Centro apskaita
UAB Centro apskaita
Get a Quote
Back to news

EU Cyber Resilience Act: Mandatory 24-Hour Incident Reporting for Hardware and Software Manufacturers

Starting September 11, 2026, manufacturers of connected hardware and software in the EU must report actively exploited vulnerabilities within 24 hours under CRA rules.

C
UAB Centro apskaita
September 15, 20262 min read1
Iliustracinė nuotrauka: Kibernetinio atsparumo aktas: įsigalioja privalomi pranešimai gamintojams per 24 valandas

On September 11, 2026, the mandatory reporting requirements under Article 14 of Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), come into effect across the European Union. While the full framework of CRA obligations—including CE marking and conformity assessments—will apply from December 11, 2027, the rules governing incident and vulnerability notifications take precedence.

The requirement applies to manufacturers of products with digital elements made available on the EU market. This encompasses both hardware and software, including IoT connected devices, industrial sensors, operating systems, firmware, and mobile applications that maintain a direct or indirect network connection.

Manufacturers must submit mandatory notifications under two specific triggers: upon identifying an actively exploited vulnerability, or following a severe incident that compromises product security. Reporting operates under a strict three-tier timeline:

1. Early Warning: Must be submitted within 24 hours of becoming aware of the actively exploited vulnerability or severe incident. It must specify whether malicious activity is suspected and whether cross-border impact exists.
2. Detailed Incident Notification: Must be submitted within 72 hours, providing an initial impact assessment, severity metrics, and applied corrective measures.
3. Final Report: Must be filed within 14 days after releasing a remediation or patch (for vulnerabilities) or within 1 month from incident mitigation (for severe incidents).

Submissions are managed centrally through the CRA Single Reporting Platform (CRA-SRP), operated by the European Union Agency for Cybersecurity (ENISA). The platform automatically routes alerts to the designated national Computer Security Incident Response Teams (CSIRTs)—in Lithuania, this role is held by the National Cyber Security Centre (NKSC).

Article 14 also requires manufacturers to notify product users without undue delay about relevant vulnerabilities or incidents, supplying clear mitigation guidelines until an official security update is deployed.

Under Article 64 of the CRA, non-compliance with Article 14 reporting duties carries administrative fines of up to €15,000,000 or up to 2.5% of total worldwide annual turnover from the preceding financial year, whichever is higher.

C

UAB Centro apskaita

September 15, 2026

Back to news

Leave the accounting worries to professionals

Save time and avoid mistakes.

Learn more