The CRA reporting obligations take effect 18 months before the other requirements. Manufacturers must report vulnerabilities from September 2026, including for existing products.
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024 and defines a phased timetable. The full cybersecurity requirements — from security by design to the software bill of materials (SBOM) and CE marking — only apply from December 2027. The reporting obligations under Article 14, however, have been moved forward to 11 September 2026.
What must be reported
Two types of events must be reported: actively exploited vulnerabilities in products with digital elements and serious security incidents affecting the safety of such products. For both, a staged procedure with fixed deadlines applies, beginning with an early warning within 24 hours of becoming aware of the event.
Reports must be sent simultaneously to the competent national CSIRT and the EU Agency for Cybersecurity (ENISA) via the unified reporting platform that ENISA is building as the central single reporting platform. Which authority in Germany will act as the CSIRT is set out in the CRA implementation law; the Federal Office for Information Security (BSI) is envisaged.
The specific deadlines, recipients of the report and the reporting procedure are covered in the overview CRA reporting obligations in detail. This article focuses on why the reporting obligation also covers existing product portfolios.
Why existing products are also subject to the reporting obligation
Here lies the central misunderstanding observed at many manufacturers. The other CRA requirements (secure development, conformity assessment, CE marking and more) do not automatically apply to older products under Article 69(2). The decisive date is 11 December 2027. Products with digital elements placed on the market before this date — i.e., existing products — are subject to the other requirements only if they undergo a substantial modification after that date.
Existing products are therefore not simply exempt. A substantial modification under the CRA is a change after placing on the market that affects compliance with the essential cybersecurity requirements or changes the intended purpose. A security-relevant functional update can fall under this. In that case, an older product may become subject to the full CRA requirements even though it was placed on the market before the cutoff date.
This limitation does not apply to the reporting obligations under Article 14. Article 69(3) explicitly states that the reporting obligations apply to all products with digital elements that fall within the scope and were placed on the market before 11 December 2027. The applicability of the reporting obligation to existing products is therefore not an inference but is directly in the text of the regulation. Machines, controllers, sensors or software already delivered and in operation at customers are also subject to the reporting obligation from September 2026.
The obligation is not retroactive: vulnerabilities whose active exploitation was already known to a manufacturer before 11 September 2026 do not have to be reported afterwards. If the manufacturer only becomes aware of active exploitation after that cutoff date, the reporting obligation applies. This clarification comes from the second draft of the European Commission’s interpretative guidelines on the CRA (section on reporting obligations) and should be understood as a non-final draft position.
What this means for manufacturers in mechanical and plant engineering
For manufacturers in machinery, plant and equipment construction, this rule has far-reaching consequences. The entire installed portfolio of connected products — from controllers through gateways to software components — falls under the reporting obligation from September 2026, provided they are products with digital elements as defined by the CRA.
This requires manufacturers to know which of their legacy products are affected, which software components are contained in those products, and through which channels they learn about actively exploited vulnerabilities. The 24-hour deadline for the early warning leaves no room for ad-hoc processes. Those who do not have established procedures for vulnerability detection and reporting by 11 September 2026 will not be able to meet the deadlines.
Distinction from the NIS-2 directive
The CRA reporting obligations complement existing reporting duties under the NIS-2 directive but do not replace them. NIS-2 addresses the organisational cybersecurity of operators of critical infrastructures, while Article 14 of the CRA targets product-related reporting duties of manufacturers. A company can fall under both regimes in parallel: as an operator under NIS-2 and as a manufacturer under the CRA. The reporting obligations are not identical and each requires its own processes.
Conclusion
The CRA reporting obligations are the first binding operational requirement of the Cyber Resilience Act. They apply from 11 September 2026 and also cover products already on the market. Those who focus exclusively on the 11 December 2027 deadline risk overlooking an obligation that affects their entire existing product portfolio.
For connected products with digital elements, a manufacturer is generally affected. What remains to be clarified is how the manufacturer learns about an actively exploited vulnerability in an existing product and who then triggers the report.