The EU Cyber Resilience Act: mandatory reporting requirements
Under the EU Cyber Resilience Act, the reporting of actively exploited vulnerabilities and severe incidents becomes mandatory today, even for products already on the market. In this article, we take a look at how these new reporting duties affect manufacturers — and how Raspberry Pi can help you stay compliant.
The Cyber Resilience Act (CRA) is the EU’s primary legislation focused on the cybersecurity of digital products. It places binding requirements on manufacturers of connected products sold on the EU market. Under the CRA, a specific set of reporting obligations takes effect from 11 September 2026; if you sell hardware or software into the EU, this is something to think about.
What you now have to report
Under Article 14, manufacturers must notify ENISA about actively exploited vulnerabilities and severe security incidents according to defined reporting schedules. The type of notification and its level of detail vary depending on the incident and where you stand in the reporting window.
Actively exploited vulnerabilities
An actively exploited vulnerability is any weakness or flaw that has been leveraged by a malicious actor. The reporting schedule for an actively exploited vulnerability is as follows:
- 24 hours — an early warning that a vulnerability is being actively exploited must be issued.
- 72 hours — a follow-up notification with more detail, including the nature of the exploit and the mitigation status, must be issued.
- 14 days — a final report assessing the severity of the exploit and detailing the corrective measure must be submitted within 14 days of the fix becoming available.
Severe incidents
A severe incident is any event that negatively affects, or is capable of negatively affecting, the product’s ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions; or where it has led or could lead to the introduction or execution of malicious code in the product or in a user’s network and information systems.
The reporting schedule for severe incidents differs slightly:
- 24 hours — an early warning stating whether the incident is suspected to be caused by unlawful or malicious acts must be issued.
- 72 hours — a follow-up notification providing more detail, including the nature of the incident and the mitigation status, must be issued.
- One month — a final report detailing the severity and impact, the likely cause, and the applied and ongoing mitigation measures must be submitted within one month of the 72-hour notification.
Note that this is narrower than full CRA conformity (which includes CE marking, technical documentation, and essential cybersecurity requirements), which is still due to land on 11 December 2027. The 11 September date specifically marks the day that the vulnerability and incident reporting requirement comes into force.
How Raspberry Pi can help
If you’re building products with Raspberry Pi hardware and need to understand how this affects your own CRA obligations, here’s where to go:
- For more information about what Raspberry Pi is doing and how we can help, see our Cyber Resilience Act page and our CRA white paper.
- For general security information, see our security page.
- For product documentation and compliance information — including technical datasheets and compliance documents — visit the official Raspberry Pi Product Information Portal.
- To report or ask about vulnerabilities affecting Raspberry Pi products, contact us via [email protected].
- For technical support, contact us via [email protected].
- For product compliance support, contact us via [email protected].
No comments
Jump to the comment form