Cyber Resilience Act reporting entered operation on 11 September
Confirmed fact. Manufacturers must now report actively exploited vulnerabilities and severe incidents affecting products with digital elements through ENISA's CRA Single Reporting Platform. The European Commission specifies an early warning within 24 hours and notification within 72 hours, followed by the applicable final report. The reporting duty also reaches products already on the EU market, not only products placed there after the CRA's main application date.
Analytical implication. Customers cannot meet their own escalation duties if product suppliers do not identify affected products, validate exploitation and notify contract owners quickly. CRA readiness therefore belongs in product-supplier governance, incident clauses and the service inventory.
Recommended actions
- Map in-scope products to suppliers, deployed versions, business services and contract owners.
- Add explicit customer-notification timing, content and cooperation duties to renewal language.
- Run a tabletop from supplier discovery to 24-hour alert and 72-hour notification.