[codicts-css-switcher id=”346″]

Global Law Experts Logo
eu cyber resilience acts 24hour reporting

Our Expert in Spain

The EU Cyber Resilience Act 24‑hour Reporting Duty: Practical Steps for Manufacturers Before 11 Sept 2026

By Global Law Experts
– posted 1 hour ago

EU cyber resilience acts 24hour reporting obligations become a live enforcement reality on 11 September 2026, the first mandatory application date for the reporting duties set out in Article 14 of Regulation (EU) 2024/2847. From that date, any manufacturer that places a product with digital elements on the EU market must be ready to notify an actively exploited vulnerability or a severe incident within twenty‑four hours of becoming aware of it. For manufacturers, importers and distributors serving the Spanish and wider European markets, this is not a distant policy debate but a concrete operational and contractual challenge that must be solved before the deadline.

This guide sets out what the duty requires, how it interacts with NIS2, DORA and the GDPR, where notifications go in Spain, and the practical steps to take now.

Executive summary, what every manufacturer must know before 11 Sept 2026

The EU cyber resilience acts 24hour reporting regime imposes short, cascading deadlines that leave little room for improvisation. The essentials are:

  • Who is affected. Manufacturers of products with digital elements, including non‑EU manufacturers placing products on the EU market, plus authorised representatives, importers and distributors with related duties.
  • The 24‑hour duty. An early‑warning notification of an actively exploited vulnerability or a severe incident having an impact on the security of the product must be submitted without undue delay and in any event within 24 hours of the manufacturer becoming aware of it.
  • Reporting destinations. Notifications flow through a single reporting platform to the relevant national CSIRT designated as coordinator and to ENISA, under Article 14 of Regulation (EU) 2024/2847.
  • Staged reporting. The 24‑hour early warning is followed by a fuller notification, and subsequently a final report, a phased sequence that requires evidence to be preserved and updated as the picture clarifies.
  • Penalties and immediate action. Non‑compliance with the reporting obligations can attract administrative fines up to the maximum levels set by the Regulation (see below). Manufacturers should update incident response plans, test the 24‑hour flow, and revise supplier contracts now.

Overview of Article 14 (Regulation (EU) 2024/2847), the 24‑hour rule and phased reports

Article 14 of the Cyber Resilience Act is the operative provision behind the EU cyber resilience acts 24hour reporting duty. It requires a manufacturer to notify any actively exploited vulnerability contained in the product with digital elements, as well as any severe incident having an impact on the security of that product. The obligation is triggered when the manufacturer becomes aware of the event, a knowledge‑based standard rather than a confirmed‑breach standard, which means the clock can start running before all facts are established.

The reporting sequence is phased. An early warning notification is due within 24 hours of awareness. A more complete notification follows, generally within 72 hours of awareness, providing general information about the nature of the exploitation or incident, an initial assessment, and any corrective or mitigating measures taken or advised. A final report is then required: for an actively exploited vulnerability, a report is due once a corrective or mitigating measure is available; for a severe incident, a final report follows within one month of the fuller notification, describing the incident, its severity and impact, and the root cause where known.

Manufacturers should treat these as cumulative obligations, not a single filing, and should confirm exact timings against the primary text.

Two features deserve emphasis. First, the becoming aware trigger obliges manufacturers to have monitoring and internal escalation good enough to detect and route events quickly, a 24‑hour deadline is only meaningful if internal awareness reaches the compliance function fast. Second, the duty exists alongside a separate obligation to inform affected users about the vulnerability or incident and, where relevant, corrective measures they can take. The consolidated legal text is published on EUR‑Lex, and manufacturers should work from the primary text rather than summaries. (Interpretive guidance; not legal advice.)

Who counts as a “manufacturer” (and related roles) under the CRA

The reach of the EU cyber resilience acts 24hour reporting duty depends on how the roles in the supply chain are defined. The Regulation allocates the primary reporting obligation to the manufacturer, but importers, distributors and authorised representatives all carry related responsibilities.

Manufacturer established in the EU versus outside the EU

A manufacturer is the entity that develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark. Crucially, the obligations apply on the basis of placing the product on the EU market, not on where the manufacturer is established. A manufacturer based outside the EU whose products are sold into Spain or elsewhere in the Union is caught by the same reporting duties as an EU‑established manufacturer. Non‑EU manufacturers should expect to designate an EU point of contact and ensure that the reporting workflow functions across time zones.

Authorised representatives, importers and distributors

Where a manufacturer is outside the EU, an authorised representative may carry out defined tasks on its behalf. Importers must ensure that the products they place on the market comply with the Regulation and must not place non‑compliant products on the market; distributors must act with due care in relation to the requirements. In practice, importers and distributors need contractual assurance that manufacturers will meet the 24‑hour timeline, because a failure upstream can expose downstream operators to compliance and reputational risk.

Example scenarios

  • OEM selling under its own brand. The OEM is the manufacturer and holds the primary reporting duty, including for embedded third‑party components.
  • White‑label products. The entity marketing the product under its own trademark is generally treated as the manufacturer and inherits the reporting obligations, even where the underlying build is outsourced.
  • Firmware and component suppliers. A supplier of a vulnerable component should notify the integrator or maintainer; the manufacturer of the finished product remains responsible for the overall product notification. Clear contractual flow‑downs are essential to avoid gaps. (Interpretive guidance; not legal advice.)

What “actively exploited” and “severe incident” mean in practice

Two definitional thresholds control when the EU cyber resilience acts 24hour reporting duty is engaged: whether a vulnerability is actively exploited, and whether an event is a severe incident. Both require practical judgement, and both should be interpreted with a bias toward timely notification where the evidence is credible.

Indicators of an actively exploited vulnerability

A vulnerability is treated as actively exploited where there is reliable evidence that a malicious actor has performed an act with the potential to compromise a system, exploiting the vulnerability in question. Practical indicators include:

  • Indicators of compromise (IOCs) linked to a known weakness in the product.
  • Functional exploit code observed in the wild, or evidence of successful exploitation against deployed instances.
  • Credible threat intelligence, including coordinated reports from customers, researchers or CSIRTs, indicating exploitation is occurring.

Indicators of a severe incident

A severe incident having an impact on the security of the product is one that negatively affects, or is capable of negatively affecting, the ability of the product to protect the availability, authenticity, integrity or confidentiality of data or functions. Practical markers include material loss of availability, unauthorised access to sensitive data, integrity compromise of critical functions, or demonstrable user harm arising from the product’s security failure.

The evidence threshold

The standard is one of reasonable belief on credible evidence, not absolute proof. Because the trigger is becoming aware, manufacturers should not wait for a fully completed forensic investigation before notifying, the 24‑hour early warning is precisely designed to accommodate incomplete information. Equally, the regime is not intended to generate noise from speculative or unverified reports. The right posture is a documented, defensible assessment process that errs toward notification when in genuine doubt. (Interpretive guidance; not legal advice.)

Where and how to notify within 24 hours, ENISA, national CSIRT and affected users

Getting the EU cyber resilience acts 24hour reporting mechanics right means knowing exactly where a notification must go and having the channel tested in advance. Under Article 14, notifications are made through a single reporting platform, reaching the relevant national CSIRT acting as coordinator and ENISA.

ENISA notification channel

ENISA plays a central role in the CRA reporting architecture and publishes guidance on the notification process and technical expectations. Manufacturers should consult ENISA’s Cyber Resilience Act resources to confirm the current notification route and the information ENISA expects at each stage, and to align internal templates with those expectations before the deadline.

Spain national CSIRT contacts and practical flow

For manufacturers with a Spanish nexus, the national CSIRT ecosystem is the operational touchpoint. The Spanish National Cybersecurity Institute (INCIBE), through INCIBE‑CERT, provides incident reporting guidance and contact points, and the Centro Criptológico Nacional (CCN‑CERT) has operational responsibilities relevant to the public sector and certain critical entities. Manufacturers should identify in advance which contact point applies to their profile, verify reporting portals and secure channels, and record the escalation matrix so that a duty officer can act within the 24‑hour window at any hour. The precise designation of coordinating CSIRTs for CRA purposes should be confirmed against national implementing guidance as it is published.

Template checklist for the 24‑hour notification

The minimum fields a 24‑hour early warning should be ready to capture are:

  • Identity and contact details of the manufacturer (and EU point of contact).
  • Product name, version and affected configurations.
  • Whether the event is an actively exploited vulnerability or a severe incident, and when awareness arose.
  • Initial assessment of impact and affected user populations.
  • Immediate mitigation or corrective measures taken or advised.
  • A named incident contact for follow‑up.

What information belongs in the early‑warning, fuller and final reports

The phased structure of the EU cyber resilience acts 24hour reporting duty means the content of each stage differs. Building three tiers of template now avoids scrambling later.

Minimum viable 24‑hour early warning

The early warning is deliberately lightweight: who, what, when, initial impact, mitigation status and a contact. Its purpose is speed, not completeness. Manufacturers should resist the temptation to delay it while chasing detail.

The fuller notification

The subsequent notification should provide general information on the nature of the exploitation or incident, an updated severity and impact assessment, and details of any corrective or mitigating measures made available. This is where forensic findings begin to firm up and where the affected‑user communication plan should already be in motion.

Final report content, timelines and sensitive information

The final report describes the incident or vulnerability, its severity and impact, and, where available, the root cause and the corrective measures applied. For a severe incident, the final report is due within one month of the fuller notification; for an actively exploited vulnerability, the final report follows once a corrective or mitigating measure is available. Sensitive information, such as un‑patched exploit detail, must be handled with care, and manufacturers may need to coordinate embargoes with CSIRTs to protect users during coordinated vulnerability disclosure.

EU cyber resilience acts 24hour reporting versus NIS2, DORA and GDPR, reconciling triggers and timelines

A single security event can trigger obligations under several regimes at once. Reconciling the EU cyber resilience acts 24hour reporting duty with NIS2, DORA and the GDPR is one of the hardest practical tasks, because each regime has a distinct trigger, recipient and deadline.

At-a-glance: CRA 24‑hour vs NIS2 / DORA / GDPR reporting

Regulation Trigger for reporting Reporting recipient Reporting deadline Key difference
Cyber Resilience Act (Article 14, Regulation (EU) 2024/2847) Awareness of an actively exploited vulnerability or a severe incident affecting product security National CSIRT (coordinator) and ENISA via single reporting platform Early warning within 24 hours, then fuller notification and final report Product‑centric; covers vulnerabilities as well as incidents
NIS2 Directive (Directive (EU) 2022/2555) Awareness of a significant incident affecting an essential or important entity National CSIRT or competent authority Early warning within 24 hours, incident notification within 72 hours, final report within one month Entity‑centric; applies to in‑scope sectors and services
DORA (Regulation (EU) 2022/2554) Major ICT‑related incident affecting a financial entity Relevant financial competent authority Staged reporting of initial, intermediate and final reports Sector‑specific to financial entities and their ICT providers
GDPR (Regulation (EU) 2016/679) Personal data breach likely to result in a risk to individuals Supervisory authority (and affected individuals where high risk) Notification to the authority within 72 hours of awareness Personal‑data‑centric; focused on rights of data subjects

Practical sequencing

The overlaps mean manufacturers should maintain a single incident intake that fans out to the correct regimes. Where an event is an actively exploited vulnerability in a product, the CRA early warning within 24 hours is likely to be the first filing. If the same event compromises personal data with risk to individuals, a GDPR notification to the supervisory authority within 72 hours will run in parallel. If the manufacturer is also an in‑scope NIS2 entity or a financial entity under DORA, those obligations sequence alongside. The practical rule is to map each regime to a named owner and to draft a coordinated reporting plan so that no deadline is missed and no filing contradicts another.

(Interpretive guidance; not legal advice.

Contractual consequences and supply‑chain allocation (practical clauses)

Because the EU cyber resilience acts 24hour reporting duty depends on prompt awareness, contracts with component suppliers and integrators are now a compliance instrument, not a formality. The clauses below are illustrative drafting starting points, not legal advice, and should be tailored to each relationship.

Notification flow‑downs and timeframes

Suppliers of components with digital elements should be obliged to notify the manufacturer of any vulnerability or incident affecting the supplied component within a short, contractually fixed window, materially shorter than 24 hours, so the manufacturer retains time to assess and file its own early warning. The clause should specify the channel, minimum content and a named 24/7 contact.

Component warranties and supplier obligations

Contracts should include warranties that components are free from known vulnerabilities at delivery, commitments to provide security updates for a defined support period, and obligations to cooperate in root‑cause analysis and coordinated disclosure. Where a supplier maintains open‑source or third‑party dependencies, the obligation to monitor and report should extend to those dependencies.

Cost allocation and coordinated disclosure

Allocate, in advance, who bears the cost of forensic investigation, patch development, user notification and remediation where a component is the root cause. A coordinated disclosure clause should require the supplier to align on timing and messaging, and to refrain from unilateral disclosure that could undermine the manufacturer’s user protection obligations.

Insurance considerations

Review cyber and product liability policies to confirm that CRA‑driven notification, remediation and potential fines exposure are addressed, and that supplier indemnities dovetail with insurance recoveries rather than leaving gaps between them.

Practical checklist, steps manufacturers, importers and distributors must take before 11 Sept 2026

The following action list translates the EU cyber resilience acts 24hour reporting duty into concrete tasks with clear ownership. Treat these as draft and illustrative, and adapt to your organisation.

  1. Update the incident response plan to embed the 24‑hour early warning, the fuller notification and the final report as distinct, owned steps.
  2. Test the 24‑hour notification flow end‑to‑end, including out‑of‑hours escalation to a duty officer who can file.
  3. Map the supply chain and identify every component with digital elements and its maintainer.
  4. Update supplier contracts with notification flow‑downs, warranties, cost allocation and coordinated disclosure clauses.
  5. Designate an EU point of contact and, for non‑EU manufacturers, confirm authorised representative arrangements.
  6. Establish importer and distributor processes so downstream operators know how and when they will be informed.
  7. Run tabletop exercises simulating an actively exploited vulnerability and a severe incident, verifying that CRA, GDPR and any NIS2/DORA obligations are triggered correctly.
  8. Improve logging and telemetry so that awareness of exploitation reaches the compliance function quickly.
  9. Prepare user notification templates for affected‑user communications and corrective‑measure guidance.
  10. Verify national CSIRT contacts, including INCIBE‑CERT and CCN‑CERT for Spain, and confirm ENISA reporting routes.

Quick litigation and enforcement risks, penalties, cross‑border enforcement and evidence preservation

Failure to meet the EU cyber resilience acts 24hour reporting duty can carry material consequences. Under the Cyber Resilience Act, infringements of the reporting obligations are subject to administrative fines, with maximum amounts set out in the Regulation according to the category of obligation breached; the highest tiers can reach the greater of a fixed euro cap or a percentage of worldwide annual turnover. Manufacturers should confirm the applicable fine tier for the reporting obligations against the current text of the Regulation and any Spanish implementing measures, rather than assuming a single figure. Enforcement is cross‑border by design, so a non‑EU manufacturer cannot assume distance provides shelter.

Manufacturers should preserve forensic evidence from the moment awareness arises, maintain clear internal reporting lines, and consider legal privilege carefully when instructing investigations, so that the factual record supports both compliance and any subsequent defence. Documented, contemporaneous decision‑making around the notification assessment is among the most valuable protections against enforcement risk. (Interpretive guidance; not legal advice.

Conclusion and next steps

The EU cyber resilience acts 24hour reporting duty is a demanding, fast‑moving obligation that will test the incident readiness of every manufacturer, importer and distributor selling products with digital elements into the EU. With 11 September 2026 fixed as the first mandatory application date for the Article 14 reporting duties, the window to update incident response plans, rework supplier contracts, verify national CSIRT and ENISA channels, and rehearse the 24‑hour flow is closing. Organisations that treat the EU cyber resilience acts 24hour reporting requirements as a cross‑functional programme, legal, security, procurement and communications working from a single coordinated plan, will be far better placed than those that leave it to the incident itself.

For jurisdiction‑specific advice on Spanish reporting channels, contract drafting and cross‑regulatory sequencing, seek qualified counsel before the deadline.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex
  2. ENISA, Cyber Resilience Act resources
  3. European Commission, Cyber Resilience Act
  4. Directive (EU) 2022/2555 (NIS2 Directive), EUR-Lex
  5. Regulation (EU) 2016/679 (GDPR), EUR-Lex
  6. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  7. Spanish National Cybersecurity Institute (INCIBE)
  8. CCN‑CERT (Centro Criptológico Nacional)
  9. European Data Protection Board (EDPB)

FAQs

What exactly must be reported within 24 hours under the Cyber Resilience Act?
Under Article 14 of Regulation (EU) 2024/2847, a manufacturer must submit an early warning notification of an actively exploited vulnerability in the product, or a severe incident affecting the product’s security, within 24 hours of becoming aware of it. The early warning is a short notification identifying the manufacturer, the product, the nature and timing of the event, the initial impact and any mitigation, followed by a fuller notification and a final report.
The manufacturer is the entity that develops or has a product with digital elements manufactured and markets it under its own name or trademark, including non‑EU manufacturers placing products on the EU market. White‑label sellers marketing under their own brand are generally treated as manufacturers, while importers, distributors and authorised representatives carry related duties.
They are separate but can be triggered by the same event. The CRA requires an early warning within 24 hours to the national CSIRT and ENISA for product vulnerabilities and severe incidents, while the GDPR requires notification of a personal data breach to the supervisory authority within 72 hours where there is risk to individuals. A single event may require both; maintain one intake process that routes to each regime with distinct owners and deadlines.
Ask for contractual notification flow‑downs with windows shorter than 24 hours, warranties that components are free from known vulnerabilities, committed security‑update support periods, cost‑allocation for forensics and remediation, coordinated disclosure cooperation, and a named 24/7 incident contact.
Infringement of the CRA reporting obligations is subject to administrative fines, with maximum amounts fixed by the Regulation according to the obligation breached and expressed as the greater of a euro cap or a percentage of worldwide annual turnover. Confirm the applicable tier against the current text, as well as reputational and downstream contractual exposure.
No. The 24‑hour early warning to the national CSIRT and ENISA remains mandatory. Sensitivities around coordinated vulnerability disclosure are managed through the handling of sensitive information and, where appropriate, embargoes agreed with CSIRTs to protect users, not by withholding the required notification.
Yes. Where a product incorporates a vulnerable third‑party component, the manufacturer of the finished product remains responsible for the product‑level notification, and should notify the component maintainer. Contractual flow‑downs should ensure the manufacturer learns of component vulnerabilities in time to meet its own 24‑hour deadline.
By Global Law Experts

posted 4 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The EU Cyber Resilience Act 24‑hour Reporting Duty: Practical Steps for Manufacturers Before 11 Sept 2026

Send welcome message

Custom Message