24-Hour Reporting Deadline Under the EU Cyber Resilience Act Now in Effect

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: September 2026
  • Category: Data Security, General Obligations

Since 11 September 2026, reporting obligations under the EU Cyber Resilience Act (CRA) are applicable to manufacturers. Under the CRA, a manufacturer is whoever puts a product with software or connectivity on the market under their own name or brand, regardless of whether they charge for it or not, and anyone who rebrands or significantly changes such a product.

Many companies still think of the CRA as a 2027 issue, since the full security requirements apply from December 2027, but manufacturers already must report security issues within strict deadlines, including for products they placed on the EU market years ago.

What Companies Need to Report, and How Fast

If you become aware of an actively exploited vulnerability or a severe security incident in one of your products, you must send an early warning within 24 hours, a detailed notification within 72 hours, and a final report afterwards. Reports are submitted through a single reporting platform run by ENISA, the EU cybersecurity agency, and go to the national CSIRT designated as coordinator. Manufacturers must also inform affected users about the issue and, where needed, about the steps they should take to protect themselves.

Missing these deadlines can cost up to €15 million or 2.5% of your global annual turnover. Beyond fines, a missed or late report can damage trust with authorities, customers, and business partners at exactly the moment a company is under pressure from a security incident.

Why a Representative Makes Sense

For manufacturers based outside the EU, the CRA offers a voluntary but valuable option: appointing an authorized representative in the EU. The appointment also answers a question that becomes urgent the moment an incident occurs: which authority do we report to?

Under the CRA, a non-EU manufacturer reports to the CSIRT of the Member State where its representative is located. Without one, responsibility shifts down the chain to importers, distributors, or wherever most users are, which can leave you guessing about which authority is in charge. In a supply chain spanning several countries, that can create confusion and delay, and a 24-hour deadline leaves no room for either.

An authorized representative therefore provides clarity, a stable point of contact with EU authorities, and local support when every hour counts. It doesn't shift the manufacturer's core responsibility for product security, but it makes meeting that responsibility far more manageable.

What You Should Do Now

Check whether your products fall under the CRA, make sure your team can meet the 24-hour deadline at any time, and consider appointing an authorized representative before your first incident forces the decision.

We at DP-Dock are happy to act as your authorized representative under the CRA. Please contact us at any time to receive further information or to schedule a call.

European Cyber Resilience Act With Law and Shield Symbol
© Cre-AI-Tor / stock.adobe.com | #1456078408

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy /en/privacy-policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy /en/privacy-policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy /en/privacy-policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed