Skip to main content

Reporting Obligations under the Cyber Resilience Act: What Companies Need to Know Now

The Cyber Resilience Act (CRA) will not become fully applicable until 11 December 2027 – however, the reporting obligations set out therein will already apply as of 11 September 2026. Affected companies therefore face an immediate need for action.

What Must Be Reported and by Whom?

Manufacturers of products with digital elements (essentially all software and hardware products capable of establishing a direct or indirect data or network connection) are henceforth required under the CRA to report two categories of events as soon as they become aware of them:

  • Actively exploited vulnerabilities contained in their product; and
  • Severe security incidents that have an impact on the security of their product.

The manner in which or the person through whom such knowledge was obtained – whether through the manufacturer's own monitoring, external security researchers, or affected users – is irrelevant.

In addition, the CRA establishes a voluntary reporting mechanism that is open not only to manufacturers but also to other actors – such as security researchers, operators of critical infrastructure, or users.

How and to Whom Must Reports Be Made?

Reports must be submitted via a central platform to ENISA and to the competent CSIRT of the relevant Member State. The CRA provides for a three-tier reporting scheme for both types of events:

  • Tier 1: Early warning – without undue delay, and no later than 24 hours after becoming aware, with brief initial information (for vulnerabilities: affected Member States; for security incidents: suspicion of unlawful or malicious acts)
  • Tier 2: Detailed notification – within 72 hours, including information on the affected product, the nature of the exploitation or incident, and any corrective measures taken
  • Tier 3: Final report – for actively exploited vulnerabilities, no later than 14 days after a corrective measure has been made available; for severe security incidents, within one month of the 72-hour notification

The CRA within the Framework of Reporting Obligations

It is crucial to recognise that the CRA does not stand in isolation but forms part of a growing framework of European and national reporting obligations in the areas of cyber security, data protection, and IT. The CRA reporting obligations apply alongside the reporting obligations under other legislative instruments such as the GDPR, the NIS2 Directive / BSIG, DORA, and the AI Act.

One and the same incident – for example, a cyberattack exploiting a vulnerability in a connected device that also involves personal data – may simultaneously trigger reporting obligations under the CRA, the GDPR, and, depending on the sector and type of undertaking, also under NIS-2/BSIG or DORA.

An Integrated Approach as the Solution

In order to effectively address the obligations arising in parallel under the various legislative instruments, an integrated governance approach is recommended. This approach should coordinate the respective reporting triggers, relevant reporting channels, and applicable deadlines, while consolidating them within a unified internal process framework.

In concrete terms, this means:

  • Early qualification of an incident: Which reporting obligations are triggered – and under which regime?
  • Coordinated initial response: Internal responsibilities (e.g. IT security, data protection, compliance, legal) must work together from the outset, as the deadlines for initial notifications are very short (in some cases 24 hours).
  • Unified documentation: Incidents, measures, and notifications must be documented across all regimes in order to avoid redundancies and to fulfil record-keeping obligations.
  • Regular review: The regulatory environment continues to evolve. The integrated approach must be continuously adapted to new or amended requirements.

Companies that begin now to review and further develop their incident response processes and reporting structures will not only achieve CRA compliance but will also strengthen their resilience vis-à-vis the entire regulatory environment.

Do you have questions about the reporting obligations under the CRA or need support with implementation? We are happy to advise you.

Did you find this useful?

Thanks for your feedback