Information Center
Information Center
Knowledge Center
2026-03-16

The manufacturer reporting obligations under the EU Cyber Resilience Act will take effect this year

Share:

Under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), although most of the Act’s requirements will not be fully applicable until 11 December 2027, one important obligation closely related to manufacturers—the manufacturer reporting obligation—will apply earlier, starting from 11 September 2026.

 

This means that from that date onward, manufacturers placing on the EU market relevant products with digital elements (hereinafter referred to as “digital products”) must not handle matters internally only if they discover that their products contain vulnerabilities that have been actively exploited by hackers, or if serious incidents affecting product security occur. Instead, they must submit reports, in accordance with the Act, to the single reporting platform maintained by the EU.

 

According to the Act, after becoming aware of the above-mentioned vulnerabilities or security incidents, manufacturers must first issue an early warning within 24 hours. Subsequently, they must submit additional information within 72 hours, describing the basic situation, the affected products, and the measures already taken. A final report must then be submitted within one month, providing further details on the impact and causes of the vulnerability or incident, as well as the remediation or mitigation measures adopted.

 

In addition to reporting to the single reporting platform, manufacturers must, where necessary, inform users of the risks and advise them of the protective measures they can take.

 

If manufacturers fail to comply with these obligations, the Act provides for relatively severe penalties. According to the Act, undertakings that violate the relevant requirements may face fines of up to EUR 15 million or 2.5% of the undertaking’s total worldwide annual turnover in the preceding financial year, whichever is higher. If an undertaking provides incorrect, incomplete, or misleading information to regulatory authorities, it may be subject to fines of up to EUR 5 million or 1% of its total worldwide annual turnover in the preceding financial year, whichever is higher.

 

The Act provides certain considerations for micro and small enterprises. Micro and small enterprises will not be fined for failing to fulfill the obligation to issue an early warning within 24 hours. Under the EU definition, a micro-enterprise is one that employs fewer than 10 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 2 million. A small enterprise is one that employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million.

 

The EU’s requirements for manufacturers no longer focus solely on “pre-market compliance,” but further emphasize ongoing post-market cybersecurity responsibilities. From 11 September 2026, manufacturers must establish internal mechanisms for vulnerability identification, incident response, external reporting, and information retention; otherwise, they will face significant compliance and enforcement risks.



Relevant information

Canada ISED Update No.2 | RSS Gen Issue 6: Analysis of General Compliance Standards for Radio Frequency Equipment
2026-08-21

Canada ISED Update No.2 | RSS Gen Issue 6: Analysis of General Compliance Standards for Radio Frequency Equipment

Last week, we mentioned that Innovation, Science and Economic Development Canada (ISED) released RSS 310 Issue 6: Licence Exempt Radio Frequency Devices...

CRA Implementation Enters a Critical Phase
2026-08-21

CRA Implementation Enters a Critical Phase

In August 2026, preparations for the implementation of the EU Cyber Resilience Act (CRA) entered a critical stage. With the reporting obligations set to take effect on September 11, 2026, drawing near, the European Commission and the European Union Agency for Cybersecurity (ENISA) have been intensively issuing implementation guidance and materials related to the single reporting platform.

Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements
2026-08-03

Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements

Innovation, Science and Economic Development Canada (ISED) has formally issued RSS-310, Issue 6, “Licence-Exempt Radio Apparatus: Category II Equipment,” replacing Issue 5, which has been in effect since 2020

Privacy Preference Center

We use cookies to allow our website to function properly, personalize content and advertisements, provide social media features, and analyze traffic. We also share information about your use of our website with our social media, advertising, and analytics partners.

View Privacy Policy

Manage consent settings

Necessary Cookies

Uniformly activate

The operation of the website relies on these cookies, and you cannot disable them in the system. These cookies are typically set based on your actions (i.e., service requests), such as setting privacy preferences, logging in, or filling out forms. You can configure your browser to block or prompt you about these cookies, but this may cause certain website functionalities to not work.

Select Language