Regulation · Cybersecurity · Digital products

Cyber Resilience Act: prepare mandatory reporting for 11 September 2026

Reporting duties applicable on 11 September 2026Deadline: 11 September 2026Reviewed: 13 August 2026Next review: 12 October 2026

01 · Post-deadline finding

What changes in practice

Article 14 of the Cyber Resilience Act applies from 11 September 2026. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents affecting product security.

The process requires an early warning within 24 hours, a complete notification within 72 hours and a final report. The regulation, not non-binding guidance, creates the obligation; most other duties apply from 11 December 2027.

02 · Who must reconsider their position

Who must reconsider their position

Concerned

Manufacturers of products with digital elements made available on the EU market, including certain products placed on the market before December 2027.

Distinguish

Guidance does not make every organisation a reporting party; legal role, product, market availability and event type determine the duty.

03 · Position shift

Position shift

Before

Reporting could be treated as the final step after a technical investigation.

Now

Qualification, escalation and authority must be organised from first awareness to meet the 24-hour window.

The 24-hour deadline turns vulnerability handling into an immediate governance decision.

The 2026 reporting milestone must be separated from the broader 2027 compliance programme.

Risk

Discovering during an incident that manufacturer status, decision authority or the evidence chain is unresolved.

Strategic opportunity

Make reporting capability a discipline of product, dependency and support governance.

04 · Five decisions to prepare

Five decisions to prepare

  1. 01

    Qualify products and roles

    List products with digital elements and document the entity acting as manufacturer.

    Horizon
    Immediate
    Decision forum
    Legal · product · security
  2. 02

    Define escalation criteria

    Approve a rule distinguishing actively exploited vulnerability, severe incident and events documented without mandatory reporting.

    Horizon
    Before 31 August 2026
    Decision forum
    Cybersecurity · incident response
  3. 03

    Assign decisions in the 24-hour window

    Name owners for early warning, complete notification and final report, including delegation.

    Horizon
    Before 31 August 2026
    Decision forum
    Management · legal · crisis
  4. 04

    Test evidence and notification

    Run a fictional incident exercise covering timestamps, evidence retention and the 24/72-hour deadlines.

    Horizon
    Before 11 September 2026
    Decision forum
    Security · operations
  5. 05

    Separate 2026 and 2027 milestones

    Keep immediate reporting work distinct from general obligations due in December 2027.

    Horizon
    Next executive meeting
    Decision forum
    Management · product governance

05 · Correction

Correction

Claim

Commission guidance makes the Act mandatory on 11 September 2026.

Verified correction

The regulation is already in force. That date activates Article 14 reporting; the guidance is non-binding and most other duties apply in December 2027.

06 · Evidence

Primary sources

07 · Revisions

Public history

Deadline, reporting windows and the non-binding nature of the guidance checked against the regulation and Commission publications.