The shorthand everyone repeats is half wrong
Almost every summary of the Cyber Resilience Act gives three numbers: 24 hours, 72 hours, 14 days. That is correct for an actively exploited vulnerability. It is wrong for a severe incident.
There are two tracks, with different deadlines and different starting points.
- Early warning
- 24 hours from becoming aware
- Notification
- 72 hours from becoming aware
- Final report Art. 14(2)(c)
- 14 days after a corrective or mitigating measure is available.
Not 14 days after you became aware.
- Early warning
- 24 hours from becoming aware, including whether it is suspected of being caused by unlawful or malicious acts
- Notification
- 72 hours from becoming aware
- Final report Art. 14(4)(c)
- One month after the 72-hour notification was submitted.
Not 14 days, and not counted from awareness.
A relief most readers miss
Each of the 72-hour and final-report obligations is prefaced by “unless the relevant information has already been provided”. If everything was said at 24 hours, there is no duty to repeat it on a schedule.
Who receives the notification
Notification goes to the CSIRT designated as coordinator of the Member State of your main establishment in the Union. The Regulation defines that as the Member State where “the decisions related to the cybersecurity of its products with digital elements are predominantly taken”. It is a decision-making test, not a headquarters test.
If you have no main establishment in the Union, the third subparagraph of Article 14(7) sets an order. Each step carries a qualifier that summaries usually drop:
- the Member State where the “the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer” is established
- failing that, where the “the importer placing on the market the highest number of products with digital elements of that manufacturer” is established
- failing that, where the “the distributor making available on the market the highest number of products with digital elements of that manufacturer” is established
- failing all of those, the Member State where “the highest number of users of products with digital elements of that manufacturer are located”
Two things soften this, and both are in the text.
The determination is made “based on the information available to the manufacturer”. You are not required to build telemetry you do not have.
And where you land on the last step, you “may submit notifications related to any subsequent actively exploited vulnerability or severe incident … to the same CSIRT designated as coordinator to which it first reported”. The counting is a one-time cost, not a cost per incident.
The platform, and the gap nobody has closed
The architecture of the single reporting platform shall allow Member States and ENISA to put in place their own electronic notification end-points.Article 16(1)
So the entry point is not necessarily one European address. A Member State may operate its own, and Article 14(7) requires you to use the end-point of the CSIRT determined by the order above.
Article 16 establishes the platform, sets out how notifications are disseminated, and requires ENISA to secure it. It says nothing about what a manufacturer does if the end-point it is required to use is not reachable while the 24-hour clock is running. Having read Articles 14 and 16 in full, I have not found that provision. If it exists, it sits in an implementing act or in operational guidance rather than in the Regulation.
Two decisions to take before the date
Whether to appoint an authorised representative
A manufacturer may, by a written mandate, appoint an authorised representative.Article 18(1)
That single word makes it a decision rather than a formality. Under Article 3(15) the representative must be established in the Union, and appointing one moves you to the first step of the order instead of the last. Appointing a representative therefore chooses your regulator. Not appointing one leaves that choice to a user distribution you may not control.
Who owns the 24 hours
A named person, a named deputy, a documented escalation path, and authority to send without further approval. This costs nothing, and it is the difference between a company that meets the deadline and one that discovers its approval chain at hour nineteen.
What is not due in September
Conformity assessment, technical documentation, CE marking and the Annex III classes bite on 11 December 2027. Two obligations are worth starting now because they take time.
The support period, Article 13
It must reflect the period during which the product is expected to be in use, and it may not be shorter than five years unless the product is expected to be in use for less. Among the factors to take into account is the support period offered by other manufacturers of similar products. For a vendor whose marketing promises longevity, its own commercial claims become evidence.
Coordinated vulnerability disclosure, Annex I Part II
Point 5 requires a policy. Point 6 requires “a contact address for the reporting of the vulnerabilities discovered in the product with digital elements”. A support portal that requires a researcher to create an account is, in practice, not a contact address.
Nine things to have in place
- Scope determined per product line, with the SaaS and remote-data-processing test applied and written down
- The Article 14(7) order worked down, with the stopping point and the reason recorded
- A recorded decision on the authorised representative
- A named owner and deputy for the 24-hour notification, with authority to send
- A written fallback if the notification end-point is unreachable
- Separate templates for the vulnerability track and the incident track
- A user notification path under Article 14(8), distinct from the authority notification
- A published disclosure policy with a contact address that does not require registration
- A support period set under Article 13 and checked against your own marketing