Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance
  • For manufacturers
  • For importers & distributors
  • For marketplaces

Company

  • About
  • Research
  • Blog
  • Skills
  • Compliance Guides
  • Event
  • Careers

Legal Data

  • Coverage Atlas
  • API Docs
  • Playground

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
Blog/Product Compliance
Product Compliance2026-09-08·6 min read
Naomie Halioua

Naomie Halioua

Co-founder & CRO, AI Research

From 11 September, EU law forces manufacturers to report an exploited vulnerability in any connected product, smart toys and wearables included, within 24 hours: the duty already covers products sold years ago, 15 months before the same regulation's CE-marking deadline

From 11 September, EU law forces manufacturers to report an exploited vulnerability in any connected product, smart toys and wearables included, within 24 hours: the duty already covers products sold years ago, 15 months before the same regulation’s CE-marking deadline

From 11 September 2026, Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, requires every manufacturer of a 'product with digital elements' placed on the EU market, hardware or software with a logical or physical connection to a device or network, connected toys, wearables, smart home assistants, routers and industrial sensors among them, to report an actively exploited vulnerability to its national CSIRT and to ENISA within 24 hours of becoming aware of it, followed by a fuller notification within 72 hours and a final report within 14 days, or within one month for a severe incident. Most coverage has filed 11 September under the Cyber Resilience Act's headline compliance date, 11 December 2027, when CE marking and the essential cybersecurity requirements in Annex I become mandatory, treating the reporting duty as a smaller procedural step on the way there. Article 69(3) of the regulation breaks that reading: it specifically carves the Article 14 reporting duty out of the CRA's general rule that only products placed on the market from December 2027 onward are covered, so the 24-hour clock starts in days for a product a brand has already been selling for years, not only for new launches.

What changes on 11 September

The Cyber Resilience Act is the EU's first horizontal cybersecurity law built around products rather than services: it applies to hardware and software 'products with digital elements' sold into the EU, a category the regulation's own recitals list as covering connected toys, wearables, smart home devices such as door locks and baby monitors, routers, laptops, smartphones and industrial sensors, among many others. It excludes products already regulated elsewhere for cybersecurity, medical devices and in-vitro diagnostics under Regulations (EU) 2017/745 and 2017/746, and motor vehicles under the UNECE-based type-approval regime in Regulation (EU) 2019/2144, along with non-commercial open-source software and products built solely for national defence. Article 14 requires a manufacturer that becomes aware a product in that scope has an actively exploited vulnerability, or has suffered a severe incident affecting its security, to notify the CSIRT designated as coordinator in the EU member state where it has its main establishment, made available to ENISA at the same time unless exceptional circumstances apply. The notification follows a fixed three-step timeline: an early warning within 24 hours flagging the exploitation and, where relevant, its cross-border reach; a fuller vulnerability or incident notification within 72 hours describing severity and any corrective measures taken or available; and a final report within 14 days for a vulnerability, or one month for a severe incident, describing the vulnerability, any exploiting actor and the remedy applied. ENISA's Single Reporting Platform, the shared portal manufacturers use to file all three, is due to be operational the same day the obligation takes effect.

Three details behind the 11 September deadline

01

Only the reporting duty starts now, not the full law

11 September activates Article 14 reporting only. The CRA's essential cybersecurity requirements and CE marking, the part most compliance roadmaps track, do not apply in full until 11 December 2027.

02

It already covers products sold years ago

Article 69(3) exempts the reporting duty from the CRA's general rule that only products placed on the market from December 2027 are covered. A device sold in 2020 needs a working 24-hour reporting process from 11 September 2026.

03

Which CSIRT to notify can depend on your distributor

A manufacturer with no main establishment in the EU must notify the CSIRT of the member state of its authorised representative, importer or distributor handling the highest volume of the product, in that order, not one it can simply choose.

10 Dec 2024

The Cyber Resilience Act, Regulation (EU) 2024/2847, enters into force.

28 Nov 2025

Commission Implementing Regulation (EU) 2025/2392 sets the technical descriptions for "important" (Class I and II) and "critical" product categories.

11 Dec 2025

Commission Delegated Regulation (EU) 2026/881 sets the conditions under which a CSIRT may delay passing a vulnerability report on to other CSIRTs.

11 Jun 2026

The framework for notifying conformity assessment bodies starts applying.

27 Jul 2026

The European Commission approves its official guidance on applying the Cyber Resilience Act.

11 Sep 2026

Article 14 vulnerability and incident reporting applies EU-wide; ENISA’s Single Reporting Platform becomes operational.

11 Dec 2027

The essential cybersecurity requirements (Annex I) and CE marking apply in full.

The numbers behind 11 September

One number is how little time a manufacturer gets once a vulnerability is being actively exploited. One is how far the reporting duty sits ahead of the deadline most roadmaps are built around. The third is the ceiling EU law already sets for getting this specific obligation wrong.

24 hours

the deadline, from becoming aware of an actively exploited vulnerability or a severe incident, to submit an early-warning notification to the national CSIRT and ENISA under Article 14

15 months

the gap between the 11 September 2026 reporting duty and 11 December 2027, when the CRA’s essential cybersecurity requirements and CE marking become mandatory

€15M / 2.5%

the higher of a flat fine or a share of a manufacturer's total worldwide annual turnover that Article 64 sets as the maximum penalty for breaching the Article 14 reporting duty

The real subject: a 24-hour duty that assumes classification and distribution data most brands have not built yet

Two details in the text turn 11 September from a cybersecurity-team milestone into a compliance-data problem. The first is Article 69(3). The CRA's general transitional rule says a product placed on the market before 11 December 2027 is not retroactively subject to the regulation unless it later undergoes a substantial modification, the framing behind most 'you have until 2027' coverage. Article 69(3) writes Article 14 out of that shelter: the reporting duty applies to a product with digital elements already on the EU market on 11 September 2026, however long it has already been sold, with no exemption for age or for having shipped before the regulation even existed. A brand cannot answer the 24-hour clock for a 2019 baby monitor or a 2021 fitness tracker by pointing to the 2027 date; it has to already know that product is in scope. The second is the CSIRT itself. A manufacturer with no main establishment in the EU, the position of most brands selling into Europe through local subsidiaries, importers or licensees, does not get to pick a CSIRT: Article 14 sets a fixed order, first the member state of its authorised representative for the highest number of its products, then the member state of the importer placing the highest number of its products on the market, then the member state of the distributor doing the same. None of that is data a security team keeps. It is distribution volume, by product line, by EU country, tracked commercially rather than technically, and a brand only discovers which of those three answers applies to a given product line by working it out in advance, because Article 14 gives it 24 hours to file the first notification once a vulnerability is being actively exploited, not 24 hours to first work out where to send it.

Why it matters for brands

The direct exposure sits with any retail, consumer-goods or luxury brand selling a physical product with any network or device connection into the EU: connected toys, wearables, smart home and beauty devices, routers and connected packaging or anti-counterfeiting tags among the categories the regulation's own examples name. Because Article 14 is already in force from 11 September 2026 and, under Article 69(3), already covers products placed on the market years before that date, the practical task is not a 2027 roadmap item; it is three things a compliance team needs answered this week. First, an accurate scope list: which SKUs, current and legacy, meet the 'product with digital elements' definition, since a company-wide assumption is not enough once the duty runs product by product. Second, a classification against Commission Implementing Regulation (EU) 2025/2392's technical descriptions, default, important Class I or II, or critical, because that classification determines which conformity route the product will need by December 2027 and, more immediately, feeds the severity and content a 24-hour notification has to state. Third, for any brand without an EU-based manufacturing entity, a documented answer to which authorised representative, importer or distributor carries the highest volume of each product line, since that is what fixes which national CSIRT the clock runs against. A brand that can produce all three today can file a compliant report within 24 hours of a live exploit. A brand that cannot spends part of that 24 hours discovering its own product and distribution data instead of containing the vulnerability.

Two ways to read 11 September

The narrow read

The EU's Cyber Resilience Act now requires fast reporting of exploited vulnerabilities in connected products, one more cybersecurity compliance date on the way to the December 2027 CE-marking deadline.

The structural read

Article 69(3) pulls the reporting duty out of the CRA's own grace period for existing products, and Article 14's CSIRT rule ties the 24-hour clock to distribution volume by country, so brands with connected products already on EU shelves need SKU-level scope, classification and distributor data in place now, fifteen months before the deadline the industry actually plans around.

Frequently asked questions

What exactly changes for manufacturers on 11 September 2026?

Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, starts applying: a manufacturer of a 'product with digital elements' sold into the EU must report an actively exploited vulnerability or a severe security incident to its national CSIRT and to ENISA within 24 hours of becoming aware of it, followed by a fuller notification within 72 hours and a final report within 14 days for a vulnerability, or one month for a severe incident. ENISA's Single Reporting Platform, the shared portal for filing these reports, is due to be operational the same day.

Does the 11 September reporting duty apply to products already sold before that date?

Yes. The CRA's general transitional rule in Article 69 says a product placed on the market before 11 December 2027 is not retroactively covered unless it later undergoes a substantial modification. Article 69(3) specifically excludes the Article 14 reporting duty from that exemption, so it applies from 11 September 2026 to any in-scope product already on the EU market, regardless of when it was first sold.

Which authority does a non-EU brand have to report to?

A manufacturer with no main establishment in the EU must notify the CSIRT of a specific member state, determined in a fixed order: first, the member state of its authorised representative handling the highest number of its products; if there is none, the member state of the importer placing the highest number of its products on the market; and if there is neither, the member state of the distributor doing the same. That ranking is based on distribution volume by country, information most brands hold commercially rather than in a security team, which is why working it out has to happen before an incident, not during the 24-hour window.

Sources

  1. European Commission, Shaping Europe’s digital future: "Cyber Resilience Act, Reporting obligations" (Article 14 timeline: 24-hour early warning, 72-hour notification, 14-day / one-month final report, CSIRT and ENISA)
  2. EUR-Lex: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), including Article 14, Article 64 and Article 69 transitional provisions
  3. ENISA: "Single Reporting Platform (SRP)" (operational date, role in Article 14 filings)
  4. EUR-Lex: Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 laying down technical descriptions of the categories of important and critical products with digital elements
  5. EUR-Lex: Commission Delegated Regulation (EU) 2026/881 of 11 December 2025 on the conditions for a CSIRT to delay dissemination of a vulnerability notification
  6. K&L Gates: "Cyber Resilience Act Part One: Companies Prepare for First Notification Obligations to Apply as Commission Publishes Implementation Guidance" (independent confirmation of the 11 September 2026 reporting start and 2026 implementation milestones)
  7. Timelex: "Cyber Resilience Act, Reporting Obligations for Manufacturers almost applicable, does it concern me?" (Article 69(3) retroactive scope for existing products, CSIRT hierarchy for non-EU manufacturers)
  8. Bird & Bird: "CRA’s phased entry into application starts in September 2026" (independent confirmation of the phased timeline, conformity assessment body framework from 11 June 2026)
  9. CRA Act (craact.eu): "Article 64, Penalties, EU Cyber Resilience Act" (€15,000,000 / 2.5% worldwide turnover ceiling for Article 13/14 breaches)

Note on verification: this session's network access allows search but blocks direct page retrieval, including from eur-lex.europa.eu, digital-strategy.ec.europa.eu and enisa.europa.eu. The Article 14 timeline, the Article 69(3) carve-out for existing products, the CSIRT hierarchy for non-EU manufacturers, the Implementing and Delegated Regulation dates and numbers, and the Article 64 penalty ceiling were each confirmed through search-indexed excerpts of the regulation text and the official EU pages, cross-checked against multiple independent legal and cybersecurity-compliance trackers (K&L Gates, Timelex, Bird & Bird, Element, ISMS Copilot, cyberresilienceact.eu, craact.eu) that separately reported the same dates, article numbers and figures.

Frequently asked questions

What exactly changes for manufacturers on 11 September 2026?

Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, starts applying: a manufacturer of a 'product with digital elements' sold into the EU must report an actively exploited vulnerability or a severe security incident to its national CSIRT and to ENISA within 24 hours of becoming aware of it, followed by a fuller notification within 72 hours and a final report within 14 days for a vulnerability, or one month for a severe incident. ENISA's Single Reporting Platform, the shared portal for filing these reports, is due to be operational the same day.

Does the 11 September reporting duty apply to products already sold before that date?

Yes. The CRA's general transitional rule in Article 69 says a product placed on the market before 11 December 2027 is not retroactively covered unless it later undergoes a substantial modification. Article 69(3) specifically excludes the Article 14 reporting duty from that exemption, so it applies from 11 September 2026 to any in-scope product already on the EU market, regardless of when it was first sold.

Which authority does a non-EU brand have to report to?

A manufacturer with no main establishment in the EU must notify the CSIRT of a specific member state, determined in a fixed order: first, the member state of its authorised representative handling the highest number of its products; if there is none, the member state of the importer placing the highest number of its products on the market; and if there is neither, the member state of the distributor doing the same. That ranking is based on distribution volume by country, information most brands hold commercially rather than in a security team, which is why working it out has to happen before an incident, not during the 24-hour window.

Related resources

Product Compliance · 2026-04-28

CE marking in 2026: from physical goods to digital products

Compliance · 2026-02-16

Cybersecurity Compliance for Tech Companies in the EU: NIS2, DORA and Beyond

Compliance · 2026-03-01

NIS2 Compliance Guide: What Every EU Business Must Know

Product Compliance · 2026-03-13

Digital Product Passport (DPP): What Retail Brands Need to Know

Try Cleo: free regulatory risk scan

See your regulatory landscape mapped in minutes. No signup, no credit card.

See the product in action
Book a call
Anaelle GuezNaomie Halioua
Request a demo