Since 11 September 2026, manufacturers of products covered by the EU Cyber Resilience Act (CRA) must report certain cybersecurity vulnerabilities and severe incidents. For product companies, this means having people and processes ready to respond when a security issue comes to light.
A responsibility that starts now
Much of the discussion around CRA has focused on December 2027, when the main requirements apply. But the reporting obligations are already in effect. Companies need to be able to recognise a reportable issue, assess its impact and get the right information to the authorities within short deadlines. The European Commission explains the reporting requirements here.
The rules concern manufacturers of hardware and software within the CRA’s scope, including many connected devices and industrial products. They also cover products already on the market. Selling a product under your own brand can make you the manufacturer for CRA purposes, even if a partner developed it. Read the Commission’s overview of who is covered.
What needs to be reported?
The reporting requirements focus on two situations: a security weakness in a product that is being actively exploited, or a severe incident affecting the product’s security. An ordinary software bug or a weakness found during testing does not automatically trigger a report. The company needs to assess what has happened and whether it meets the reporting criteria.
When reporting is required, manufacturers must act without undue delay. An early warning is due within 24 hours of becoming aware of the issue, followed by a more detailed notification within 72 hours of becoming aware. Both deadlines run from that same starting point. The initial warning can be submitted while the investigation continues.
The first reporting deadlines
Within
24 hours
Early warning
Within
72 hours
Detailed notification
Both deadlines run from awareness of a reportable vulnerability or incident. Act without undue delay. Follow-up reports are also required.
Reports go through ENISA’s Single Reporting Platform to the relevant national cybersecurity response team and ENISA. Follow-up reports are also required: for an exploited vulnerability, within 14 days after a corrective or mitigating measure becomes available; for a severe incident, within one month after the detailed notification. Affected users must also be informed about the issue and any protective steps they should take. These duties are set out in Article 14 of the CRA.
Make the response practical
Imagine receiving a security alert about one of your products on a Friday afternoon. Your team needs to know who will assess it, who can make decisions and who will handle reporting and customer communication. Clear responsibilities help people act while the facts are still emerging.
A useful starting point is to:
Know your products. Keep an overview of the products and software components that may be affected.
Assign responsibility. Agree who receives alerts, assesses urgency and coordinates the response, including outside normal office hours.
Prepare the process. Set out how to report, keep records and communicate with customers.
Practise together. Walk through a realistic scenario with the people involved and identify any gaps.
How Svep can help
Svep’s CRA Monitoring service helps companies keep track of relevant security risks and understand what they mean for their products. We can help assess alerts, identify affected products and support the next steps, including customer communication, documentation and reporting.
We also manage on-call coverage 365 days a year, including weekends and holidays. This means your engineers do not need to be on call during weekends and holidays, while Svep handles the monitoring and initial assessment of security alerts.
Our cybersecurity specialists work alongside engineers with experience in electronics, embedded software and connected products. This helps us connect a security alert with the product, its components and the people who depend on it.
Is your team ready to respond? Explore Svep’s CRA Monitoring service or contact us to discuss a practical approach for your products.

