Our Expert in Ireland
No results available
EU Cyber Resilience Act reporting obligations for manufacturers of products with digital elements begin to apply on 11 September 2026, opening a new and demanding chapter in product-security compliance across the European Union. From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents through ENISA’s single reporting platform against tight 24-hour and 72-hour deadlines. The urgency is heightened by an unusual asymmetry: while these reporting duties are among the first CRA obligations to apply, the bulk of the substantive requirements of Regulation (EU) 2024/2847 do not apply until 11 December 2027, leaving an interim window in which companies may need to report incidents before having completed their full compliance programmes.
This guide explains who must report, what triggers a notification, how the ENISA platform works, and how these duties intersect with NIS2 and GDPR, with practical, Ireland-focused steps for manufacturers, in-house counsel, CISOs and product-security teams.
Who this is for: manufacturers of products with digital elements, in-house legal teams, CISOs, product-security teams, suppliers, and Irish private-practice lawyers.
What you’ll get: a clear summary of the reporting obligations under the Cyber Resilience Act (Regulation (EU) 2024/2847), step-by-step timelines (the 24- and 72-hour clocks), how to use ENISA’s single reporting platform, the interplay with NIS2 and GDPR, enforcement risks, and practical incident-response, contractual and evidence-retention checklists.
The Cyber Resilience Act, formally Regulation (EU) 2024/2847, is the EU’s horizontal cybersecurity law for products with digital elements. It entered into force on 10 December 2024. Among its provisions, the reporting duties are among the first to apply, from 11 September 2026. For in-house counsel and security leads, understanding the eu cyber resilience act reporting obligations is becoming an operational priority rather than a distant planning exercise.
The Regulation distinguishes between two categories of reportable event:
Each category triggers a staged reporting sequence: an early warning within 24 hours, a fuller notification within 72 hours, and a final report thereafter. For actively exploited vulnerabilities, the final report is generally due no later than 14 days after a corrective or mitigating measure becomes available; for severe incidents, a final report is due within one month of the 72-hour notification. The staged approach recognises that manufacturers rarely have complete information at first detection, and prioritises speed of early notification over completeness.
The interim period between the reporting duties applying (11 September 2026) and the main body of substantive obligations applying (11 December 2027) is significant. During this window, a manufacturer may be legally obliged to report an actively exploited vulnerability even though the wider conformity, documentation and secure-by-design requirements are not yet mandatory. Counsel should treat reporting readiness as a discrete, immediate workstream.
The Regulation casts the net widely. The core obligation falls on the manufacturer, the natural or legal person who develops or manufactures products with digital elements, or has them designed, developed or manufactured, and markets them under its own name or trademark. But responsibility does not stop there.
The concept of a “product with digital elements” is broad: it captures software and hardware products, and their remote data-processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. In practice this reaches consumer IoT devices, industrial control components, operating systems, applications, network equipment and connected appliances.
Certain products regulated under sector-specific EU frameworks, for example, particular medical devices, in-vitro diagnostic devices, aviation products or motor vehicles, are excluded or subject to specialised regimes to avoid double regulation. Manufacturers with product lines that straddle these boundaries should map each product against both the CRA and any sector-specific regime, because an IoT device may sit clearly within the CRA while a connected medical device may be governed principally by medical-device law. Legacy products that remain supported and placed on the market also warrant careful analysis.
Getting scope right is the foundation of any credible approach to the eu cyber resilience act reporting obligations, because the reporting duty presupposes that you have correctly identified yourself as an in-scope economic operator.
Two thresholds drive the reporting duty, and both require judgement.
Actively exploited vulnerabilities. A vulnerability moves from theoretical to reportable when there is evidence that a malicious actor is exploiting it. Practical indicators include observed exploitation in telemetry, exploit code circulating in the wild against your product, threat-intelligence reports naming your product, or customer reports of compromise traceable to a specific flaw. The trigger is the exploitation, not merely the existence of the vulnerability.
Severe security incidents. Severity is assessed by impact. Signals include a significant loss of availability of the product or its functions, unauthorised access to or exfiltration of data, loss of integrity of processed data, or a compromise affecting a large number of users or safety-critical functions. An incident affecting the security of the product that could enable an actor to compromise data confidentiality, integrity or availability should be treated as potentially reportable.
At the moment of first discovery, the priority is to capture a minimum evidentiary record so that later reports are accurate and defensible. Record, as a minimum:
This local record is not the report itself, but it is what turns a chaotic first hour into a structured submission and underpins compliance with the eu cyber resilience act reporting obligations under time pressure.
The Regulation designates a single reporting platform, established and maintained by ENISA, as the mechanism through which manufacturers submit their notifications. The platform is intended to be operational to coincide with the start of the reporting obligations from 11 September 2026. Manufacturers should treat this platform as the authoritative destination for CRA notifications and should not rely on ad hoc emails or informal contacts as a substitute for a proper submission.
Practically, preparing to use the platform means resolving several operational questions in advance rather than at the point of crisis:
Reports submitted through the platform are not public disclosures in the manner of a press release. The platform is designed to route information to the relevant authorities, including the relevant national CSIRT designated as coordinator and, where appropriate, market surveillance authorities, so that they can coordinate response and, where necessary, protect users. Manufacturers understandably worry about being named or about premature disclosure of an unpatched flaw. The framework recognises the risk that early disclosure can increase harm, and information handling is calibrated accordingly; in defined circumstances a manufacturer may raise justified grounds relating to imminent risk or ongoing investigations.
Nonetheless, counsel should assume that submitted material may be shared with authorities across Member States and should draft reports precisely, factually and without speculation.
To operationalise the platform, prepare internal templates for each report type, agree sign-off responsibilities (who approves a submission and how quickly), and maintain a current list of named platform contacts. These small pieces of preparation are what allow a manufacturer to meet the eu cyber resilience act reporting obligations calmly rather than reactively.
The reporting clocks start when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident. “Awareness” is a practical threshold: it is reached when the manufacturer has a reasonable basis to believe that a reportable event has occurred, not the moment a full forensic picture is complete. Because awareness can begin with a single credible alert, escalation processes must be fast enough that the responsible team learns of a potential event within the first hours, not days.
A simple decision-tree helps teams act quickly: Is there credible evidence of active exploitation or a severe impact on the product’s security or the data it handles? If yes, the 24-hour clock has started, issue the early warning even if detail is thin, then schedule the 72-hour follow-up immediately. Sample early-warning wording can be as short as: “[Manufacturer] is notifying an actively exploited vulnerability in [product/version]. Exploitation observed at [time]. Impact assessment and mitigations are in progress; a fuller notification will follow within 72 hours.” Treating the timelines as fixed operational milestones is the single most important discipline in complying with the eu cyber resilience act reporting obligations.
A single event can trigger several parallel legal duties. The same ransomware intrusion might be an actively exploited vulnerability under the CRA, a significant incident under Directive (EU) 2022/2555 (NIS2) if the entity is an essential or important entity, and a personal data breach under Regulation (EU) 2016/679 (GDPR) if personal data is affected.
These regimes are not identical. They have different triggers, different notification recipients and different, though sometimes overlapping, timelines. GDPR requires notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours. NIS2 imposes its own early-warning and reporting cadence on in-scope entities, including a 24-hour early warning and a 72-hour notification. The CRA adds the manufacturer-focused 24/72-hour sequence through the single reporting platform.
The practical answer is coordination rather than duplication of effort. We recommend:
For Irish organisations, this means engaging with domestic authorities alongside the platform. Personal data breaches are notified to the Data Protection Commission, which publishes practical guidance and contact points. Significant cyber incidents affecting Irish entities are coordinated with the National Cyber Security Centre. Ireland’s transposition of NIS2 is being given effect through national legislation; organisations should check the current status of the relevant Irish measures. Building both into your escalation matrix ensures the eu cyber resilience act reporting obligations are handled in step with, not in isolation from, national duties.
| Law | Triggering event | Who must notify | Timeline | Channel | Penalty focus |
|---|---|---|---|---|---|
| Cyber Resilience Act, Regulation (EU) 2024/2847 | Actively exploited vulnerability or severe security incident affecting a product with digital elements | Manufacturer (with importer/authorised representative duties) | 24-hour early warning; 72-hour notification; final report (generally 14 days after a fix is available / 1 month) | ENISA single reporting platform (routing to national CSIRTs) | Administrative fines and market surveillance measures |
| NIS2, Directive (EU) 2022/2555 | Significant incident affecting service provision | Essential and important entities | 24-hour early warning, 72-hour incident notification and final report on a staged cadence | National CSIRT / competent authority | Administrative fines and supervisory measures |
| GDPR, Regulation (EU) 2016/679 | Personal data breach | Data controllers (and processors, to controllers) | Without undue delay, and where feasible within 72 hours | National supervisory authority (in Ireland, the Data Protection Commission) | Administrative fines up to the higher GDPR tier |
Non-compliance carries real consequences. The Regulation provides for administrative fines and for the enforcement powers of national market surveillance authorities, which can require corrective action, restrict or prohibit the making available of a product, or order a withdrawal or recall. The CRA sets tiered maximum administrative fines, with the highest tier applying to breaches of core essential requirements and obligations, lower ceilings for other obligations, and a further tier for the supply of incorrect, incomplete or misleading information to authorities. The precise ceilings are set out in the Regulation and are expressed as fixed maxima and as percentages of worldwide annual turnover, whichever is higher; counsel should consult the current text for the applicable figures.
The Regulation also builds in proportionality. When authorities decide on the amount of a fine, they take into account factors such as the nature, gravity and duration of the infringement, whether the operator cooperated, and whether the breach was self-reported. In practice, prompt and candid engagement, including timely use of the reporting platform, is likely to be treated as a mitigating factor, while concealment or delay is likely to aggravate.
Micro and small enterprises benefit from specific tailoring within the framework, and the Regulation directs that the situation of such enterprises be considered in enforcement so that penalties are proportionate. This does not exempt small manufacturers from the reporting duty; the obligation to report an actively exploited vulnerability or severe incident applies regardless of company size. These considerations shape how obligations are administered and how enforcement discretion is exercised, not whether the eu cyber resilience act reporting obligations apply at all.
The best way to meet tight deadlines is to rehearse them. A CRA-aware incident-response playbook maps each phase of your response to a specific reporting milestone.
Assign clear roles before an incident: an incident commander who owns the timeline and the submissions; legal counsel to assess the parallel CRA, NIS2 and GDPR triggers and manage privilege; and a security lead to drive technical investigation and remediation. Keep two short templates ready, one for the 24-hour early warning and one for the 72-hour notification, so drafting under pressure becomes a matter of populating fields rather than composing from scratch.
24-hour quick checklist:
Throughout, preserve evidence rigorously. Capture and hold logs, indicators of compromise, forensic images and communications, and maintain a clear chain of custody so that later reports, and any subsequent regulatory scrutiny, rest on defensible records. Sound evidence handling is inseparable from meeting the eu cyber resilience act reporting obligations credibly.
Modern products are assemblies of third-party components, so a manufacturer’s ability to report on time depends on suppliers reporting to it on time. In-house counsel should update supply and development contracts to flow down the practical substance of the CRA regime. Key clauses to include:
Top 5 contract clauses to flow down: supplier reporting deadlines; cooperation and information-sharing; evidence preservation and chain of custody; remediation and patch commitments; indemnities for reporting or remediation failures.
Because the CRA’s final-report windows extend beyond the initial notifications, and because enforcement authorities may later examine an incident, manufacturers should adopt disciplined retention practices. Preserve, for a defined and documented period aligned to the reporting cycle and any limitation considerations, the material that substantiates each report: system and application logs, indicators of compromise, forensic images, timelines, internal decision records and copies of the submissions themselves.
Good documentation practice includes recording the moment of awareness (which anchors the clocks), the reasoning behind threshold decisions, and the sequence of mitigations. Where forensic imaging is undertaken, follow a documented chain-of-custody procedure. Handle legally privileged material with care, keeping legal analysis separate from factual incident records so that the factual record can be shared with authorities without waiving privilege over legal advice. For manufacturers operating across borders, consider how evidence held in different jurisdictions, and any export-control sensitivities in the data, affect what can be shared and when.
The eu cyber resilience act reporting obligations are coming into force from 11 September 2026, and readiness cannot wait for the 2027 substantive deadline. Irish manufacturers and counsel should take four immediate actions: confirm how to access and register for the ENISA single reporting platform and name responsible contacts; update the incident-response playbook to embed the 24-hour and 72-hour clocks; audit supplier contracts to flow down reporting and evidence-preservation duties; and build a product inventory that identifies which items fall within scope. Coordinating these steps with existing NIS2 and GDPR processes, and with the Data Protection Commission and National Cyber Security Centre in Ireland, will turn a demanding regime into a manageable, well-rehearsed routine.
This article is provided for information only and is not legal advice; complex or cross-border incidents warrant tailored guidance.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Dean Cunningham at Cunningham Solicitors, a member of the Global Law Experts network.
posted 3 minutes ago
posted 24 minutes ago
posted 44 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message