24-Hour Reporting Deadline Under the EU Cyber Resilience Act Now in Effect
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: September 2026
- Category: Data Security, General Obligations
Since 11 September 2026, reporting obligations under the EU Cyber Resilience Act (CRA) are applicable to manufacturers. Under the CRA, a manufacturer is whoever puts a product with software or connectivity on the market under their own name or brand, regardless of whether they charge for it or not, and anyone who rebrands or significantly changes such a product.
Many companies still think of the CRA as a 2027 issue, since the full security requirements apply from December 2027, but manufacturers already must report security issues within strict deadlines, including for products they placed on the EU market years ago.
What Companies Need to Report, and How Fast
If you become aware of an actively exploited vulnerability or a severe security incident in one of your products, you must send an early warning within 24 hours, a detailed notification within 72 hours, and a final report afterwards. Reports are submitted through a single reporting platform run by ENISA, the EU cybersecurity agency, and go to the national CSIRT designated as coordinator. Manufacturers must also inform affected users about the issue and, where needed, about the steps they should take to protect themselves.
Missing these deadlines can cost up to €15 million or 2.5% of your global annual turnover. Beyond fines, a missed or late report can damage trust with authorities, customers, and business partners at exactly the moment a company is under pressure from a security incident.
Why a Representative Makes Sense
For manufacturers based outside the EU, the CRA offers a voluntary but valuable option: appointing an authorized representative in the EU. The appointment also answers a question that becomes urgent the moment an incident occurs: which authority do we report to?
Under the CRA, a non-EU manufacturer reports to the CSIRT of the Member State where its representative is located. Without one, responsibility shifts down the chain to importers, distributors, or wherever most users are, which can leave you guessing about which authority is in charge. In a supply chain spanning several countries, that can create confusion and delay, and a 24-hour deadline leaves no room for either.
An authorized representative therefore provides clarity, a stable point of contact with EU authorities, and local support when every hour counts. It doesn't shift the manufacturer's core responsibility for product security, but it makes meeting that responsibility far more manageable.
What You Should Do Now
Check whether your products fall under the CRA, make sure your team can meet the 24-hour deadline at any time, and consider appointing an authorized representative before your first incident forces the decision.
We at DP-Dock are happy to act as your authorized representative under the CRA. Please contact us at any time to receive further information or to schedule a call.