We use some essential cookies to make our website work.

We use optional cookies, as detailed in our cookie policy, to remember your settings and understand how you use our website.

The EU Cyber Resilience Act: mandatory reporting requirements

Under the EU Cyber Resilience Act, the reporting of actively exploited vulnerabilities and severe incidents becomes mandatory today, even for products already on the market. In this article, we take a look at how these new reporting duties affect manufacturers — and how Raspberry Pi can help you stay compliant.

The Cyber Resilience Act (CRA) is the EU’s primary legislation focused on the cybersecurity of digital products. It places binding requirements on manufacturers of connected products sold on the EU market. Under the CRA, a specific set of reporting obligations takes effect from 11 September 2026; if you sell hardware or software into the EU, this is something to think about.

What you now have to report

Under Article 14, manufacturers must notify ENISA about actively exploited vulnerabilities and severe security incidents according to defined reporting schedules. The type of notification and its level of detail vary depending on the incident and where you stand in the reporting window.

Actively exploited vulnerabilities

An actively exploited vulnerability is any weakness or flaw that has been leveraged by a malicious actor. The reporting schedule for an actively exploited vulnerability is as follows:

  • 24 hours — an early warning that a vulnerability is being actively exploited must be issued.
  • 72 hours — a follow-up notification with more detail, including the nature of the exploit and the mitigation status, must be issued.
  • 14 days — a final report assessing the severity of the exploit and detailing the corrective measure must be submitted within 14 days of the fix becoming available.

Severe incidents

A severe incident is any event that negatively affects, or is capable of negatively affecting, the product’s ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions; or where it has led or could lead to the introduction or execution of malicious code in the product or in a user’s network and information systems.

The reporting schedule for severe incidents differs slightly:

  • 24 hours — an early warning stating whether the incident is suspected to be caused by unlawful or malicious acts must be issued.
  • 72 hours — a follow-up notification providing more detail, including the nature of the incident and the mitigation status, must be issued.
  • One month — a final report detailing the severity and impact, the likely cause, and the applied and ongoing mitigation measures must be submitted within one month of the 72-hour notification.

Note that this is narrower than full CRA conformity (which includes CE marking, technical documentation, and essential cybersecurity requirements), which is still due to land on 11 December 2027. The 11 September date specifically marks the day that the vulnerability and incident reporting requirement comes into force.

How Raspberry Pi can help

If you’re building products with Raspberry Pi hardware and need to understand how this affects your own CRA obligations, here’s where to go:

No comments
Jump to the comment form

Leave a Comment