The cybersecurity of technology products is entering a new phase in Europe. Since 11 September 2026, some of the first significant obligations under the Cyber Resilience Act (CRA) have started to apply, particularly those relating to the notification of actively exploited vulnerabilities and severe incidents.
This does not mean that every European company must now report every vulnerability to the authorities. The obligations that have just started to apply primarily concern manufacturers of certain hardware and software products placed on the European Union market.
However, the CRA will also have implications for distributors, importers, technology providers and companies purchasing digital solutions. Understanding what is changing now will help businesses prepare before the regulation becomes fully applicable on 11 December 2027.
What is the Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847 and establishes common cybersecurity requirements for products with digital elements placed on the European Union market.
Its aim is to ensure that security no longer depends solely on how customers configure a product after purchasing it. Manufacturers must take cybersecurity into account throughout the design, development, maintenance and lifecycle of the product.
The concept of a “product with digital elements” is broad. It can include complete products as well as hardware or software components marketed separately whose intended use involves a direct or indirect connection to another device or network.
This may include operating systems, applications, network devices, software components, certain IoT devices and many other solutions commonly found within business infrastructures.
The regulation entered into force on 10 December 2024, but its obligations are being introduced progressively. Most of its requirements will apply from December 2027, while certain provisions have already started to apply during 2026.
What changed on 11 September 2026?
The main development in September is the application of Article 14 of the Cyber Resilience Act.
Since 11 September 2026, affected manufacturers must report actively exploited vulnerabilities and severe incidents that have an impact on the security of their products with digital elements.
The procedure establishes several deadlines that affected organisations should pay particular attention to:
- 24 hours: an initial alert from the moment the manufacturer becomes aware of an actively exploited vulnerability or severe incident.
- 72 hours: submission of a more complete notification providing additional information about the issue.
- Final report: in certain cases, detailed information on the incident, the measures taken and its resolution must subsequently be submitted.
For an actively exploited vulnerability, the final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For certain severe incidents, the deadline may extend to one month after the 72-hour notification.
This is an important change because vulnerability management is no longer solely an internal technical process. In certain circumstances, it also becomes part of a formal reporting procedure involving the relevant authorities.
A single European platform for reporting vulnerabilities
To centralise these communications, ENISA has launched the CRA Single Reporting Platform (SRP).
The platform became operational on 11 September 2026 and allows organisations to submit a single notification that can subsequently be distributed among the relevant CSIRTs and competent authorities.
This is intended to prevent manufacturers marketing a product across several Member States from having to manage separate reporting processes in each country.
For affected companies, however, having a common platform does not remove a fundamental requirement: they must be able to quickly identify what happened, which products and versions are affected and what measures users can take.
Without an inventory, traceability and a vulnerability management procedure, meeting a 24- or 72-hour deadline can become a significant operational challenge.
Which companies are actually affected by the Cyber Resilience Act?
It is important to avoid interpreting the regulation too broadly.
A company that simply uses computers, firewalls, business applications or connected devices does not automatically become a manufacturer and, for that reason alone, is not subject to the reporting obligation currently established under Article 14.
The CRA primarily directs its obligations towards manufacturers placing products with digital elements on the market under their own name or trademark. It also establishes specific responsibilities for other economic operators, including importers, distributors and authorised representatives.
There is also another situation that some organisations should examine carefully: a company may be considered a manufacturer if it markets a product with digital elements under its own name or trademark, even when some of its development or manufacturing has been carried out by third parties.
It is therefore not enough to ask whether the company manufactures hardware. Organisations should also determine whether they develop, commission, integrate, market or distribute any digital product and understand exactly what role they play within the supply chain.
The Cyber Resilience Act and NIS2 are not the same
The succession of new European cybersecurity rules can create some confusion. The CRA and NIS2 are both related to improving Europe’s digital resilience, but they take different approaches.
NIS2 establishes risk management and security obligations for certain entities and sectors. The Cyber Resilience Act focuses primarily on the security of products with digital elements placed on the European market.
A company may be affected by one of these frameworks, by both, or indirectly through requirements passed down the supply chain by its customers and suppliers.
For this reason, each framework should be analysed separately rather than treating “cybersecurity compliance” as a single generic concept.
What businesses should review during 2026
Although many organisations still have until December 2027 before certain obligations apply, waiting until then may mean having to resolve issues affecting processes, development, documentation and suppliers within a very short period.
A good starting point is to review the following areas:
- Determine the company’s role under the CRA. Identify whether the organisation acts as a manufacturer, importer, distributor, integrator or simply as a user of digital products.
- Maintain an up-to-date inventory. Knowing which products, software components, versions, firmware, libraries and dependencies are in use makes it easier to respond quickly when a vulnerability appears.
- Define a vulnerability management procedure. Organisations should establish how internally or externally identified vulnerabilities are received, classified, investigated and resolved.
- Prepare an incident response procedure. Technical, security, management and compliance teams should know who makes decisions and what information needs to be collected when an incident occurs.
- Review the technology supply chain. Many products include components developed by third parties. Understanding these dependencies is essential when assessing a vulnerability correctly.
- Document the actions taken. Risk assessments, updates, mitigation measures, affected versions and decisions made should be traceable afterwards.
- Review update and patch management processes. Identifying a vulnerability provides little protection if the organisation does not have effective mechanisms for deploying a fix.
- Prepare for December 2027. The CRA will introduce broader requirements relating to security by design, security by default, risk assessment, vulnerability management, documentation and product conformity.
This work should not be handled solely by the legal department. A significant part of compliance depends on knowing which assets exist, how they are configured and how they are managed throughout their lifecycle.
What changes for a company that only purchases technology?
Even when a company is not a manufacturer and is not directly subject to the September 2026 reporting obligations, the Cyber Resilience Act may still change the way it selects and manages technology suppliers.
The regulation aims to ensure that manufacturers maintain the security of their products throughout the support period, manage vulnerabilities and provide the information needed to use those products securely.
This creates an opportunity to introduce additional criteria into technology purchasing decisions.
Before purchasing a solution, it will become increasingly important to understand how long it will remain supported, how security updates are delivered, how the manufacturer communicates vulnerabilities and what happens when the product reaches the end of its lifecycle.
Within a business infrastructure, these issues are particularly important for firewalls, switches, operating systems, critical applications, IoT devices, remote access solutions and any technology connected to the corporate network.
Keeping devices in operation after they stop receiving security updates can unnecessarily increase an organisation’s attack surface.
For this reason, an effective business cybersecurity strategy should include not only defensive measures but also proper management of the lifecycle of technology assets.
Vulnerability management is becoming even more important
One of the central messages of the Cyber Resilience Act is that the security of a product does not end when it is placed on the market.
A vulnerability may appear months or years after installation. What makes the difference is the ability of manufacturers and the companies using their technology to detect it, assess its impact and apply the necessary corrective measures.
In business environments, this requires a combination of asset inventory, monitoring, patch management, network segmentation and protective mechanisms capable of reducing the potential impact while a permanent update is being prepared.
Perimeter security solutions for businesses, for example, can provide additional layers of protection, segmentation and traffic control against certain risks affecting internal systems.
Likewise, having continuous system maintenance and monitoring makes it easier to identify unusual behaviour and keep critical infrastructure components up to date.
The CRA should not be treated solely as a regulatory obligation
The Cyber Resilience Act introduces new requirements, but it also reinforces practices that should already form part of any mature technology strategy.
Knowing which assets are in use, controlling versions, keeping products within their supported lifecycle, managing vulnerabilities and documenting incidents all improve security regardless of whether a company is directly subject to the regulation.
The application of the reporting obligations from September 2026 is therefore a good opportunity to review how the organisation currently manages its technology products and suppliers.
During 2026, the European Commission also published guidance to help manufacturers and businesses prepare, including clarifications regarding the regulation’s scope, substantial modifications, support periods, risk assessments and reporting obligations.
For further information, businesses can consult the European Commission’s official information on Cyber Resilience Act reporting obligations.
Frequently asked questions about the Cyber Resilience Act
These are some of the most common questions regarding the changes introduced by the CRA and its implementation timeline.
When does the Cyber Resilience Act apply?
The Regulation entered into force on 10 December 2024, but its application is progressive. The reporting obligations under Article 14 have applied since 11 September 2026, while most of the CRA will apply from 11 December 2027.
Do all companies have to report vulnerabilities within 24 hours?
No. The obligation that started to apply in September 2026 primarily concerns manufacturers of products with digital elements covered by the CRA. Simply using business software or hardware does not automatically make a company subject to this reporting requirement.
What needs to be reported?
Affected manufacturers must report actively exploited vulnerabilities and certain severe incidents that have an impact on the security of their products with digital elements. The first alert must be submitted within a maximum of 24 hours, followed by the additional information required.
Where should notifications be submitted?
ENISA has developed the Cyber Resilience Act Single Reporting Platform. It has been operational since 11 September 2026 and acts as a common point for managing mandatory notifications.
What should a company do if it does not manufacture digital products?
Even without direct reporting obligations, it should review the support and lifecycle of its technology products, update management processes, suppliers, asset inventory and vulnerability response procedures.
Prepare your infrastructure for a more demanding cybersecurity environment
The Cyber Resilience Act reinforces a clear trend: businesses will need to understand the digital products on which their operations depend and demand stronger security guarantees throughout their lifecycle.
At Inmove IT Solutions, we help businesses improve the technical management of their systems through infrastructure inventory and maintenance, system updates, monitoring, perimeter security and protection measures adapted to each environment.
If you want to review how your company manages its systems, vulnerabilities and technology lifecycle, we can help you define the technical measures needed to reduce risk and improve your ability to respond.
Contact Inmove IT Solutions and tell us about your company’s technology requirements.




