The European regulation on cyber resilience is now entering its operational phase. Here we discuss the relevant parties and what they need to report starting from this date.
Scientists confirm: This is the most effective way to get your cat’s attention, according to new research
Elderly Couple Refuses Reserved Seats—Viral Train Standoff Sparks Fiery Debate on Courtesy
- How the deadline of September 11 impacts and who is affected?
- How to report an exploited vulnerability or a severe incident?
- An intermediate step in the implementation of the CRA
The Cyber Resilience Act (CRA) reaches its first mandatory stage this Friday, September 11, 2026. Article 14 of the European regulation on cyber resilience requires manufacturers of products with digital components to report actively exploited vulnerabilities and serious incidents impacting their security.
What does the September 11 deadline change, and who is affected?
The scope is broad: software, hardware, and their remote data processing solutions, as long as they are made available on the EU market in a commercial capacity. The responsibility rests on the manufacturer, the entity that develops or has the product developed and markets it under its own name.

Why You Should Never Reheat These Foods in the Microwave – The Hidden Dangers Experts Warn About
I tried the top 5 guard dogs—here’s what makes these breeds the ultimate protectors
Here are the stakeholders affected by this deadline:
- Software publishers: desktop or mobile applications, firmware, components sold separately,
- Manufacturers of connected hardware: from household objects to network equipment,
- Agencies and studios, who market under their own brand a product they have developed or had developed,
- Importers and distributors, who brand a product with their label, or modify it before re-marketing it.
The obligation isn’t limited to new products. Article 69 of the regulation subjects to Article 14 products that were already on the market before December 11, 2027, the date when the text is fully applicable. Thus, software that has been on the market for several years and is still maintained enters the scope from day one.
For users, the obligation targets the supplier, not the company that utilizes the product. However, a client can demand from the manufacturer that security updates are available for the entire support period of the product, as ANSSI reminds in its FAQ dedicated to the CRA.
How to report an exploited vulnerability or a severe incident?
In practice, all notifications are to be submitted through a single platform, shared across the entire European Union, which is set to go live on September 11, 2026. This platform is managed by ENISA, the EU’s cybersecurity agency. The manufacturer must post an initial alert within 24 hours of discovering a vulnerability or incident, followed by a complete notification within 72 hours. Additional information is then added to this notification as required by the regulation.

Upon registering on the platform, the publisher specifies the country of their primary establishment. Then, with each notification, they must detail the countries affected by the reported vulnerability or incident. Each EU country has an incident response center tasked with receiving these reports. In France, this role is played by CERT-FR (French Computer Emergency Response Team), attached to ANSSI, which accesses the information provided by the manufacturer and forwards it to other concerned countries.
This center can also pass this information to the national market surveillance authority (ANFR for France). It is this authority that checks the compliance of marketed products and can enforce necessary corrective or restrictive measures.
A practical guide from the European Commission for applying the CRA
On July 27, 2026, the European Commission published “practical guidelines to assist manufacturers, developers, and businesses of all sizes in meeting their obligations under cyber resilience legislation.” This document clarifies the scope of products covered, the concept of substantial modification, and support periods. It includes 67 practical examples and decision trees designed for microenterprises and SMEs.
An intermediate step in the implementation of the CRA
The timeline for the regulation extends until the end of 2027, with September 11, 2026, being just one milestone. The next step involves compliance checks: significant class II products and critical products will need to be assessed by a notified body. In France, ANSSI serves as this notifying authority.
The notification procedure will be published soon by ANSSI. This will be based on the accreditation by Cofrac of the candidate body for notification. Accreditation is expected to open in the second half of 2026, and notifications should thus begin by the end of 2026, according to the FAQ.
The full implementation of the regulation will occur on December 11, 2027, with essential cybersecurity requirements, technical documentation, the EU declaration of conformity, and CE marking as stipulated by the CRA.
Similar Posts
- Cyber Resilience Act Explained: Top 5 Questions Answered!
- Cybersecurity Alert: Microsoft and ENISA Reveal How Hackers Exploit Employee Trust
- 7 Free Tools to Boost Your Business Cybersecurity: Protect Your Data Now!
- MacBook Pro M5 Launches in Europe: First Mac Ever Sold Without a Charger!
- Data Breach Crisis: Essential Communication Strategies in the First Hours

Jordan Park writes in-depth reviews and editorial opinion pieces for Touch Reviews. With a background in UI/UX design, Jordan offers a unique perspective on device usability and user experience across smartphones, tablets, and mobile software.