Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act’s mandatory reporting rules.
The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation’s exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based.
Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours.
The same deadlines apply to severe incidents affecting the security of products with digital elements.
The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report.
Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience.
“The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt,” he said.
“Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk.”
EU and non-EU manufacturers must file these reports through ENISA’s Single Reporting Platform (SRP).
Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, this is generally the CSIRT for the member state where it has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc.
Manufacturers must also inform affected users, where appropriate, about actively exploited vulnerabilities or severe incidents. The CRA states that users must be informed of available corrections or mitigations without undue delay.
Generally, failures under the CRA are punishable by varying tiers of fines, the most serious of which can reach €15 million ($17.4 million) or 2.5 percent of the offender’s annual turnover, whichever is higher.
The reporting duties that took effect today are classified as core responsibilities under the act, meaning failures to comply with them could lead to the maximum fines being issued.
They are the latest step in the EU’s plan to drip-feed tighter security regulations on companies operating in the bloc.
Most remaining CRA provisions become applicable on December 11, 2027, at which time manufacturers will also be required to embed security by design and default. That means no default passwords and security updates are no longer optional.
Products covered by the CRA will also have to undergo the applicable conformity assessment before being placed on the EU market and bearing a CE mark.
The CRA’s new rules are not just intended to accelerate manufacturers’ responses to security flaws. They are also intended to give businesses a better understanding of their software supply chains.
With the reporting clock starting as soon as manufacturers become aware of an issue, they cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a comprehensive view of the affected product and any related products that may share the flaw if they are to meet the deadlines.
Furthermore, those requirements demand that manufacturers maintain this understanding throughout each product’s lifecycle.
Creating a software bill of materials (SBOM) when a product is launched is one thing. The SBOM becomes a mandatory requirement when most of the CRA’s remaining provisions become applicable next year.
Maintaining that security snapshot over time, however, is intended to help reduce the number and impact of serious cyberattacks across the EU.
“What all this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list,” said Eran Kinsbruner, VP of product marketing at Checkmarx.
“Modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected,” he added. “Organisations need to understand these components, their dependencies and the risks they introduce.”
Given enough time, the CRA looks set to improve cyber resilience across the board. However, lawyers warn that manufacturers, particularly those outside heavily regulated sectors, must now contend with a growing body of overlapping rules.
“The CRA is arriving as organisations are already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act,” said Heidi Waem, data, privacy and cybersecurity partner at DLA Piper.
“We’re seeing the compliance challenge for many businesses evolving beyond understanding single regulations in isolation, but determining how multiple frameworks interact, where requirements overlap and how compliance programmes can be coordinated across them.”
John Magee, partner and global co-chair of data, privacy, and cybersecurity at the same law firm, added: “Even now we’re seeing the breadth of the regulation’s reach catching organisations off guard.
“Many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements. For compliance teams already very busy managing multiple Digital Decade initiatives, there is a risk that this first wave of CRA obligations has arrived sooner, and with a wider impact, than they had expected.”
Whilst the rules of the act may be more nuanced than that, is it realistic for the EU to have set a deadline which at first glance sounds quite strict? Let us know your thoughts.
Get in touch"*" indicates required fields
Software Asset Management is a business practice that involves managing and optimising the life cycle of software within an organisation.
Software asset management is relevant to many facets of a business - take a look at some of the roles that it can form part of the focus of.
Software vendors come in all shape and sizes - all with their own set of licensing models and rules. We take a look at just a few of them.
As a constantly evolving subject, SAM is not without its challenges. We take a look at some of the most common ones.
Wondering what an investment in SAM could do for your business? Fill out a few details and find out what return you could get!
Answer a few questions about your SAM infrastructure & experience, and we'll put together a personalised recommendation for the future.
A simple health check of what's being used across your Office 365 estate in this FREE, Microsoft backed and easy to setup review.
Just like you would with your vehicle each year, get an annual check up of your software asset management programme.
Overwhelmed by the task of documenting the steps for a successful SAM programme? Get the experts in to help!
Concerned your SAM tools aren't covering your whole estate? Or on the look out for an entirely new tool? Get us in to assist.
Not content with covering all things SAM related, we've teamed up with Capital to provide a comprehensive hardware asset management review.
A simple, one-time reconciliation of the software you have deployed versus the licence entitlement you own.
A regularly scheduled analysis of your organisation's estate, specifically adapted to your needs and budget.
A full appraisal of your Microsoft 365 setup and how best to optimise it through automated recommendations.
An add-on to our SAMplicity One, MOT and Plus offerings, quickly diagnose your ability to migrate your resources to the cloud.
In collaboration with law firm Addleshaw Goddard, ensure the legality of your SAM programme and get assistance with any contract disputes.
Available as standard with SAMplicity Plus, ensure you're compliant if you're unexpectedly audited by a vendor.
We've teamed up with some of the forefront experts in licensing knowledge so you can teach yourself to be an expert too.
Stumped by the continually evolving complexities of SAM? Join us for one of our comprehensive courses, either in-person or online.
It’s chock full of useful advice, exclusive events and interesting articles. Don’t miss out!