Law / European Union

Cyber Resilience Act, Manufacturer Reporting Obligations

Regulation (EU) 2024/2847, Art. 14

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 5 days, effective 11 September 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This duty binds now: the reporting obligations of Article 14 have applied to a product with digital elements since 11 September 2026.
  • Notify the CSIRT designated as coordinator for your main establishment and ENISA, through the single reporting platform, of any actively exploited vulnerability you become aware of in your product: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available.
  • Notify the same recipients of any severe incident affecting the security of your product on the same 24-hour early warning and 72-hour incident notification clock, followed by a final report within one month of the incident notification.
  • After becoming aware of the vulnerability or incident, inform the affected users, and where appropriate all users, of it and of any risk mitigation or corrective measures they can take.
  • Apply this to every product with digital elements you have on the EU market, including one placed there before 11 December 2027, because Article 69(3) exempts Article 14 from the transitional rule that spares existing products until they are substantially modified.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 64(2): non-compliance with the obligations set out in Articles 13 and 14 (together with the essential cybersecurity requirements of Annex I) carries a higher tier of up to EUR 15,000,000 or 2.5 percent of worldwide annual turnover, whichever is higher. Article 64(10)(a) exempts manufacturers qualifying as microenterprises or small enterprises from the administrative fine for missing the Article 14(2)(a) or 14(4)(a) 24-hour early-warning deadline specifically, and Article 64(10)(b) exempts open-source software stewards from administrative fines for any infringement of the Regulation.

Rule
Higher of
As of
8 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
2.5

Who enforces it

Enforcement body

The market surveillance authority designated by each EU Member State under Article 52 of the Regulation, working with the CSIRT designated as coordinator and ENISA under the single reporting platform established by Article 16.

Settledness

As of
8 September 2026
Guidance link
https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
Guidance body
European Commission, Directorate-General for Communications Networks, Content and Technology (DG CONNECT)
Open questions
When does a manufacturer become "aware" of an actively exploited vulnerability or severe incident for the purpose of starting the 24-hour early warning clock: on the first internal report reaching any employee, or only once a function within the manufacturer responsible for cybersecurity has confirmed it?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 requires a manufacturer to notify any actively exploited vulnerability or severe incident affecting a product with digital elements to the CSIRT designated as coordinator for its main establishment and simultaneously to ENISA, through the single reporting platform established under Article 16.

For a vulnerability, the manufacturer submits an early warning within 24 hours of becoming aware, a fuller vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the same 24-hour early warning and 72-hour incident notification apply, followed by a final report within one month of the incident notification.

After becoming aware of either, the manufacturer must inform the affected users of the product, and where appropriate all users, of the vulnerability or incident and of any risk mitigation or corrective measures they can take. Article 65 makes Directive (EU) 2020/1828 on representative actions apply to an infringement of this Regulation that harms, or may harm, the collective interests of consumers, letting a qualified consumer-protection entity, not an individual consumer, bring that action.

When LexLint raises it

  • distributes_software_product
  • ships_mobile_app

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2024/2847

Back to the example  ·  Lint your app