Skip to content
Phalanx
roRequest a quote
Menu+

CRA: what changed on 11 September 2026

The Cyber Resilience Act reporting obligations took effect. Briefly: who is in scope, which deadlines run, and where to start.

On 11 September 2026 the reporting obligations in Regulation (EU) 2024/2847, the Cyber Resilience Act, became applicable. Not the whole regulation, only the reporting part. That happens to be the part with short deadlines, so it is worth understanding before you need it.

Who it applies to

The regulation addresses manufacturers of products with digital elements made available on the EU market. The wording is broad, and that frightens people more than it should, because in practice most companies are not manufacturers in the sense the regulation means.

Three situations, with completely different consequences:

You are the manufacturer. You place the product on the market under your own name. The reporting obligations are yours, in full.

You supply a manufacturer. Your component goes into somebody else’s product, and they are the one who reports. You have no filing obligation, but you do have a practical and usually contractual one: tell them quickly. Their 24 hours starts when they become aware, and if you find out first and stay quiet, you are spending their deadline.

Software used only internally. You do not place it on the market, so it is not covered.

The third case is the one companies handle worst, and not because it is hard. It is easy. The problem is that they never write it down. An auditor asking a year later why you filed nothing does not want to hear that it did not apply. They want to see that you assessed it and dated the conclusion.

What starts the clocks

Two things: a vulnerability being actively exploited in your product, or a severe incident affecting the security of the product. From the moment you become aware, four deadlines run.

Deadline What you file
24 hours Early warning
72 hours Full notification
14 days Final report for a vulnerability, from when a corrective measure exists
1 month Final report for an incident, from the 72 hour notification

Filing goes through the ENISA single reporting platform, which routes the notification to the CSIRT in the state where you are established. For Romania, that is DNSC.

What “become aware” means

It is the first question you will ask, and the regulation gives you no number in reply. In practice it means the moment somebody in the organisation holds the information and is in a position to recognise it for what it is. Which makes it matter more than it looks who receives vulnerability reports, and how fast they reach a person who can decide.

If you have no single point where that kind of information arrives, fix that first, before any reporting procedure.

Where to start

Not with the reporting procedure. With the inventory.

List the products you place on the market, record the capacity in which you do it for each one, and date the conclusion. If the result is that nothing is in scope, you are done, and you have the evidence. If something is, then the conversation about deadlines becomes real and deserves a written process.

That is the order the CRA module in our platform works in as well: scope determination first, clocks second. A platform that opens a regulatory deadline on a company that owes nothing is not helping anyone.