established
  2. failing that, where the “the importer placing on the market the highest number of products with digital elements of that manufacturer” is established
  3. failing that, where the “the distributor making available on the market the highest number of products with digital elements of that manufacturer” is established
  4. failing all of those, the Member State where “the highest number of users of products with digital elements of that manufacturer are located”

Two things soften this, and both are in the text.

The determination is made “based on the information available to the manufacturer”. You are not required to build telemetry you do not have.

And where you land on the last step, you “may submit notifications related to any subsequent actively exploited vulnerability or severe incident … to the same CSIRT designated as coordinator to which it first reported”. The counting is a one-time cost, not a cost per incident.

The platform, and the gap nobody has closed

The architecture of the single reporting platform shall allow Member States and ENISA to put in place their own electronic notification end-points.Article 16(1)

So the entry point is not necessarily one European address. A Member State may operate its own, and Article 14(7) requires you to use the end-point of the CSIRT determined by the order above.

Article 16 establishes the platform, sets out how notifications are disseminated, and requires ENISA to secure it. It says nothing about what a manufacturer does if the end-point it is required to use is not reachable while the 24-hour clock is running. Having read Articles 14 and 16 in full, I have not found that provision. If it exists, it sits in an implementing act or in operational guidance rather than in the Regulation.

Two decisions to take before the date

Whether to appoint an authorised representative

A manufacturer may, by a written mandate, appoint an authorised representative.Article 18(1)

That single word makes it a decision rather than a formality. Under Article 3(15) the representative must be established in the Union, and appointing one moves you to the first step of the order instead of the last. Appointing a representative therefore chooses your regulator. Not appointing one leaves that choice to a user distribution you may not control.

Who owns the 24 hours

A named person, a named deputy, a documented escalation path, and authority to send without further approval. This costs nothing, and it is the difference between a company that meets the deadline and one that discovers its approval chain at hour nineteen.

What is not due in September

Conformity assessment, technical documentation, CE marking and the Annex III classes bite on 11 December 2027. Two obligations are worth starting now because they take time.

The support period, Article 13

It must reflect the period during which the product is expected to be in use, and it may not be shorter than five years unless the product is expected to be in use for less. Among the factors to take into account is the support period offered by other manufacturers of similar products. For a vendor whose marketing promises longevity, its own commercial claims become evidence.

Coordinated vulnerability disclosure, Annex I Part II

Point 5 requires a policy. Point 6 requires “a contact address for the reporting of the vulnerabilities discovered in the product with digital elements”. A support portal that requires a researcher to create an account is, in practice, not a contact address.

Nine things to have in place