EU cyber resilience acts 24hour reporting obligations become a live enforcement reality on 11 September 2026, the first mandatory application date for the reporting duties set out in Article 14 of Regulation (EU) 2024/2847. From that date, any manufacturer that places a product with digital elements on the EU market must be ready to notify an actively exploited vulnerability or a severe incident within twenty‑four hours of becoming aware of it. For manufacturers, importers and distributors serving the Spanish and wider European markets, this is not a distant policy debate but a concrete operational and contractual challenge that must be solved before the deadline.
This guide sets out what the duty requires, how it interacts with NIS2, DORA and the GDPR, where notifications go in Spain, and the practical steps to take now.
The EU cyber resilience acts 24hour reporting regime imposes short, cascading deadlines that leave little room for improvisation. The essentials are:
Article 14 of the Cyber Resilience Act is the operative provision behind the EU cyber resilience acts 24hour reporting duty. It requires a manufacturer to notify any actively exploited vulnerability contained in the product with digital elements, as well as any severe incident having an impact on the security of that product. The obligation is triggered when the manufacturer becomes aware of the event, a knowledge‑based standard rather than a confirmed‑breach standard, which means the clock can start running before all facts are established.
The reporting sequence is phased. An early warning notification is due within 24 hours of awareness. A more complete notification follows, generally within 72 hours of awareness, providing general information about the nature of the exploitation or incident, an initial assessment, and any corrective or mitigating measures taken or advised. A final report is then required: for an actively exploited vulnerability, a report is due once a corrective or mitigating measure is available; for a severe incident, a final report follows within one month of the fuller notification, describing the incident, its severity and impact, and the root cause where known.
Manufacturers should treat these as cumulative obligations, not a single filing, and should confirm exact timings against the primary text.
Two features deserve emphasis. First, the becoming aware trigger obliges manufacturers to have monitoring and internal escalation good enough to detect and route events quickly, a 24‑hour deadline is only meaningful if internal awareness reaches the compliance function fast. Second, the duty exists alongside a separate obligation to inform affected users about the vulnerability or incident and, where relevant, corrective measures they can take. The consolidated legal text is published on EUR‑Lex, and manufacturers should work from the primary text rather than summaries. (Interpretive guidance; not legal advice.)
The reach of the EU cyber resilience acts 24hour reporting duty depends on how the roles in the supply chain are defined. The Regulation allocates the primary reporting obligation to the manufacturer, but importers, distributors and authorised representatives all carry related responsibilities.
A manufacturer is the entity that develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark. Crucially, the obligations apply on the basis of placing the product on the EU market, not on where the manufacturer is established. A manufacturer based outside the EU whose products are sold into Spain or elsewhere in the Union is caught by the same reporting duties as an EU‑established manufacturer. Non‑EU manufacturers should expect to designate an EU point of contact and ensure that the reporting workflow functions across time zones.
Where a manufacturer is outside the EU, an authorised representative may carry out defined tasks on its behalf. Importers must ensure that the products they place on the market comply with the Regulation and must not place non‑compliant products on the market; distributors must act with due care in relation to the requirements. In practice, importers and distributors need contractual assurance that manufacturers will meet the 24‑hour timeline, because a failure upstream can expose downstream operators to compliance and reputational risk.
Two definitional thresholds control when the EU cyber resilience acts 24hour reporting duty is engaged: whether a vulnerability is actively exploited, and whether an event is a severe incident. Both require practical judgement, and both should be interpreted with a bias toward timely notification where the evidence is credible.
A vulnerability is treated as actively exploited where there is reliable evidence that a malicious actor has performed an act with the potential to compromise a system, exploiting the vulnerability in question. Practical indicators include:
A severe incident having an impact on the security of the product is one that negatively affects, or is capable of negatively affecting, the ability of the product to protect the availability, authenticity, integrity or confidentiality of data or functions. Practical markers include material loss of availability, unauthorised access to sensitive data, integrity compromise of critical functions, or demonstrable user harm arising from the product’s security failure.
The standard is one of reasonable belief on credible evidence, not absolute proof. Because the trigger is becoming aware, manufacturers should not wait for a fully completed forensic investigation before notifying, the 24‑hour early warning is precisely designed to accommodate incomplete information. Equally, the regime is not intended to generate noise from speculative or unverified reports. The right posture is a documented, defensible assessment process that errs toward notification when in genuine doubt. (Interpretive guidance; not legal advice.)
Getting the EU cyber resilience acts 24hour reporting mechanics right means knowing exactly where a notification must go and having the channel tested in advance. Under Article 14, notifications are made through a single reporting platform, reaching the relevant national CSIRT acting as coordinator and ENISA.
ENISA plays a central role in the CRA reporting architecture and publishes guidance on the notification process and technical expectations. Manufacturers should consult ENISA’s Cyber Resilience Act resources to confirm the current notification route and the information ENISA expects at each stage, and to align internal templates with those expectations before the deadline.
For manufacturers with a Spanish nexus, the national CSIRT ecosystem is the operational touchpoint. The Spanish National Cybersecurity Institute (INCIBE), through INCIBE‑CERT, provides incident reporting guidance and contact points, and the Centro Criptológico Nacional (CCN‑CERT) has operational responsibilities relevant to the public sector and certain critical entities. Manufacturers should identify in advance which contact point applies to their profile, verify reporting portals and secure channels, and record the escalation matrix so that a duty officer can act within the 24‑hour window at any hour. The precise designation of coordinating CSIRTs for CRA purposes should be confirmed against national implementing guidance as it is published.
The minimum fields a 24‑hour early warning should be ready to capture are:
The phased structure of the EU cyber resilience acts 24hour reporting duty means the content of each stage differs. Building three tiers of template now avoids scrambling later.
The early warning is deliberately lightweight: who, what, when, initial impact, mitigation status and a contact. Its purpose is speed, not completeness. Manufacturers should resist the temptation to delay it while chasing detail.
The subsequent notification should provide general information on the nature of the exploitation or incident, an updated severity and impact assessment, and details of any corrective or mitigating measures made available. This is where forensic findings begin to firm up and where the affected‑user communication plan should already be in motion.
The final report describes the incident or vulnerability, its severity and impact, and, where available, the root cause and the corrective measures applied. For a severe incident, the final report is due within one month of the fuller notification; for an actively exploited vulnerability, the final report follows once a corrective or mitigating measure is available. Sensitive information, such as un‑patched exploit detail, must be handled with care, and manufacturers may need to coordinate embargoes with CSIRTs to protect users during coordinated vulnerability disclosure.
A single security event can trigger obligations under several regimes at once. Reconciling the EU cyber resilience acts 24hour reporting duty with NIS2, DORA and the GDPR is one of the hardest practical tasks, because each regime has a distinct trigger, recipient and deadline.
| Regulation | Trigger for reporting | Reporting recipient | Reporting deadline | Key difference |
|---|---|---|---|---|
| Cyber Resilience Act (Article 14, Regulation (EU) 2024/2847) | Awareness of an actively exploited vulnerability or a severe incident affecting product security | National CSIRT (coordinator) and ENISA via single reporting platform | Early warning within 24 hours, then fuller notification and final report | Product‑centric; covers vulnerabilities as well as incidents |
| NIS2 Directive (Directive (EU) 2022/2555) | Awareness of a significant incident affecting an essential or important entity | National CSIRT or competent authority | Early warning within 24 hours, incident notification within 72 hours, final report within one month | Entity‑centric; applies to in‑scope sectors and services |
| DORA (Regulation (EU) 2022/2554) | Major ICT‑related incident affecting a financial entity | Relevant financial competent authority | Staged reporting of initial, intermediate and final reports | Sector‑specific to financial entities and their ICT providers |
| GDPR (Regulation (EU) 2016/679) | Personal data breach likely to result in a risk to individuals | Supervisory authority (and affected individuals where high risk) | Notification to the authority within 72 hours of awareness | Personal‑data‑centric; focused on rights of data subjects |
The overlaps mean manufacturers should maintain a single incident intake that fans out to the correct regimes. Where an event is an actively exploited vulnerability in a product, the CRA early warning within 24 hours is likely to be the first filing. If the same event compromises personal data with risk to individuals, a GDPR notification to the supervisory authority within 72 hours will run in parallel. If the manufacturer is also an in‑scope NIS2 entity or a financial entity under DORA, those obligations sequence alongside. The practical rule is to map each regime to a named owner and to draft a coordinated reporting plan so that no deadline is missed and no filing contradicts another.
(Interpretive guidance; not legal advice.
Because the EU cyber resilience acts 24hour reporting duty depends on prompt awareness, contracts with component suppliers and integrators are now a compliance instrument, not a formality. The clauses below are illustrative drafting starting points, not legal advice, and should be tailored to each relationship.
Suppliers of components with digital elements should be obliged to notify the manufacturer of any vulnerability or incident affecting the supplied component within a short, contractually fixed window, materially shorter than 24 hours, so the manufacturer retains time to assess and file its own early warning. The clause should specify the channel, minimum content and a named 24/7 contact.
Contracts should include warranties that components are free from known vulnerabilities at delivery, commitments to provide security updates for a defined support period, and obligations to cooperate in root‑cause analysis and coordinated disclosure. Where a supplier maintains open‑source or third‑party dependencies, the obligation to monitor and report should extend to those dependencies.
Allocate, in advance, who bears the cost of forensic investigation, patch development, user notification and remediation where a component is the root cause. A coordinated disclosure clause should require the supplier to align on timing and messaging, and to refrain from unilateral disclosure that could undermine the manufacturer’s user protection obligations.
Review cyber and product liability policies to confirm that CRA‑driven notification, remediation and potential fines exposure are addressed, and that supplier indemnities dovetail with insurance recoveries rather than leaving gaps between them.
The following action list translates the EU cyber resilience acts 24hour reporting duty into concrete tasks with clear ownership. Treat these as draft and illustrative, and adapt to your organisation.
Failure to meet the EU cyber resilience acts 24hour reporting duty can carry material consequences. Under the Cyber Resilience Act, infringements of the reporting obligations are subject to administrative fines, with maximum amounts set out in the Regulation according to the category of obligation breached; the highest tiers can reach the greater of a fixed euro cap or a percentage of worldwide annual turnover. Manufacturers should confirm the applicable fine tier for the reporting obligations against the current text of the Regulation and any Spanish implementing measures, rather than assuming a single figure. Enforcement is cross‑border by design, so a non‑EU manufacturer cannot assume distance provides shelter.
Manufacturers should preserve forensic evidence from the moment awareness arises, maintain clear internal reporting lines, and consider legal privilege carefully when instructing investigations, so that the factual record supports both compliance and any subsequent defence. Documented, contemporaneous decision‑making around the notification assessment is among the most valuable protections against enforcement risk. (Interpretive guidance; not legal advice.
The EU cyber resilience acts 24hour reporting duty is a demanding, fast‑moving obligation that will test the incident readiness of every manufacturer, importer and distributor selling products with digital elements into the EU. With 11 September 2026 fixed as the first mandatory application date for the Article 14 reporting duties, the window to update incident response plans, rework supplier contracts, verify national CSIRT and ENISA channels, and rehearse the 24‑hour flow is closing. Organisations that treat the EU cyber resilience acts 24hour reporting requirements as a cross‑functional programme, legal, security, procurement and communications working from a single coordinated plan, will be far better placed than those that leave it to the incident itself.
For jurisdiction‑specific advice on Spanish reporting channels, contract drafting and cross‑regulatory sequencing, seek qualified counsel before the deadline.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.
posted 4 minutes ago
posted 23 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message