Europe's New Cyber Reporting Clock Starts Now — and Most Manufacturers Aren't Ready
Published on 09/11/2026 at 11:31 | Editorial boerse-global.de
Manufacturers of any product carrying a digital component are now legally bound to flag serious security incidents and actively exploited flaws to authorities on a tight clock, under the EU's Cyber Resilience Act. The reporting duties, set out in Article 14 of the regulation, have been brought forward, with a single EU-wide platform serving as the main channel for submissions.
Three deadlines, one portal
The regime operates in stages. A manufacturer must file an initial early warning within 24 hours of learning about an incident or vulnerability. A fuller, supplementary notification is due within 72 hours. The sequence closes with a final report, submitted 14 days after corrective or remedial measures are implemented — or, in especially severe cases, no later than one month after the first notification.
Submissions run through the ENISA Single Reporting Platform (SRP), which requires an EU Login and multi-factor authentication. According to reports, the central platform will only go live on the relevant cut-off date. No advance registration for companies and no system trials were planned beforehand. In Germany, the Federal Office for Information Security (BSI) acts as the competent national authority.
Who is caught, and for how long
The obligation covers every manufacturer of products with digital elements, regardless of whether the company is based inside or outside the EU. It also extends to products already placed on the market before 11 December 2027. Regulators have made clear that not every identified weakness triggers a report — the decisive factor is whether third parties are actively exploiting it.
Beyond incident reporting, the CRA will require security updates across a defined support period. As a rule this should last at least 5 years, or match the product's expected service life where that is shorter. The duties reach beyond manufacturers to distributors, installers, procurers and operators of connected devices.
Penalties, and a small-business carve-out
Breaches can draw fines of up to €15 million or 2.5% of worldwide annual turnover. Those sanctions only apply from 11 December 2027, the same date on which further CRA requirements become binding — among them software bills of materials (SBOMs) and comprehensive risk assessments.
Micro and small enterprises get relief on enforcement of fines tied to the 24-hour deadline. Companies with fewer than 10 or 50 employees, and annual turnover below €2 million or €10 million respectively, are exempt from those specific penalties.
German industry: aware, but not prepared
Survey evidence paints a patchy picture of readiness. A Bitkom poll of 1,003 companies with at least 10 employees, conducted in spring 2026, found that 67% of respondents had heard of the Cyber Resilience Act — yet only 29% understood what it concretely means for their own organisation. Around 38% said they could not yet gauge the consequences, while 28% had no knowledge of the rules at all.
A separate ONEKEY study of 200 German industrial firms highlights the operational strain: 62% see the 24-hour reporting duty as a major challenge. Even so, 61% of those surveyed have already budgeted for implementation. Roughly 20% have a dedicated CRA team in place, and 28% intend to assign up to 10 staff to compliance with the new security requirements.
