Cybersecurity & EU Regulation
Cyber Resilience Act Article 14: Reporting Duties and Readiness Checklist
The Cyber Resilience Act introduces strict vulnerability and incident reporting duties for manufacturers of connected products. This client alert explains the Article 14 reporting framework, key deadlines and the practical steps companies should take before the obligations become operational.

Legal & Strategic Advisory — AI Act · GDPR · NIS2 · Cyber Resilience Act
Cyber Resilience Act — Article 14 Reporting
Client Alert & Readiness Checklist
The Cyber Resilience Act is the third leg of the EU's shift from voluntary cybersecurity practice to statutory duty, joining NIS2 and the AI Act in attaching hard obligations — and hard fines — to how connected products are built and maintained. Where GDPR gave companies roughly two years to prepare before enforcement, the Cyber Resilience Act's core reporting duty arrives on a matter of weeks once its implementing detail falls into place, and 11 September 2026 is the first such date to bite.
The obligation itself is a departure from how most manufacturers have treated product security: an internal engineering matter becomes an external notification duty running in hours, not weeks, enforced through a dedicated EU reporting platform. It attaches to the manufacturer regardless of where in the world they are based, provided the product reaches the EU market — which catches a wide range of Ukrainian, UK, US and Asian manufacturers who have assumed EU rules do not reach them directly.
What follows is the practical scope test, the reporting timeline, and the readiness steps we recommend completing before the date.
From 11 September 2026, the vulnerability- and incident-reporting duty under Article 14 of Regulation (EU) 2024/2847 (the Cyber Resilience Act) becomes enforceable. There is no transition period and no grandfathering for products already on the market. This note sets out who is caught, what must be reported and by when, and the steps we recommend completing before the date.
DOES THIS APPLY TO YOU?
The duty applies if you manufacture — inside or outside the EU — a “product with digital elements” that is placed on the EU market. In practice, that reaches:
☐ Hardware with any network or data connection, and embedded software or firmware you produce for it
☐ Standalone software products or components, including open-source components you commercially support
☐ Remote data processing solutions functionally linked to a hardware or software product you manufacture
☐ White-label or OEM products sold under your brand, regardless of where they are manufactured
WHAT MUST BE REPORTED, AND WHEN
Trigger | Early warning | Notification | Final report |
Actively exploited vulnerability | 24 hours — flags affected Member States | 72 hours — nature of the exploit, corrective/mitigating measures available | 14 days after a fix is available — severity, impact, threat-actor detail |
Severe incident | 24 hours — whether unlawful or malicious acts are suspected | 72 hours — nature of the incident, initial assessment, mitigation taken | 30 days — full description, root cause, mitigation applied |
All notifications route through ENISA's Single Reporting Platform to the relevant national CSIRT. Affected users must separately be informed “without undue delay,” with mitigation guidance in a structured, machine-readable format where relevant. If you miss the deadline, the CSIRT may notify users itself.
READINESS CHECKLIST — COMPLETE BEFORE 11 SEPTEMBER
☐ Inventory every product with digital elements on the EU market, including legacy products, embedded software and OEM/white-label lines
☐ Confirm the manufacturer of record for each product across group entities, OEM arrangements and white-label distribution
☐ Identify your main EU establishment and monitor ENISA's list of coordinating national CSIRTs for your routing
☐ Register for ENISA's Single Reporting Platform and complete any available training or dry-run once access opens
☐ Set internal thresholds for what counts as an actively exploited vulnerability or a severe incident, so the 24-hour clock is unambiguous
☐ Pre-build reporting templates matching the SRP's data fields for each of the three tiers above
☐ Assign a named owner bridging security, legal and communications for the reporting decision and sign-off
☐ Draft a user-notification playbook, including the structured/machine-readable format for mitigation guidance
WHAT NON-COMPLIANCE COSTS
Fines reach the Cyber Resilience Act's top tier: up to €15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Micro and small enterprises are exempted specifically from fines for missing the 24-hour early-warning deadline — every other duty still applies to them in full.
How CORVUS AI can help — a scope assessment confirming whether your products are caught, and an SRP-readiness review covering routing, thresholds and templates, typically completed within one week.
Oleksandr Sobovyi, PhD · Founder, CORVUS AI · oleksandr@corvusai.eu
This note is general information for CORVUS AI clients and contacts, not legal advice on any specific product or fact pattern.
