CRA reporting obligations also apply to existing products

The CRA reporting obligations take effect 18 months before the other requirements. From September 2026 manufacturers must report vulnerabilities, including for products already on the market.

The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024 and establishes a staggered timetable. The full cybersecurity requirements — from security by design through the software bill of materials (SBOM) to CE marking — only apply from December 2027. The reporting obligations under Article 14, however, have been brought forward by the legislator to 11 September 2026.

This obligation was deliberately moved earlier: the EU wants an early overview of actively exploited vulnerabilities in connected products. The reporting requirement is therefore the CRA’s first operational obligation for manufacturers. It takes effect before conformity assessments, technical documentation or secure development processes are formally required.

What must be reported

Two types of events must be reported: actively exploited vulnerabilities in products with digital elements and serious security incidents affecting the safety of such products. For both types there is a staged procedure with fixed deadlines, beginning with an early warning within 24 hours of becoming aware.

Reports are submitted simultaneously to the competent national CSIRT and to the EU Agency for Cybersecurity (ENISA), via the unified reporting platform that ENISA is setting up as the central single reporting platform. Which body in Germany will act as the CSIRT is regulated by the CRA implementing law; the BSI is envisaged.

The deadlines, recipients of the report and the reporting procedure are covered in the overview CRA reporting obligations in detail. This article focuses on why the reporting obligation also covers the existing product portfolio.

Why existing products are also subject to the reporting obligation

Here lies the central misunderstanding observed at many manufacturers. The other CRA requirements (secure development, conformity assessment, CE marking and others) do not apply across the board to older products under Article 69(2). The decisive date is 11 December 2027. Products with digital elements that were placed on the market before that date, i.e. existing products, are subject to the other requirements only if they undergo a substantial change after that date.

Existing products are thus not automatically exempt. A substantial change under the CRA is a post‑marketing modification that affects conformity with the essential cybersecurity requirements or changes the intended purpose. A security‑relevant functional update can fall under that. In that case an older product may become subject to the CRA’s full requirements even though it was placed on the market before the cut‑off date.

That limitation does not apply to the reporting obligations under Article 14. Article 69(3) explicitly clarifies that the reporting obligations apply to all products with digital elements that fall within the scope and were placed on the market before 11 December 2027. The applicability of the reporting obligation to existing products is therefore not an inference but is stated directly in the text of the Regulation. Machines, controllers, sensors or software that have already been delivered and are in operation at customers’ sites are also subject to the reporting obligation from September 2026.

The obligation is not retroactive: vulnerabilities whose active exploitation was already known to a manufacturer before 11 September 2026 do not have to be reported after the fact. If, however, the manufacturer only becomes aware of active exploitation after that cut‑off date, the reporting obligation applies. This clarification comes from the second draft of the European Commission’s interpretative guidelines on the CRA (section on reporting obligations) and should be understood as a non‑final draft position.

What this means for manufacturers in mechanical and plant engineering

For manufacturers in the machinery, plant and equipment sectors this rule has far‑reaching consequences. The entire installed portfolio of connected products, from controllers through gateways to software components, falls under the reporting obligation from September 2026, provided they are products with digital elements within the meaning of the CRA.

This requires manufacturers to know which of their existing products are affected, which software components are contained in those products and through which channels they find out about actively exploited vulnerabilities. The 24‑hour deadline for the early warning leaves no room for ad‑hoc processes. Those who do not have established procedures for vulnerability detection and reporting by 11 September 2026 will not be able to meet the deadlines.

Distinction from the NIS‑2 Directive

The CRA reporting obligations complement existing reporting duties under the NIS‑2 Directive, but do not replace them. NIS‑2 addresses the organisational cybersecurity of operators of essential services; Article 14 of the CRA targets the product‑related reporting obligation of manufacturers. A company can fall under both frameworks at the same time: as an operator under NIS‑2 and as a manufacturer under the CRA. The reporting obligations are not identical and require separate processes.

Conclusion

The CRA reporting obligations are the Cyber Resilience Act’s first binding operational requirement. They apply from 11 September 2026, and they also cover products that are already on the market. Focusing solely on the December 2027 cut‑off date risks overlooking an obligation that affects the entire existing product portfolio.

The key question is not whether a manufacturer is affected. For connected products with digital elements that is usually the case. The crucial question is whether internal processes for vulnerability detection and reporting will be in place in time.