The manufacturer reporting obligations under the EU Cyber Resilience Act will take effect this year
Under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), although most of the Act’s requirements will not be fully applicable until 11 December 2027, one important obligation closely related to manufacturers—the manufacturer reporting obligation—will apply earlier, starting from 11 September 2026.
This means that from that date onward, manufacturers placing on the EU market relevant products with digital elements (hereinafter referred to as “digital products”) must not handle matters internally only if they discover that their products contain vulnerabilities that have been actively exploited by hackers, or if serious incidents affecting product security occur. Instead, they must submit reports, in accordance with the Act, to the single reporting platform maintained by the EU.
According to the Act, after becoming aware of the above-mentioned vulnerabilities or security incidents, manufacturers must first issue an early warning within 24 hours. Subsequently, they must submit additional information within 72 hours, describing the basic situation, the affected products, and the measures already taken. A final report must then be submitted within one month, providing further details on the impact and causes of the vulnerability or incident, as well as the remediation or mitigation measures adopted.
In addition to reporting to the single reporting platform, manufacturers must, where necessary, inform users of the risks and advise them of the protective measures they can take.
If manufacturers fail to comply with these obligations, the Act provides for relatively severe penalties. According to the Act, undertakings that violate the relevant requirements may face fines of up to EUR 15 million or 2.5% of the undertaking’s total worldwide annual turnover in the preceding financial year, whichever is higher. If an undertaking provides incorrect, incomplete, or misleading information to regulatory authorities, it may be subject to fines of up to EUR 5 million or 1% of its total worldwide annual turnover in the preceding financial year, whichever is higher.
The Act provides certain considerations for micro and small enterprises. Micro and small enterprises will not be fined for failing to fulfill the obligation to issue an early warning within 24 hours. Under the EU definition, a micro-enterprise is one that employs fewer than 10 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 2 million. A small enterprise is one that employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million.
The EU’s requirements for manufacturers no longer focus solely on “pre-market compliance,” but further emphasize ongoing post-market cybersecurity responsibilities. From 11 September 2026, manufacturers must establish internal mechanisms for vulnerability identification, incident response, external reporting, and information retention; otherwise, they will face significant compliance and enforcement risks.
Relevant information
CRA Implementation Enters a Critical Phase
In August 2026, preparations for the implementation of the EU Cyber Resilience Act (CRA) entered a critical stage. With the reporting obligations set to take effect on September 11, 2026, drawing near, the European Commission and the European Union Agency for Cybersecurity (ENISA) have been intensively issuing implementation guidance and materials related to the single reporting platform.
Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements
Innovation, Science and Economic Development Canada (ISED) has formally issued RSS-310, Issue 6, “Licence-Exempt Radio Apparatus: Category II Equipment,” replacing Issue 5, which has been in effect since 2020