Cyber Resilience Act, Manufacturer Reporting Obligations
Regulation (EU) 2024/2847, Art. 14
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 12 days, effective 11 September 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This duty binds now: the reporting obligations of Article 14 have applied to a product with digital elements since 11 September 2026.
- Notify the CSIRT designated as coordinator for your main establishment and ENISA, through the single reporting platform, of any actively exploited vulnerability you become aware of in your product: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available.
- Notify the same recipients of any severe incident affecting the security of your product on the same 24-hour early warning and 72-hour incident notification clock, followed by a final report within one month of the incident notification.
- After becoming aware of the vulnerability or incident, inform the affected users, and where appropriate all users, of it and of any risk mitigation or corrective measures they can take.
- Apply this to every product with digital elements you have on the EU market, including one placed there before 11 December 2027, because Article 69(3) exempts Article 14 from the transitional rule that spares existing products until they are substantially modified.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 64(2): non-compliance with the obligations set out in Articles 13 and 14 (together with the essential cybersecurity requirements of Annex I) carries a higher tier of up to EUR 15,000,000 or 2.5 percent of worldwide annual turnover, whichever is higher. Article 64(10)(a) exempts manufacturers qualifying as microenterprises or small enterprises from the administrative fine for missing the Article 14(2)(a) or 14(4)(a) 24-hour early-warning deadline specifically, and Article 64(10)(b) exempts open-source software stewards from administrative fines for any infringement of the Regulation.
- Rule
- Higher of
- As of
- 8 September 2026
- Currency
- EUR
- Fixed cap
- 15,000,000
- Turnover percentage cap
- 2.5
Who enforces it
Enforcement body
The market surveillance authority designated by each EU Member State under Article 52 of the Regulation, working with the CSIRT designated as coordinator and ENISA under the single reporting platform established by Article 16.
Enforcement record
The Regulation's own applicability provision, Article 71(2), states that the reporting obligations of Article 14 apply from 11 September 2026, ahead of the Regulation's general application date of 11 December 2027. Before 11 September 2026 no manufacturer was subject to the Article 14 duty, so no market surveillance authority could have taken an enforcement action under it in the period leading up to that date. actions_per_year is recorded as 0 for the period before 11 September 2026 on the strength of the applicability article itself; the duty has applied for under a week as of the date above, too briefly for a register of enforcement action under it to exist yet.
- As of
- 17 September 2026
- Source link
- https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
Settledness
- As of
- 8 September 2026
- Guidance link
- https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- Guidance body
- European Commission, Directorate-General for Communications Networks, Content and Technology (DG CONNECT)
- Open questions
- When does a manufacturer become "aware" of an actively exploited vulnerability or severe incident for the purpose of starting the 24-hour early warning clock: on the first internal report reaching any employee, or only once a function within the manufacturer responsible for cybersecurity has confirmed it?
What it reaches
Obligation class
Reporting, Security
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r2847
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 14 requires a manufacturer to notify any actively exploited vulnerability or severe incident affecting a product with digital elements to the CSIRT designated as coordinator for its main establishment and simultaneously to ENISA, through the single reporting platform established under Article 16.
For a vulnerability, the manufacturer submits an early warning within 24 hours of becoming aware, a fuller vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the same 24-hour early warning and 72-hour incident notification apply, followed by a final report within one month of the incident notification.
After becoming aware of either, the manufacturer must inform the affected users of the product, and where appropriate all users, of the vulnerability or incident and of any risk mitigation or corrective measures they can take. Article 65 makes Directive (EU) 2020/1828 on representative actions apply to an infringement of this Regulation that harms, or may harm, the collective interests of consumers, letting a qualified consumer-protection entity, not an individual consumer, bring that action.
When LexLint raises it
distributes_software_productships_mobile_app
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2024/2847
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.