Compliance & SecurityOct 11, 20265 min read

Cyber Resilience Act: What the new reporting obligations for software manufacturers mean now

As of 11 September 2026, the EU Cyber Resilience Act's reporting obligations are binding. Anyone selling software under their own brand on the EU market must report actively exploited vulnerabilities within 24 hours — regardless of company size.

Cyber Resilience Act: What the new reporting obligations for software manufacturers mean now — Compliance & Security

Since 11 September 2026, the EU Cyber Resilience Act (CRA) reporting obligations are binding — and they affect more companies than initially expected. Anyone offering software or digital products under their own name on the European market is a manufacturer under this regulation and must now actively report exploited vulnerabilities and serious security incidents. Here is what applies and what to do about it.

What the Cyber Resilience Act covers

The CRA establishes mandatory cybersecurity requirements for products with digital elements — from business software and mobile apps to SaaS platforms and connected hardware. The regulation entered into force on 10 December 2024. Most requirements — including secure-by-design principles, CE marking, and the obligation to provide a Software Bill of Materials (SBOM) — do not apply until 11 December 2027. However, the reporting obligations under Article 14 came into force earlier: since 11 September 2026, they apply to all manufacturers whose products are on the EU market.

The reporting obligations: what applies since September

Two categories of events trigger reporting: actively exploited vulnerabilities in digital products, and serious security incidents affecting product security. Reporting goes through the ENISA Single Reporting Platform (SRP) in a three-stage process:

DeadlineContentTrigger
24 hoursEarly warning: initial notification with available informationAwareness of the event
72 hoursDetailed report with further information on the incidentAwareness of the event
14 days (vulnerabilities) / 30 days (incidents)Final report after the security update or countermeasure is availableUpdate / fix available

Importantly, the 24-hour deadline starts from awareness — not after a completed analysis. This makes the challenge less technical than organisational. Many companies still lack clear internal responsibilities for deciding whether an event triggers CRA reporting, and for actually submitting the notification.

Who the CRA affects — including mid-sized software manufacturers

A manufacturer under the CRA is anyone who places a product with digital elements on the EU market under their own name or brand. This includes mid-sized companies that sell their own industry software, a web application, or a mobile app to third parties. Companies developing software solely for internal use are not in scope. Non-commercially released open-source software is also explicitly exempt. Micro-enterprises can use simplified procedures; the European Commission provides helpdesks and regulatory sandboxes for support.

The question also matters for companies that do not develop software themselves but have it built by partners and sell it under their own name: in this setup, the company acting as manufacturer bears the reporting obligation — not the development service provider.

What you should do now

  • Take stock: which of your products fall under the CRA definition of products with digital elements? SaaS products, apps, and connected services sold to third parties are generally in scope.
  • Assign responsibility: who internally identifies whether a reportable event has occurred — and who submits the notification to the ENISA Single Reporting Platform within the deadline?
  • Define an escalation process: from the product team through IT and compliance to company leadership, you need a clear pathway that works within 24 hours.
  • Start building your SBOM: a complete inventory of all software components becomes mandatory in December 2027 — starting now avoids a last-minute scramble.
  • Document your support period: the CRA requires manufacturers to declare how long they will provide free security updates — five years is the recommended baseline.

Anyone having custom software developed or selling their own digital products should integrate CRA compliance into product planning from the start — not as an afterthought. Our guide on selecting a software agency in Bavaria covers which criteria matter when choosing a development partner. For a structured assessment of your CRA obligations, our IT consulting team is happy to help.

Explore our IT consulting

This article was created with AI assistance and editorially reviewed.

Have an idea worth building?

Tell us where you want to go. We'll help you get there with software that performs.