Cyber Resilience Act: Reporting Obligations apply from 11 September 2026
The Cyber Resilience Act (CRA) aims to ensure that products with digital elements (which is broadly defined) are designed, developed, and maintained with appropriate levels of cybersecurity. Most of the CRA’s obligations will apply from 11 December 2027, however, the incident reporting obligations apply from 11 September 2026. This briefing considers the incoming incident reporting obligations and how organisations should prepare to meet those obligations.
What is in-scope?
The CRA applies to ‘products with digital elements’ (“PDEs”) made available on the EU market and which connect, directly or indirectly, to another device or network. This is a broad category of software and hardware products. Common examples include wearables and smart home devices; however, the range of in-scope PDEs is extensive and is not limited to consumer connected devices. Recent guidance from the European Commission published in July 2026 further confirms the broad scope of the CRA which can cover a range of PDEs, including:
- Standalone software, such as mobile apps and computer programs, whether digitally or physically distributed.
- Hardware with embedded software (e.g. IoT devices, laptops, tablets).
- Standalone hardware (e.g. integrated circuits, motherboards).
- Any combination of hardware and software supplied separately but intended to operate together.
The CRA has extraterritorial application and applies to any economic operator, irrespective of where they are established, placing or making PDEs available on the EU market.
What are the reporting obligations?
From 11 September 2026, manufacturers of PDEs must report two types of security incidents affecting PDEs:
- Actively Exploited Vulnerabilities: These are vulnerabilities for which there is reliable evidence that exploitation has been carried out by a malicious actor in a system.
- Severe Incidents: An incident is considered severe if it (a) negatively affects or is capable of negatively affecting the PDE’s ability to protect sensitive or important data or functions; or (b) has led, or is capable of leading, to malicious code being introduced or executed in the PDE or in the user’s network or systems.
Notifications are to be made simultaneously to the Computer Security Incident Response Team (CSIRT) of the EU Member State in which the manufacturer has its main establishment or in which its authorised representative is established and to the European Union Agency for Cybersecurity (ENISA) using ENISA’s Single Reporting Platform (SRP). The advantage of a SRP means that the manufacturer only has to make one notification, rather than having to notify multiple national authorities. ENISA has published a factsheet, FAQs and other materials with details of how to report incidents using the SRP. Notably, a phased reporting process applies as follows:
| Notification Phases | Actively Exploited Vulnerabilities | Severe Incidents |
|---|---|---|
| Phase 1 (24 hours): Early Warning | An early warning is to be submitted within 24 hours of becoming aware of the actively exploited vulnerability. | An early warning is to be submitted within 24 hours of becoming aware of the severe incident. |
| Phase 2 (72 hours): Vulnerability Notification / Incident Notification | Unless the relevant information has been submitted as part of phase 1, a vulnerability notification must be made within 72 hours. | Unless the relevant information has been submitted as part of phase 1, an incident notification must be made within 72 hours. |
| Phase 3: Final Report | Unless the relevant information has already been provided, a final report must be submitted no later than 14 days after a corrective or mitigating measure is available. | Unless the relevant information has already been provided, a final report must be submitted within 1 month of the incident notification. |
Who is the manufacturer?
The reporting obligations apply to the manufacturer of the PDE. Importantly, the manufacturer is not just the entity that develops or manufactures the PDE or that has a PDE designed, developed or manufactured for it. It is possible for others to also become a ‘manufacturer’ under the CRA and subject to the reporting obligations. For example, importers and distributors who market the PDE under their own name or trade mark or make a substantial modification to the PDE become a ‘manufacturer’ for the purposes of the CRA.
How to prepare
As is the case with any new law, the first step is to determine whether the CRA applies at all and, if so, to what extent does it apply to your organisation. Given the tight reporting timelines and various phases of information to be provided under the CRA, any organisation that is a ‘manufacturer’ of PDEs should review its internal processes to ensure that there are clear internal procedures and policies in place to enable it to comply with the reporting obligations under the CRA. Manufacturers will also need to consider how these align with potential notification obligations under other overlapping legislative regimes, such as the GDPR and NIS2 and it is important that the manufacturer’s processes are streamlined to enable it to address its applicable notification obligations in all of the jurisdictions in which it operates.
How we can assist
For assistance with the Cyber Resilience Act or other cyber security laws, please contact one of the key contacts below or your usual McCann FitzGerald LLP contact.
This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.


Select how you would like to share using the options below