Cyber Resilience Act

CRA reporting obligations apply since 2026-09-11

Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the ENISA Single Reporting Platform (SRP) within fixed deadlines. ACM Consultants clarifies your applicability, structures the 24/72-hour process and ensures clear responsibilities, reporting paths and evidence.

  • Clarify manufacturer applicability with confidence
  • Structure the 24/72-hour reporting process
  • Define responsibilities, evidence and reporting paths

Introduction

Classify the Cyber Resilience Act reliably for manufacturers

The Cyber Resilience Act (CRA) makes cybersecurity a binding product characteristic. For companies, this means more than implementing individual technical measures: product scope, roles, vulnerability management and reporting paths must work together across the entire product lifecycle. ACM Consultants combines regulatory classification with practical security and process structures.

Target groups

Executive management

Executive management is responsible for resources, roles and the entrepreneurial implementation of the CRA. ACM creates decision-making clarity, prioritizes action areas and makes risks transparent.

Product management and development

Product portfolios, technical documentation, development, updates and support converge here. ACM translates CRA requirements into robust workflows for product and software teams.

IT and information security leaders

They must detect, assess and escalate vulnerabilities and incidents within the required deadlines. ACM integrates CRA reporting paths into existing incident, vulnerability and security processes.

Overview

What the Cyber Resilience Act now requires

The CRA applies to products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. The regulation is already in force: the reporting obligations under Article 14 apply since 2026-09-11, while most other obligations apply from 2027-12-11. This creates concrete operational action needs for companies today.

Manufacturers must report actively exploited vulnerabilities and severe security incidents. Under Article 69(3), the obligation also covers products that were placed on the market before the CRA applies in full.

Reports are submitted through the ENISA Single Reporting Platform: an early warning within 24 hours, a complete notification within 72 hours and a final report afterwards.

Full application will add broader requirements for secure product development, vulnerability handling, updates, documentation and conformity. The current reporting process should therefore connect to the overall CRA implementation.

Quick Check

Is your company affected by the CRA?

This quick check gives an initial orientation regarding possible manufacturer applicability. It does not replace legal review; product scope, economic operator role and possible exemptions must be assessed case by case.

Do you place products with digital elements on the EU market under your name or brand?
Do your products contain software or are they directly or indirectly connected to a device or network?
Has your company assessed and documented whether a CRA exemption or specific sector regulation applies to the products concerned?
Please answer the questions for an initial assessment.

Requirements

What manufacturers must organize for CRA reporting

In an incident, the deadline begins when the manufacturer becomes aware of the issue. Reporting criteria, responsibilities and information flows must therefore be defined, documented and usable in practice beforehand.

Actively exploited vulnerabilities and severe security incidents must be reliably detected and assessed against clear reporting criteria. Inputs from product development, support, vulnerability management and incident response must converge for this.

It must be clear who assesses the matter, makes the reporting decision, submits the report and informs affected users. Deputies and approvals must not block the short deadlines.

Access, the responsible CSIRT, roles and deputies in the ENISA Single Reporting Platform must be clarified before an incident occurs. Technical access alone does not replace an aligned internal process.

An early warning must be submitted within 24 hours; within 72 hours, a complete notification follows with the information available at that time about the product, the matter and possible countermeasures.

For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or risk mitigation measure is available; for severe incidents, it is due within one month after the 72-hour notification. Affected users must also be informed appropriately.

Assessments, decisions, reports and measures must be documented traceably. Overlaps with NIS-2, GDPR and sector-specific obligations should be reflected in an aligned workflow.

Challenges

Typical starting points - structured and solvable

The biggest obstacle is rarely one single CRA requirement. The critical part is the interaction of product knowledge, security, legal input and short deadlines. These situations can be managed with clear decisions and prepared workflows.

Solution

CRA implementation that works in real incidents

ACM Consultants combines regulatory classification with information security and practical process design. You do not receive an isolated legal interpretation, but clear responsibilities, usable workflows and traceable evidence.

1

Scope and applicability

Systematically classify products, market roles, exemptions and legacy products.

Result: documented product scope and prioritized action needs.

2

Reporting process

Define reporting criteria, responsibilities, escalations, templates and the SRP workflow.

Result: practical 24/72-hour process.

3

Integration and evidence

Integrate CRA into incident, vulnerability, product and compliance processes and clarify interfaces with NIS-2 and GDPR.

Result: consistent workflows and traceable documentation.

4

Support and effectiveness

Support implementation, enable involved teams and test the reporting process with a realistic scenario.

Result: tested process with concrete improvement measures.

Top Consultants

Across all consulting topics, ACM convinces with both its service portfolio and many years of expertise. With broad IT know-how, ACM provides professional solutions for individual requirements. In-house or remote - according to customer needs.

Top-Consultant 2022 | ACM Consultants GmbH
Top-Consultant 2023 | ACM Consultants GmbH
Top-Consultant 2024 | ACM Consultants GmbH

Approach

Four steps toward robust CRA processes

We start with applicability and the currently urgent reporting process. Existing structures are then used, gaps are closed and the workflow is tested in practice.

01

Quick check and scope

Initial classification of products, market roles, possible exemptions and urgent action needs.

02

Analysis

Assessment of existing incident, vulnerability, product and reporting processes and identification of concrete gaps.

03

Implementation

Definition of reporting criteria, responsibilities, escalation paths, templates, SRP roles and required evidence.

04

Practical test and improvement

Run through a realistic reporting case, test the 24/72-hour workflow and implement targeted improvements.

Use Cases

CRA knowledge in compact form for practice

The ACM information sheet summarizes reporting obligations, deadlines, reporting path and initial preparation steps for manufacturers.

CRA reporting obligation: act since 2026-09-11

Manufacturers / product companies

CRA reporting obligation: act since 2026-09-11

Compact overview of Article 14 CRA, 24/72-hour deadlines, final report, user information, Single Reporting Platform and preparatory measures.

Download information sheet

FAQ

Frequently asked questions about the Cyber Resilience Act

Direct answers on scope, reporting obligations, deadlines and the classification of the Cyber Resilience Act.

The Cyber Resilience Act (CRA) is a directly applicable EU regulation for the cybersecurity of products with digital elements. It requires manufacturers, among other things, to provide secure products, handle vulnerabilities in a structured way and, since the reporting obligations entered into force, report certain vulnerabilities and security incidents.

The focus is on manufacturers that make products with digital elements available on the EU market. Importers and distributors also have their own review and action obligations; they can be considered manufacturers in particular if they offer a product under their own name or brand or substantially modify it.

These include hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Whether the CRA applies also depends on the specific market role and possible legal exemptions.

Manufacturers must report actively exploited vulnerabilities and severe security incidents that affect the security of a product with digital elements. The relevant point is when the manufacturer becomes aware of the reportable matter.

The early warning must be submitted within 24 hours after awareness, and the complete notification within 72 hours. A final report follows afterwards; informing affected users is an additional obligation and not a fourth part of the authority notification.

Yes. Under Article 69(3), the reporting obligation in Article 14 also applies to products within the CRA scope that were placed on the market before the regulation applies in full. The broader product and conformity obligations must be assessed separately.

The Single Reporting Platform (SRP) is the central online platform operated by ENISA for CRA reports. Manufacturers submit their report once to the responsible CSIRT; internally, access, roles and deputies must be clarified before an incident occurs.

The CRA primarily addresses the cybersecurity of products with digital elements and their lifecycle. NIS-2 primarily addresses certain entities and their organizational cybersecurity and risk management. In an incident, both regulatory frameworks and GDPR can be relevant in parallel.

Contact

Clarify CRA applicability and build robust reporting processes

Do you want to know which products are affected or whether your 24/72-hour process will work in an incident? ACM Consultants supports you from classification to practical implementation.

Get in touch

Or you would like to call us directly

Patrick Andreas > ACM Consultants GmbH | ACM Consultants GmbH Patrick Andreas Managing Director ACM +49 151 14665555

With us, you take centre stage!
We provide you with comprehensive advice on many different topics, identify the status quo of your company and create customised, target-oriented action plans. We are happy to put these into practice for you, but we also provide support in constellations with other service providers - in exactly the way that best serves your requirements.