The Cyber Resilience Act (CRA) will not become fully applicable until 11 December 2027 – however, the reporting obligations set out therein will already apply as of 11 September 2026. Affected companies therefore face an immediate need for action.
Manufacturers of products with digital elements (essentially all software and hardware products capable of establishing a direct or indirect data or network connection) are henceforth required under the CRA to report two categories of events as soon as they become aware of them:
The manner in which or the person through whom such knowledge was obtained – whether through the manufacturer's own monitoring, external security researchers, or affected users – is irrelevant.
In addition, the CRA establishes a voluntary reporting mechanism that is open not only to manufacturers but also to other actors – such as security researchers, operators of critical infrastructure, or users.
Reports must be submitted via a central platform to ENISA and to the competent CSIRT of the relevant Member State. The CRA provides for a three-tier reporting scheme for both types of events:
It is crucial to recognise that the CRA does not stand in isolation but forms part of a growing framework of European and national reporting obligations in the areas of cyber security, data protection, and IT. The CRA reporting obligations apply alongside the reporting obligations under other legislative instruments such as the GDPR, the NIS2 Directive / BSIG, DORA, and the AI Act.
One and the same incident – for example, a cyberattack exploiting a vulnerability in a connected device that also involves personal data – may simultaneously trigger reporting obligations under the CRA, the GDPR, and, depending on the sector and type of undertaking, also under NIS-2/BSIG or DORA.
In order to effectively address the obligations arising in parallel under the various legislative instruments, an integrated governance approach is recommended. This approach should coordinate the respective reporting triggers, relevant reporting channels, and applicable deadlines, while consolidating them within a unified internal process framework.
In concrete terms, this means:
Companies that begin now to review and further develop their incident response processes and reporting structures will not only achieve CRA compliance but will also strengthen their resilience vis-à-vis the entire regulatory environment.
Do you have questions about the reporting obligations under the CRA or need support with implementation? We are happy to advise you.