Executive management
Executive management is responsible for resources, roles and the entrepreneurial implementation of the CRA. ACM creates decision-making clarity, prioritizes action areas and makes risks transparent.
Cyber Resilience Act
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the ENISA Single Reporting Platform (SRP) within fixed deadlines. ACM Consultants clarifies your applicability, structures the 24/72-hour process and ensures clear responsibilities, reporting paths and evidence.
Introduction
The Cyber Resilience Act (CRA) makes cybersecurity a binding product characteristic. For companies, this means more than implementing individual technical measures: product scope, roles, vulnerability management and reporting paths must work together across the entire product lifecycle. ACM Consultants combines regulatory classification with practical security and process structures.
Executive management is responsible for resources, roles and the entrepreneurial implementation of the CRA. ACM creates decision-making clarity, prioritizes action areas and makes risks transparent.
Product portfolios, technical documentation, development, updates and support converge here. ACM translates CRA requirements into robust workflows for product and software teams.
They must detect, assess and escalate vulnerabilities and incidents within the required deadlines. ACM integrates CRA reporting paths into existing incident, vulnerability and security processes.
Overview
The CRA applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. The regulation is already in force: the reporting obligations under Article 14 apply since 2026-09-11, while most other obligations apply from 2027-12-11. This creates concrete operational action needs for companies today.
Manufacturers must report actively exploited vulnerabilities and severe security incidents. Under Article 69(3), the obligation also covers products that were placed on the market before the CRA applies in full.
Reports are submitted through the ENISA Single Reporting Platform: an early warning within 24 hours, a complete notification within 72 hours and a final report afterwards.
Full application will add broader requirements for secure product development, vulnerability handling, updates, documentation and conformity. The current reporting process should therefore connect to the overall CRA implementation.
Quick Check
This quick check gives an initial orientation regarding possible manufacturer applicability. It does not replace legal review; product scope, economic operator role and possible exemptions must be assessed case by case.
Requirements
In an incident, the deadline begins when the manufacturer becomes aware of the issue. Reporting criteria, responsibilities and information flows must therefore be defined, documented and usable in practice beforehand.
Actively exploited vulnerabilities and severe security incidents must be reliably detected and assessed against clear reporting criteria. Inputs from product development, support, vulnerability management and incident response must converge for this.
It must be clear who assesses the matter, makes the reporting decision, submits the report and informs affected users. Deputies and approvals must not block the short deadlines.
Access, the responsible CSIRT, roles and deputies in the ENISA Single Reporting Platform must be clarified before an incident occurs. Technical access alone does not replace an aligned internal process.
An early warning must be submitted within 24 hours; within 72 hours, a complete notification follows with the information available at that time about the product, the matter and possible countermeasures.
For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or risk mitigation measure is available; for severe incidents, it is due within one month after the 72-hour notification. Affected users must also be informed appropriately.
Assessments, decisions, reports and measures must be documented traceably. Overlaps with NIS-2, GDPR and sector-specific obligations should be reflected in an aligned workflow.
Challenges
The biggest obstacle is rarely one single CRA requirement. The critical part is the interaction of product knowledge, security, legal input and short deadlines. These situations can be managed with clear decisions and prepared workflows.
Solution
ACM Consultants combines regulatory classification with information security and practical process design. You do not receive an isolated legal interpretation, but clear responsibilities, usable workflows and traceable evidence.
Systematically classify products, market roles, exemptions and legacy products.
Result: documented product scope and prioritized action needs.
Define reporting criteria, responsibilities, escalations, templates and the SRP workflow.
Result: practical 24/72-hour process.
Integrate CRA into incident, vulnerability, product and compliance processes and clarify interfaces with NIS-2 and GDPR.
Result: consistent workflows and traceable documentation.
Support implementation, enable involved teams and test the reporting process with a realistic scenario.
Result: tested process with concrete improvement measures.
Across all consulting topics, ACM convinces with both its service portfolio and many years of expertise. With broad IT know-how, ACM provides professional solutions for individual requirements. In-house or remote - according to customer needs.
Approach
We start with applicability and the currently urgent reporting process. Existing structures are then used, gaps are closed and the workflow is tested in practice.
Initial classification of products, market roles, possible exemptions and urgent action needs.
Assessment of existing incident, vulnerability, product and reporting processes and identification of concrete gaps.
Definition of reporting criteria, responsibilities, escalation paths, templates, SRP roles and required evidence.
Run through a realistic reporting case, test the 24/72-hour workflow and implement targeted improvements.
Use Cases
The ACM information sheet summarizes reporting obligations, deadlines, reporting path and initial preparation steps for manufacturers.
Manufacturers / product companies
Compact overview of Article 14 CRA, 24/72-hour deadlines, final report, user information, Single Reporting Platform and preparatory measures.
FAQ
Direct answers on scope, reporting obligations, deadlines and the classification of the Cyber Resilience Act.
The Cyber Resilience Act (CRA) is a directly applicable EU regulation for the cybersecurity of products with digital elements. It requires manufacturers, among other things, to provide secure products, handle vulnerabilities in a structured way and, since the reporting obligations entered into force, report certain vulnerabilities and security incidents.
The focus is on manufacturers that make products with digital elements available on the EU market. Importers and distributors also have their own review and action obligations; they can be considered manufacturers in particular if they offer a product under their own name or brand or substantially modify it.
These include hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Whether the CRA applies also depends on the specific market role and possible legal exemptions.
Manufacturers must report actively exploited vulnerabilities and severe security incidents that affect the security of a product with digital elements. The relevant point is when the manufacturer becomes aware of the reportable matter.
The early warning must be submitted within 24 hours after awareness, and the complete notification within 72 hours. A final report follows afterwards; informing affected users is an additional obligation and not a fourth part of the authority notification.
Yes. Under Article 69(3), the reporting obligation in Article 14 also applies to products within the CRA scope that were placed on the market before the regulation applies in full. The broader product and conformity obligations must be assessed separately.
The Single Reporting Platform (SRP) is the central online platform operated by ENISA for CRA reports. Manufacturers submit their report once to the responsible CSIRT; internally, access, roles and deputies must be clarified before an incident occurs.
The CRA primarily addresses the cybersecurity of products with digital elements and their lifecycle. NIS-2 primarily addresses certain entities and their organizational cybersecurity and risk management. In an incident, both regulatory frameworks and GDPR can be relevant in parallel.
Contact
Do you want to know which products are affected or whether your 24/72-hour process will work in an incident? ACM Consultants supports you from classification to practical implementation.
With us, you take centre stage!
We provide you with comprehensive advice on many different topics, identify the status quo of your company and create customised, target-oriented action plans. We are happy to put these into practice for you, but we also provide support in constellations with other service providers - in exactly the way that best serves your requirements.