Kirkland Alert

The EU Cyber Resilience Act: Preparing for the New Reporting Obligations for “Products With Digital Elements

This Alert is based on an article by Kirkland & Ellis to be published in the Computer and Telecommunications Law Review (CTLR).

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) (the CRA) represents the first EU-wide horizontal framework imposing mandatory cybersecurity requirements on “products with digital elements”, including both hardware and software, placed on the EU market. The CRA imposes a broad range of obligations on manufacturers, importers and distributors of in-scope products, including security-by-design requirements, continuous vulnerability management, technical documentation, conformity assessment and CE marking, as well as mandatory incident and vulnerability reporting. The CRA may apply regardless of where a manufacturer is established, giving the regulation potential global reach.

This Alert is Part I of a two-part series providing an overview on the CRA. Part I focuses on the reporting obligations that took effect on 11 September 2026 and provides practical guidance for businesses preparing to meet these requirements. Part II (to follow) will address the remaining substantive CRA obligations, including essential cybersecurity requirements, vulnerability handling, technical documentation and conformity assessment, which are set to apply from 11 December 2027.

Products in Scope. The CRA applies to all “products with digital elements”, both hardware and software, that have a direct or indirect data connection to other devices or networks. Products in scope range from consumer IoT devices (smart watches, baby monitors, connected home devices) to enterprise software, industrial systems, operating systems and firmware. Products without data connection capability (such as standalone appliances with embedded firmware but no network features) are excluded.

SaaS. The CRA applies to hardware and software products, including embedded and on-premise software, but is not intended to cover software delivered purely as a service (which is already subject to the cyber reporting requirements under NIS2 and DORA). Pure SaaS offerings are therefore generally excluded, unless they qualify as “remote data processing” that is essential to a covered product’s core functionality. Determining whether remote processing is “essential” to core functionality will necessitate a case-by-case assessment. For example, a locally installed product that requires cloud-based features for its main use may be in scope if the remote component (i.e., the SaaS embedded in the product) is necessary for the product’s intended functionality (rather than being an optional add-on). SaaS providers should therefore not assume automatic exclusion from the CRA’s scope.

Other Key Exclusions. Certain products subject to specific EU sector regulations (e.g., medical devices, motor vehicles, aviation, marine equipment), products for national security or defence, open-source software developed outside commercial activity and spare parts replacing identical components are also excluded. Dual-use products with both civilian and defence applications remain subject to the CRA, other than where such products have been modified exclusively for national security or defence purposes.

Manufacturers, Importers and Distributors. The CRA imposes obligations on manufacturers1 as the primary obligation holders. An importer2 or distributor3 placing a product on the market under its own name or trademark, or who has made a “substantial modification” to the product, assumes full manufacturer obligations. Additionally, if an upstream component is separately placed on the market, the component vendor is also deemed a manufacturer under the CRA and assumes the corresponding obligations.

Reporting Obligations


The CRA introduces mandatory reporting obligations that apply from 11 September 2026 — the first substantive compliance deadline. These requirements demand immediate attention from manufacturers (which may also include importers, distributors and component manufacturers that assume manufacturer obligations as described above).

Article 14 Reporting: September 2026 Deadline


With effect from 11 September 2026, Article 14 of the CRA establishes a mandatory three-stage reporting process for actively exploited vulnerabilities and severe incidents identified in respect of in-scope products. Notifications must be submitted to the European Union Agency for Cybersecurity (ENISA) and the relevant national Computer Security Incident Response Team (CSIRT) through a single EU reporting platform (SRP). Via the SRP, manufacturers file a single notification addressed to the CSIRT coordinator for their main establishment, which the ENISA will then disseminate to other relevant CSIRTs in member states where the product is available.

Scope of September 2026 Reporting


The Article 14 reporting obligations apply to all products with digital elements that fall within the scope of the CRA — including products already on the market before 11 September 2026. This is a key exception to the general rule that the CRA applies only to products placed on the market after 11 December 2027. The Commission’s CRA FAQs (updated July 2026) provide the following clarifications:

  • Reporting obligations continue to apply after a product’s support period ends (unlike vulnerability handling obligations, which apply only during the support period).
  • If a manufacturer was aware of both a vulnerability and its active exploitation before 11 September 2026, reporting is not required. However, if the manufacturer knew of a vulnerability before that date but only becomes aware of its active exploitation after 11 September 2026, reporting is required.
  • Where an actively exploited vulnerability originates in a third-party component, reporting is required only if the vulnerability is exploitable in (and has been exploited in) the manufacturer’s own product. If unexploitable in the manufacturer’s product, reporting is voluntary, but the manufacturer must still address the vulnerability and report it upstream per Article 13.
  • Manufacturers must inform impacted users and, where appropriate, all users. If they fail to do so in a timely manner, the relevant CSIRT may provide such information directly to users.

Reporting Deadlines


Manufacturers must report actively exploited vulnerabilities and severe incidents according to the following timelines:

Actively Exploited Vulnerabilities Reporting (Article 14.2) Severe Incidents Reporting (Article 14.4)
Early warning: within 24 hours of becoming aware of the actively exploited vulnerability. Early warning: within 24 hours of becoming aware of the incident, including whether it is suspected of being caused by unlawful or malicious acts.
Vulnerability notification: within 72 hours of becoming aware of the actively exploited vulnerability, including general information about the product, nature of the exploit and vulnerability, corrective or mitigating measures taken or available to users and any sensitivity concerns. Incident notification: within 72 hours of becoming aware of the incident, including general information about the product, nature of the incident, initial assessment, corrective or mitigating measures taken or available to users and any sensitivity concerns.
Final report: within 14 days after a corrective or mitigating measure is available, including: (i) description of the vulnerability (severity and impact); (ii) information on any malicious actor exploiting the vulnerability (as available); and (iii) details of security updates or corrective measures. Final report: within one month after the incident notification, including: (i) detailed description of the incident (severity and impact); (ii) likely threat type or root cause; and (iii) applied and ongoing mitigation measures.

The CSIRT coordinator may also request an intermediate report with status updates on vulnerabilities or incidents.

What Triggers Reporting?


An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited a flaw in the manufacturer’s product (including weaknesses in identification and authentication functions). Vulnerabilities discovered without malicious intent (e.g., through security research or internal testing) do not trigger mandatory reporting, though manufacturers may choose to report them voluntarily.

A severe incident is a cybersecurity incident affecting the manufacturer’s development, production or maintenance processes in a way that could result in increased cybersecurity risk for users. For example, where an attacker introduces malicious code into the manufacturer’s security update release channel.

“Becoming Aware”: When Does the Clock Start?


Similar to the GDPR reporting obligations for data breaches, the CRA reporting obligation is triggered when the manufacturer “becomes aware” of an actively exploited vulnerability or severe incident. According to official guidance, a manufacturer is regarded as having become aware when, after initial assessment, it has a reasonable degree of certainty that a vulnerability in its product is being actively exploited or a severe incident has compromised the product’s security. The emphasis is on prompt initial assessment followed by remedial action and notification through the SRP.

Article 13: Upstream Reporting to Component Maintainers (applicable from 11 December 2027)


Separately, under Article 13, manufacturers must report vulnerabilities discovered in integrated third-party components to the component maintainer. This “upstream reporting” obligation operates separately from Article 14 ENISA/CSIRT reporting. Key points:

  • Where the component maintainer has established security policies or coordinated vulnerability disclosure processes, manufacturers should report in accordance with them and particularly where premature disclosure could increase cybersecurity risks.
  • No upstream reporting is required where the component maintainer is already aware of the vulnerability.
  • No upstream reporting is required where the component no longer has a maintainer, or where the manufacturer no longer relies on the original maintainer for new versions or security fixes.

Enforcement and Penalties


Member states must designate market surveillance authorities with broad enforcement powers, including conducting inspections, requiring technical documentation, ordering corrective actions, and withdrawing or recalling noncompliant products. The CRA establishes a three-tiered administrative fines regime (Article 64):

  • Up to 15 million or 2.5% of worldwide annual turnover: Noncompliance with essential cybersecurity requirements and core manufacturer obligations (Articles 13, 14 — applicable to noncompliance with the CRA’s reporting obligations)
  • Up to 10 million or 2% of worldwide annual turnover: Noncompliance with other CRA obligations, including importer/distributor duties and CE marking
  • Up to 5 million or 1% of worldwide annual turnover: Supplying incorrect, incomplete or misleading information to authorities

Practical Steps: Preparing for Compliance With the Reporting Obligations


  • Determine the relevant CSIRT coordinator. Notifications must be submitted to the Member State CSIRT coordinator where the manufacturer has its “main establishment”, i.e., the Member State where decisions related to product cybersecurity are predominantly taken. If not determinable, use the Member State with the highest number of employees. Where no EU main establishment exists, submit notifications based on other factors such as the location of the authorised representative, importer, distributor or largest user base.
  • Establish internal incident detection and escalation processes. Ensure your organisation can identify actively exploited vulnerabilities and severe incidents promptly with clear escalation procedures to meet the required notification deadlines.
  • Prepare notification templates. Draft standard templates for early warning notifications, follow-up reports and final reports to enable rapid response within the 24-hour/72-hour/14-day/one-month deadlines.
  • Coordinate with other reporting regimes. Align CRA reporting processes with GDPR and NIS2 obligations to avoid inconsistent regulatory notifications for a single incident. Do not assume a notification under the CRA is sufficient to satisfy any separate reporting obligations under other regimes.
  • Inventory legacy products. Since reporting obligations apply to products already on the market, manufacturers should inventory their existing product portfolio and maintain visibility over vulnerabilities affecting those products.
  • Register on the ENISA Single Reporting Platform. The ENISA has published user registration guidance for “Assigned Representatives” (primary and secondary contacts). Complete registration before any incident occurs (i.e., the 24-hour clock does not pause for onboarding). The platform also accepts voluntary reports under Article 15, covering vulnerabilities, cyber threats, incidents and near misses.

Conclusion


The CRA represents a significant shift in the EU’s approach to product cybersecurity, moving from voluntary best practices to mandatory requirements backed by substantial penalties. The September 2026 reporting deadline is a critical milestone affecting all in-scope products currently on the EU market. Part II of this series will address the remaining substantive CRA obligations, including essential cybersecurity requirements, vulnerability handling, technical documentation and conformity assessment, which apply from 11 December 2027.

For further guidance on CRA compliance or assistance for the September 2026 reporting obligations, please contact your usual Kirkland & Ellis contact.


1. Article 3(13) CRA defines “manufacturer” as a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge (emphasis added).

2. Article 3(16) CRA defines “importer” as a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union (emphasis added).

3. Article 3(17) CRA defines “distributor” as a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the market (emphasis added).

This publication is distributed with the understanding that the author, publisher and distributor of this publication and/or any linked publication are not rendering legal, accounting, or other professional advice or opinions on specific facts or matters and, accordingly, assume no liability whatsoever in connection with its use. Pursuant to applicable rules of professional conduct, portions of this publication may constitute Attorney Advertising.