← All knowledge notes

EU cybersecurity news · 17

The EU Cyber Resilience Act’s 24-hour reporting clock is now running

Manufacturers of connected hardware now face a 24-hour early-warning deadline for certain cybersecurity events—more than a year before the CRA’s main product rules take effect.

Published
Reading time
7 minutes
Last updated
A smartphone beside a disconnected charging cable on a wooden desk, used as an editorial image for connected-hardware cybersecurity reporting.
Editorial photograph of a smartphone and charging cable. It does not depict a CRA notification, affected product, security incident, ZIMONAI client, supplier or test result.Editorial photograph · Karola G / Kaboompics.com

News summary

EU Cyber Resilience Act reporting began on 11 September: manufacturers must now report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The sequence starts with an early warning within 24 hours, a fuller notification within 72 hours and a final report through ENISA’s Single Reporting Platform. The bigger story is the timing: reporting starts 15 months before the main product rules apply on 11 December 2027 and can reach products already sold in the EU. Connected-hardware manufacturers now need product, firmware, support and incident teams to assemble one defensible record before the clock runs out.

  • 01

    From 11 September 2026, manufacturers must use ENISA’s Single Reporting Platform for mandatory notifications of actively exploited vulnerabilities and severe security incidents.

  • 02

    The sequence is an early warning within 24 hours, a notification within 72 hours, then a final report on the statutory timetable for the event type.

  • 03

    Reporting can reach products already available in the EU before the broader 11 December 2027 compliance date, making legacy product records and supplier escalation paths immediately relevant.

01

What changed on 11 September?

The European Commission says manufacturers must now notify two defined event types: an actively exploited vulnerability, where reliable evidence shows malicious exploitation without the system owner’s permission, and a severe incident affecting the security of a product with digital elements. A routine bug, failed update or unverified report is not automatically one of these events; the legal trigger depends on the CRA definitions and the facts known to the manufacturer.

Once the manufacturer becomes aware, the first deadline is short. The early warning is due without undue delay and within 24 hours, while the notification with general information and an initial assessment is due within 72 hours. For an actively exploited vulnerability, the final report follows no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, it is due within one month of the 72-hour notification.

02

Why does this arrive before the rest of the CRA?

Most CRA product obligations—including the wider cybersecurity requirements and conformity framework—apply from 11 December 2027. Reporting was deliberately brought forward to 11 September 2026. The Commission’s legislative summary states that the reporting duty applies to products with digital elements made available on the EU market, including products placed there before the 2027 date.

That split creates an unusual transition period: a product may not yet be subject to the full 2027 design regime, but its manufacturer may already need to report an active exploit or severe incident. ENISA’s platform is designed as a single entry point; the report is routed to the coordinating national Computer Security Incident Response Team and, except in narrowly defined circumstances, made available to ENISA and relevant authorities.

  • 11 September 2026: mandatory manufacturer reporting begins
  • Within 24 hours: early warning after awareness
  • Within 72 hours: fuller notification and initial assessment
  • Final report: deadline depends on vulnerability or incident route
  • 11 December 2027: the CRA’s main product obligations apply
03

What does this mean for connected charging hardware?

The CRA covers hardware and software products with digital elements when their intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A conventional, non-connected charger should not be treated as identical to an app-controlled power bank, network-managed charging hub or device whose firmware and remote service are integral to its function. Whether a particular product is in scope requires a product-specific legal and technical assessment.

ZIMONAI’s editorial view is that the reporting deadline will expose weak handoffs in hardware supply chains. A brand may receive customer complaints, a module vendor may see the vulnerable component, and an app developer may hold the relevant logs; none of them alone has the whole incident. Manufacturers that cannot connect model, firmware version, component source, affected markets and decision ownership will lose time before they can judge and report. Buyers should therefore watch whether connected-product suppliers publish security contacts, support periods and update channels—not merely whether a package carries familiar compliance marks.

What to watch next

What to watch next

  • Whether ENISA updates its launch guidance or platform workflow after real submissions begin
  • How national CSIRTs interpret awareness and severity in early cases
  • Whether manufacturers publish dedicated vulnerability-reporting contacts and support periods
  • How brands connect product models and firmware versions to third-party software components
  • Whether incident notices identify affected markets, versions and available mitigations clearly
  • How the Commission’s 2027 implementation guidance changes product documentation and conformity plans

Sources and evidence

Sources and evidence

Facts in this note were checked against the following primary and independent sources. Links open the source publisher’s website.

  1. 01
  2. 02
    European Union Agency for CybersecurityCRA Single Reporting Platform
  3. 03
    Official Journal of the European UnionRegulation (EU) 2024/2847 — Cyber Resilience Act
  4. 04
  5. 05
    Ireland National Cyber Security CentreEU Cyber Resilience Act — reporting obligations

Produced by the ZIMONAI Editorial Desk at Zhimengwan Technology.

Charger & power electronics

Have a supplier claim you need checked?

Send the supplier, proposed product and buying decision. We will define what can be reviewed and which scope fits.

Discuss your requirement