CRA Compliance: The September 2026 Reporting Deadline Manufacturers Are Missing
CRA
Profile picture of Sarath Kumar S

Sarath Kumar S

Regulatory Compliance Analyst | EU/UK Product Compliance & Risk Mitigation Regulatory Compliance Analyst at Euverify with experience in EU and UK product safety requirements. Focused on risk assessments, technical file preparation, and regulatory mapping across diverse products. Brings a creative edge to compliance work, supported by a background in AI-driven research and analysis.

CRA Compliance: The September 2026 Reporting Deadline Manufacturers Are Missing

If you sell anything with a chip, a Bluetooth connection, or an app into the EU, you’ve probably heard that the Cyber Resilience Act (CRA) becomtrue. It’s also not the deadline you need to worry about first.

The one that matters right now is 11 September 2026. From that date, manufacturers of es fully enforceable in December 2027. That’s “products with digital elements” have to report actively exploited vulnerabilities and severe security incidents to EU authorities, on timelines measured in hours, not weeks.

Miss it, and you’re not late for a paperwork exercise. You’re non-compliant with binding EU law, on products you may have already shipped.

What Is the Cyber Resilience Act (CRA)? 

Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. It’s the EU’s first horizontal cybersecurity law for products, meaning it applies across almost every category of connected product rather than sitting inside a single sector’s rules. It covers the full lifecycle of a product, from design through to the point it’s taken off the market.

The regulation phases in over three years:

  • 10 December 2024: entered into force
  • 11 September 2026: vulnerability and incident reporting obligations begin
  • 11 December 2027: full application, including conformity assessment and CE marking for all in-scope products

Most coverage of the CRA focuses on the 2027 date because that’s when the full compliance regime lands. But the reporting obligation arrives over a year earlier, and it’s the one with the least room for error, because the clock starts the moment you become aware of a problem, not when you’ve had time to prepare a response.

CRA Reporting Requirements: What Changes on 11 September 2026 

CRA Reporting Requirements: What Changes on 11 September 2026

Article 14 of the CRA sets out a three-stage reporting obligation:

  1. 24 hours: an early warning to ENISA and your relevant national CSIRT (Computer Security Incident Response Team) once you become aware of an actively exploited vulnerability or a severe incident affecting product security
  2. 72 hours: a fuller notification with more detail on the vulnerability or incident, its severity, and any indicators of compromise
  3. Final report: due within 14 days of a corrective measure becoming available for an exploited vulnerability, or within 1 month for a severe incident

All three go through ENISA’s Single Reporting Platform (SRP), which is designed to notify both ENISA and your national CSIRT from a single submission. The platform is scheduled to be operational by 11 September 2026, with a testing period beforehand.

You report once. But you need to know within hours that there’s something to report, which is the part most businesses aren’t set up for yet.

Who Needs to Comply? CRA Scope and Product Categories 

“Products with digital elements” is a deliberately wide category. It covers hardware and software, and any remote data processing solutions tied to them, including firmware or software sold separately from the physical product. In practice, this includes:

  • IoT devices and smart home products
  • Wearables
  • Routers and networking equipment
  • Connected toys
  • Standalone software and firmware
  • Connected industrial equipment

Medical devices, motor vehicles, aviation and marine equipment, and products built exclusively for national security, military, or intelligence purposes sit outside the CRA, because they’re already governed by their own regimes.

Within the products that are in scope, the CRA sorts them into risk tiers, which matters because it determines how much scrutiny your product needs once full conformity requirements land in 2027:

The higher the risk tier, the less room there is to self-certify, and the more lead time you’ll need before 2027. But the September 2026 reporting obligation applies regardless of tier, so a “default” category product doesn’t buy you any extra breathing room on this specific deadline.

CategoryExamplesAssessment route
DefaultMost everyday connected productsSelf-assessment if harmonised standards are applied
Important, Class IPassword managers, VPN products, routers, browsers, non-tamper-resistant microprocessors/microcontrollers with security functionsSelf-assessment where standards apply; otherwise third-party assessment
Important, Class IIFirewalls, intrusion detection/prevention systems, hypervisors and container runtime systems, tamper-resistant microprocessors and microcontrollersThird-party assessment required
CriticalSmart meter gateways, hardware security-box devices, smartcards/secure elementsEuropean cybersecurity certification scheme

Two CRA Compliance Gaps Manufacturers Are Missing 

This isn’t limited to new launches. The reporting obligation applies to in-scope products already placed on the EU market before the CRA’s full application date, not just anything you launch from here on. If you’ve been selling a connected product for years, it’s in scope for reporting from September, whether or not you were thinking about the CRA when you designed it.

You can’t report what you haven’t detected. The 24-hour window starts when you become aware of an actively exploited vulnerability or severe incident, not when it technically occurred. Without a vulnerability monitoring and detection process, a business can end up in breach of Article 14 not because it failed to report, but because nobody internally knew there was anything to report. That’s a process gap, not a compliance technicality, and it’s the one that needs the most lead time to close.

How the CRA Fits With RED, RoHS, GPSR and Other EU Compliance Rules 

CRA doesn’t replace your existing obligations for connected products, it adds a cybersecurity layer on top of them.

  • RED, RoHS, and WEEE still apply as they do now. CRA doesn’t remove them.
  • CE marking is still required, and CRA-covered products need to demonstrate CRA conformity as part of that marking from 2027.
  • The RED Delegated Regulation (EU) 2022/30, which already sets cybersecurity requirements for internet-connected radio equipment, will eventually be superseded by the CRA for products that fall under both.
  • GPSR now treats cybersecurity as a factor in the general product safety assessment, so the two regimes reinforce rather than duplicate each other.
  • Machinery with digital elements needs to satisfy both the Machinery Regulation and CRA cybersecurity requirements where both apply.

Beyond reporting, the CRA also requires manufacturers to build security into the design process from the outset, maintain a Software Bill of Materials (SBOM), and provide security updates for a minimum of five years, or the expected lifetime of the product if shorter. Those obligations phase in more gradually, but the underlying vulnerability handling processes need to exist before September 2026 anyway, since you can’t meet a 24-hour reporting deadline without them.

Does the UK Have a Cyber Resilience Act Equivalent? 

As of now, the UK has no direct equivalent to the CRA. The closest comparable law is the Product Security and Telecommunications Infrastructure (PSTI) Act 2022, which covers baseline IoT security requirements but doesn’t carry the same reporting obligations or risk-tiered conformity structure. If you sell connected products into both the EU and UK, that gap is worth watching. For now, it means EU and UK cybersecurity obligations for the same product can diverge, which adds another layer to manage if your compliance documentation currently treats the two markets as a single set of requirements.

CRA Compliance Checklist: How to Prepare Before September 2026 

  1. Build a product inventory. List everything you sell into the EU with digital elements, including legacy products still on the market, not just anything currently in development.
  2. Identify your national CSIRT. Know who you’re reporting to and how, before you need to, rather than working it out under a 24-hour clock.
  3. Put a detection process in place. You need a way to actually find out about vulnerabilities and incidents, not just a form ready to fill in once you do.
  4. Assign clear ownership. Someone specific needs to be responsible for spotting issues and starting the reporting clock. Ambiguity here is exactly where the 24-hour deadline gets missed.
  5. Check where cybersecurity sits in your existing compliance setup. If a Responsible Person or Authorised Representative is already managing your GPSR or electronics compliance, confirm whether CRA reporting has actually been factored in, or quietly assumed to be someone else’s responsibility.

Getting Ahead of the CRA Reporting Deadline 

The CRA’s headline deadline is December 2027, but the obligation that can catch businesses out is the one arriving over a year earlier. From 11 September 2026, if your product has digital elements and you don’t know about a vulnerability within hours of it becoming exploitable, you’re already behind. The businesses that will be fine in September are the ones treating this as an operational readiness question now, not a compliance deadline to revisit closer to the date.

If you’re not sure whether your products fall inside CRA’s scope, whether your current AR/RP setup already accounts for this, or where the gaps are in your reporting process, we can help you check before September arrives rather than after. Get in touch with Euverify to talk through what CRA readiness actually looks like for your product range.