Guide · IT security

Cyber Resilience Act: what starts on 11 September

In a few days the first hard obligation of the Cyber Resilience Act takes effect: anyone who manufactures a product with digital elements must report actively exploited vulnerabilities within 24 hours. Unlike NIS2, company size plays no role here – a business with twelve employees is covered too.

By Dipl.-Ing. Mohamed Khater, Founder and Managing Director, since 1992 · · 9 min read

Why this regulation takes many by surprise

The Cyber Resilience Act – Regulation (EU) 2024/2847 – entered into force on 11 December 2024. Because it only applies in full from 11 December 2027, hardly anyone among small and medium-sized businesses has it on their radar. What gets overlooked is the earlier date: the reporting obligations under Article 14 already apply from 11 September 2026.

The second reason for the surprise is its scope. NIS2 is tied to sector and size; the CRA is tied to the product. If you build machines with control systems, manufacture measuring devices, produce electronics or develop software, you are covered – regardless of how many people work in the business. There is no threshold like the one in NIS2.

The group of those with obligations is also wider than the term “manufacturer” suggests. Anyone who sells third-party software under their own name or substantially modifies a purchased product counts as a manufacturer themselves. Importers and distributors have their own checking obligations.

Tool

Are we affected? A check in four steps

An initial assessment in under a minute. The evaluation runs in your browser – nothing is transmitted and nothing is stored.

1 What is your role in relation to the product?

Anyone who sells third-party software under their own name or substantially modifies a product also counts as a manufacturer.

2 Does the product contain digital elements?

Software, firmware or embedded control – standalone or inside a device.

3 Can the product exchange data with a device or network?

Directly or indirectly – network, Wi-Fi, Bluetooth, USB, maintenance interface, cloud connection.

4 Is the product already covered by its own specific regulation?

Medical devices, vehicles, aviation and a few other areas are excluded because their own rules apply. Pure services without a delivered product are not covered either.

Result

Answer the four questions to get an initial assessment.

This check is for orientation only and is not legal advice. Classifying a specific product – especially the demarcation from rules that take precedence and the assignment to a product class – belongs in expert hands. The text of Regulation (EU) 2024/2847 is authoritative.

Article 14

The three-stage reporting chain

Two events must be reported: actively exploited vulnerabilities in your own product, and severe incidents that affect its security. Both go through the same first two stages.

  • Early warning within 24 hours. Only a few details: type of notification, manufacturer, product, a title and the member states in which the product has been made available. For incidents, also whether a malicious act is involved.
  • Notification within 72 hours. Builds on the early warning: nature of the vulnerability, nature of the exploitation, countermeasures taken and what users can do themselves.
  • Final report – with two different triggers. For a vulnerability, within 14 days of a fix becoming available. For a severe incident, within one month of the 72-hour notification. If you handle both cases with the same form, you will inevitably calculate one of the two deadlines wrongly.
  • One reporting channel for everything. Notifications are submitted via ENISA's single reporting platform and go simultaneously to the coordinating national CSIRT – in Germany, the BSI (German Federal Office for Information Security) – and to ENISA.

Tool

Deadline calculator under Article 14

Enter the time you became aware. The calculator gives you the three deadlines – and distinguishes between the two triggers for the final report.

1 When did you become aware?

The moment reliable indications were available – not the moment of internal confirmation.

2 What is it about?

Your deadlines

Enter the time and type to calculate the deadlines.

The calculation follows Article 14 of Regulation (EU) 2024/2847 and does not replace a legal assessment of the individual case. All times are in your local time.

What small manufacturers should know

Fines for breaches of the reporting obligation can reach up to 15 million euros or 2.5 percent of worldwide annual turnover – whichever is higher. That is the regulation's top tier, on the same level as breaches of the essential security requirements.

For micro and small enterprises there is exactly one relief, and it is narrower than it first sounds: fines for missing the 24-hour early warning are excluded. The reporting obligation itself remains, as do the 72-hour notification and the final report – and the exemption does not apply to those.

In practice this means that even a small business needs a named person responsible, a documented time of awareness and access to the reporting platform. If you only start sorting this out after an incident, you have already missed the first deadline.

One detail is often overlooked: products placed on the market before 11 December 2027 are not subject to all the later requirements – but they are covered by the reporting obligations of Article 14 from 11 September 2026. So the devices you have already delivered are not exempt.

In the coming weeks

What to prepare now

The ability to report is the part that must be in place by 11 September. Everything else can wait until December 2027.

  1. Create a product list

    Which products with digital elements do you have on the market, in which versions, since when, in which countries? Without this list you cannot even fill in the early warning.

  2. Name a person responsible

    One person with a deputy, reachable outside business hours too. The 24-hour deadline does not stop for weekends.

  3. Record the time of awareness

    A simple log is enough: who learned what, and when. This moment starts all three deadlines and is the decisive document in the event of a dispute.

  4. Set up the reporting channel and rehearse it once

    Sort out access to the reporting platform and do one dry run of the process. The first real case is the wrong time to go looking for the login.

  5. Build a software bill of materials

    The SBOM is required anyway and is also the backbone of your ability to report: without machine-readable knowledge of which component is in which product version, even the 72-hour notification turns into a search operation.

  6. Define the support period

    How long will you provide a product with security updates? This commitment becomes binding and, from December 2027, must be included in the product information.

What we can take on – and what we cannot

To avoid false expectations: the CRA is product law. Part of it is a technical task, part of it is not.

  • What we can do: vulnerability monitoring of the components in use, building and maintaining the software bill of materials, update and patch processes, securing the development and build environment, technical documentation, reporting channels and logging, tested recovery.
  • What we cannot do: the conformity assessment, the CE marking, the legal classification of your product into a product class and the demarcation from rules that take precedence. For that you need a notified body or specialist legal advice.
  • Why we know the subject: INFONET develops software itself and is therefore on the same side as you. We are currently building these processes in-house – not just on paper.

Frequently asked questions

What we are often asked about this

We only have 15 employees. Does this really affect us?

Yes. Unlike NIS2, the Cyber Resilience Act has no size threshold. Anyone who manufactures a product with digital elements that can exchange data with a device or network is covered. For micro and small enterprises there is only one relief, on fines for a missed 24-hour early warning – the obligation itself remains.

We do not manufacture products, we only use them. What then?

Then you have no obligations of your own under the CRA. You will still notice it: your suppliers will have to commit to a support period, provide security updates and disclose fixed vulnerabilities. Ask about this explicitly the next time you buy – and, for existing devices, ask how much longer they will be supported.

We buy in software and sell it under our own name. Are we a manufacturer?

As a rule, yes. Anyone who places a product on the market under their own name or trademark counts as a manufacturer – as does anyone who substantially modifies a purchased product. This is one of the most common misunderstandings about this regulation.

What counts as “actively exploited”?

There must be reliable evidence that someone is actually exploiting the vulnerability without permission. A reported vulnerability with no sign of exploitation does not trigger the reporting obligation, and neither does a finding from a good-faith security test. In individual cases the line is blurred – if in doubt, have it clarified by an expert rather than interpreting it generously yourself.

Does the CRA also apply to our cloud application?

A pure service with no delivered product is not covered. But as soon as software is installed at the customer's premises, or data processing is an integral part of a delivered product, the classification changes. For service providers, NIS2 and the GDPR are more likely to be relevant anyway.

Is it enough if we deal with this by December 2027?

No. The reporting obligations have applied since 11 September 2026, and they also cover products that were delivered long ago. What can wait until December 2027 are the conformity assessment, the CE marking and the full requirements for new products.

Dipl.-Ing. Mohamed Khater

Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992 and still runs it as its owner. INFONET develops software itself and is therefore covered by the same regulation – the processes described here are currently being put in place in-house as well.

Further reading

Before 11 September

Ready to report in one week.

Product list, person responsible, awareness log, access to the reporting platform: together we can set up the technical part in a few days. Call us while there is still time.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement