ARTICLE
15 September 2026

Cyber Resilience Act: New Vulnerability Reporting Requirements Now In Force

BJ
Browne Jacobson

Contributor

Social and environmental impact are at the top of the business agenda. At Browne Jacobson, we’ve always worked across business and society, and this expertise sets us apart. Here, we champion fairness, make the complex simple and forge connections between clients to find creative solutions. This is how we improve outcomes for every person, community and business we serve.

Law needs all voices to reflect the society it serves. We’re working towards social mobility, diversity and inclusion in our firm and our profession. And we’re focusing on well-being and individuality so that all our people can thrive.

The EU Cyber Resilience Act introduces mandatory reporting obligations for manufacturers of digital products, requiring them to notify authorities within 24 hours of discovering actively exploited vulnerabilities or severe security incidents. This regulation establishes strict timelines for early warnings, detailed vulnerability notifications, and final reports, fundamentally changing how manufacturers must respond to cybersecurity threats.
Ireland Technology
Browne Jacobson are most popular:
  • with readers working within the Insurance and Utilities industries

As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements.

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) (the 'CRA') is a piece of EU legislation establishing comprehensive cybersecurity requirements for digital products in the EU. The CRA imposes obligations on manufacturers, importers and distributors throughout the digital product lifecycle. It entered into force on 10 December 2024, with its provisions applying on a phased basis through to 11 December 2027.

Obligations from 11 September

The obligations which came into force on 11 September come from Article 14 of the CRA, which outlines the reporting obligations for manufacturers. Importantly, there is no grace period for these obligations coming into force. The obligation for in-scope digital products is to report:

  • any actively exploited vulnerability contained in its digital product that manufacturers become aware of; and 
  • any severe incident having an impact on the security of the digital product that manufacturers becomes aware of.

Importantly, even where an in-scope product’s support period has ended, the reporting obligations still apply.

What is the timeline for reporting?

Early warning notification

The initial obligation is an ‘early warning notification’, which should be made as soon as the manufacturer becomes aware that a vulnerability is being actively exploited or that a severe incident has occurred and has led to the security of its digital product being compromised. 

Article 14 outlines that an early warning notification must be made for both potential vulnerabilities and severe incidents "without undue delay and in any event within 24 hours of the manufacturer becoming aware". Guidance issued by the European Commission in July 2026 further clarifies the moment when a manufacturer is deemed to ‘become aware’. Per that guidance, when a manufacturer detects a suspicious event, it must assess the situation immediately and is then considered to have become aware when, after the initial assessment, it has reasonable degree of certainty that:

  • a vulnerability contained in its digital product is being actively exploited; or 
  • a severe incident has occurred and has led to the security of its digital product being compromised.

This guidance makes it clear that prompt action from the outset of any potential vulnerability or incident being detected is essential. 

Vulnerability notification

Then, unless the relevant information has already been provided, a ‘vulnerability notification’ must be made within a maximum of 72 hours of awareness. This notification should include measures taken to mitigate the situation and how sensitive the manufacturer considers the notified information to be. 

Final report

Again, unless the relevant information has already been provided, in the case of a vulnerability report, a final report should be made within 14 days of a mitigating measure being available. A final report on an exploited vulnerability should contain:

  • a description of the vulnerability, including its severity and impact; 
  • where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; and
  • details about the security update or other corrective measures that have been made available to remedy the vulnerability.

Similarly, in the case of a severe incident notification, a final report should be made within one month after the incident notification. A final report on a severe incident should include:

  • a detailed description of the incident, including its severity and impact; 
  • the type of threat or root cause that is likely to have triggered the incident; and
  • applied and ongoing mitigation measures.

Who must manufacturers report to?

Reports must be made to: (i) the Computer Security Incident Response Team (CSIRT) in the member state in which the manufacturer has its main establishment and (ii) ENISA. In Ireland, the CSIRT body is operated by the National Cyber Security Centre

Manufacturers must report to impacted users, and where appropriate, all users. However, in line with the CRA’s risk-based approach, the obligation to inform users is to be applied in a risk-based and proportionate manner. Specifically, the need to provide information does not mean that such information must be made public or disclosed indiscriminately. This is particularly important to consider for manufacturers notifying in relation products with digital elements used in sensitive or essential environments, where broader disclosure of technical details could itself increase cybersecurity risks. 

Key takeaways for manufacturers 

These reporting obligations represent the first real enforcement test of the CRA for many organisations. Given the overlap with reporting requirements under various EU digital regulation instruments, manufacturers should ensure that robust monitoring and incident response processes are in place. Prompt and effective engagement with regulators will now be critical alongside addressing the underlying vulnerability or incident itself.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More