Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

37418

Cyber Resilience Act: 24-Hour Reporting Changes Product Security Responsibility

What Is Changing

From 11 September 2026, the reporting obligations under the Cyber Resilience Act (CRA) begin to apply. They affect manufacturers of products with digital elements made available on the European Union market.

This includes software, connected devices, hardware with digital functions and products that exchange data over a network. The core idea is simple: when a product is part of the digital environment of users and organizations, its security is no longer only an internal manufacturer concern.

This new stage does not mean that all CRA requirements start immediately. The main compliance rules will apply from 11 December 2027. But reporting obligations begin earlier — on 11 September 2026.

What Must Be Reported

Manufacturers must report two categories of events:

  • actively exploited vulnerabilities in their products;
  • severe incidents affecting the security of the product.

For an actively exploited vulnerability, the manufacturer must submit an early warning without undue delay and in any event within 24 hours of becoming aware of it.

Further information is expected in subsequent reporting stages, including a description of the vulnerability, the affected product, possible consequences and measures taken or planned.

This shifts the topic from “do we know about the vulnerability” to “can we prove when we became aware, what we checked and what we did.”

Why 24 Hours Is an Operational Test

The 24-hour deadline is not only a legal deadline. It is a test of process maturity.

To report on time, the manufacturer must quickly answer several questions:

  • is the vulnerability actually being exploited;
  • which versions or products are affected;
  • is there evidence from customers, researchers, logs or external sources;
  • is there a temporary risk reduction measure;
  • who owns the reporting decision;
  • how are technical, legal, product and communications teams coordinated.

In a weak process, 24 hours are spent collecting internal information. In a prepared process, those 24 hours are used for confirmation, risk reduction and clear reporting.

The Single Reporting Platform

ENISA (European Union Agency for Cybersecurity) is preparing the Single Reporting Platform. It is expected to be operational from 11 September 2026.

The goal is to provide manufacturers with one channel for submitting notifications, while competent teams in Member States receive information in a structured way.

This matters for the whole market. One product may be sold in many countries, used across different sectors and embedded in critical processes. When a vulnerability is already being actively exploited, slow or incomplete communication increases risk for all users of the product.

Who Is Affected

CRA affects manufacturers of products with digital elements made available on the EU market. This may include:

  • software products;
  • connected devices;
  • industrial and network devices;
  • products with remote control or data exchange;
  • components integrated into other digital products.

The regulation also matters for companies outside the EU if their products are made available on the European market.

For some organizations, this will be a new type of obligation. For others already working under NIS2 (Network and Information Security Directive 2), ISO 27001 or sector-specific requirements, CRA adds another layer: responsibility for product security across its lifecycle.

What Companies Should Prepare

Manufacturers and organizations developing or maintaining digital products need to prepare processes, not only documents.

Practical checks:

  • whether there is an internal process for receiving and assessing vulnerability reports;
  • who decides whether a vulnerability is actively exploited;
  • whether affected products, versions and customers can be identified;
  • whether teams can gather evidence within 24 hours;
  • whether a temporary risk reduction procedure exists;
  • whether technical, legal, product and communications teams are coordinated;
  • whether reporting templates and follow-up communication are prepared;
  • whether vulnerability remediation and customer notification are tracked.

The core question is not only “do we know the regulation.” It is “can we act fast enough when exploitation is real.”

DIAMATIX Comment

From the DIAMATIX perspective, the Cyber Resilience Act moves cybersecurity closer to the product, not only the infrastructure.

This is an important change. When a vulnerability is actively exploited, the manufacturer must know what is happening, what the scope is, which customers are affected and what actions were taken. These answers are not built on the day of the incident. They depend on prior visibility, logs, ownership and response readiness.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes can support this readiness by connecting vulnerabilities, assets, logs, external signals and behavior in the environment. This helps the organization not only report, but report with better context and clearer evidence.

For companies offering products on the European market, CRA is no longer a distant regulatory topic. The 24-hour reporting requirement demands operational preparation now.

Questions for CISO, Product and Legal Teams

  • Do we know which of our products fall under CRA?
  • Do we have a process for receiving reports from customers, researchers and external sources?
  • Can we determine within 24 hours whether a vulnerability is actively exploited?
  • Do we have evidence for affected versions, customers and environments?
  • Who makes the reporting decision?
  • How are technical, legal, product and communications teams coordinated?
  • How do we notify customers without delay and without unverified claims?
  • How do we prove that corrective actions were taken?

The practical takeaway: CRA turns vulnerability management into a leadership process with short deadlines, evidence and clear accountability.

 

Prepare the process before the 24-hour clock starts

DIAMATIX can help assess reporting readiness, vulnerability management, logs, incident response and alignment with regulatory requirements such as CRA, NIS2 and ISO 27001.

Request a CRA and vulnerability management readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • European Commission. Cyber Resilience Act — Reporting obligations.
  • European Commission. Cyber Resilience Act — Summary of the legislative text.
  • EUR-Lex. Regulation (EU) 2024/2847 — Cyber Resilience Act.
  • ENISA. Single Reporting Platform.
  • ENISA. Single Reporting Platform — Frequently Asked Questions.
  • European Commission. Cyber Resilience Act implementation guidance.

This article summarizes publicly available information as of September 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.