From 11 September 2026, Article 14 of the Cyber Resilience Act applies. Actively exploited vulnerabilities and severe incidents must be reported within 24 hours. This also covers products that have been on the market for years.
A year ago we wrote about the Cyber Resilience Act and warned about the tight timeline. Now it is here: in ten days, on 11 September 2026, the reporting obligation under Article 14 of EU Regulation 2024/2847 enters into application. If you are planning around December 2027, you are planning around the wrong deadline. Full product conformity comes later. The reporting obligation comes now, and it applies from day one to all products with digital elements on the EU market.
What Must Be Reported
Article 14 has two triggers. First: actively exploited vulnerabilities, meaning vulnerabilities in your product for which there is reliable evidence that an attacker has exploited them without the system owner's permission. Second: severe incidents impacting the security of the product, for example when malicious code is introduced or the product's ability to protect sensitive data and functions is compromised. Ordinary bugs, routine patches and internally discovered vulnerabilities without exploitation are not reportable. The obligation is narrower than many fear, but when it applies, it applies hard.
The Deadlines: 24 Hours, 72 Hours, 14 Days
The early warning must be submitted within 24 hours of becoming aware. The full notification follows within 72 hours, including an assessment, severity and available countermeasures. The final report is due no later than 14 days after a corrective measure becomes available for vulnerabilities, and within one month of the 72-hour notification for severe incidents. In addition, you must inform impacted users, including available countermeasures. The clock starts when you become aware, not when your analysis is complete. If you only work out who reports what once the incident hits, the 24 hours are already gone.
The Single Reporting Platform
Reports are filed through ENISA's Single Reporting Platform (SRP): one submission that reaches the coordinating national CSIRT and ENISA simultaneously, instead of separate notifications to multiple authorities. At the time of writing, the platform is not yet live. ENISA plans to have it operational by 11 September, and the public URL will only be published at launch. The step-by-step guidance published in July and August 2026, however, already shows the process: registration runs through an EU Login account, which you can create today. During registration you select your coordinating CSIRT. For Swiss manufacturers without a main establishment in the EU, jurisdiction follows the EU authorised representative or where the products are made available.
Legacy Products Are Also In Scope
Article 69(3) makes it clear: the reporting obligation applies to all products with digital elements on the EU market, including those placed on the market before December 2027. A product you shipped in 2020 and have not touched since needs a working 24-hour reporting capability from September. Vulnerabilities in integrated third-party and open-source components do not release you either: if a component in your product is actively exploited, you report. Violations of the obligations under Articles 13 and 14 carry fines of up to 15 million euros or 2.5 percent of worldwide annual turnover. Reporting is where enforcement will bite first, because a missed report is the easiest violation to prove.
What You Can Do Before 11 September
None of this requires the platform. Create EU Login accounts for a responsible person and a deputy. Clarify which of your products fall within scope, because the 72-hour notification asks for product type and category. Build the early warning as an internal form matching ENISA's mandatory fields and name two people who can complete it outside office hours. Review your supplier contracts: without information duties on your suppliers, you may learn about an exploited component vulnerability too late. And make sure you can actually detect exploitation: without telemetry, monitoring or a channel for external vulnerability reports, you cannot report what you cannot see. Operators of critical infrastructure already know the mechanism from the ISG reporting obligation, but should note: CRA and ISG are separate obligations with separate recipients.
How MilesGuard Helps
MilesGuard prepares Swiss manufacturers for the reporting obligation: product inventory and scoping, a reporting process with templates for all three stages, integration with your vulnerability management and, on request, detection capability through our SIEM. A prepared reporting process costs an afternoon. An unprepared one costs the 24 hours you do not have.
