The Cyber Resilience Act (CRA) is the first European Union regulation to introduce mandatory cybersecurity requirements for all connected hardware and software products, applying the principle of secure by design throughout the product's entire lifecycle.
Cyber Resilience Act: What changes from September 11, 2026
September 11, 2026, marks one of the first operational deadlines of the Cyber Resilience Act. From that date, the reporting obligations set out in Article 14 of the Regulation will begin to apply.

Article 14 requires the entities involved in the CRA (the manufacturers) to report to the CSIRT and ENISA vulnerabilities in their products when active exploitation is detected, as well as serious incidents that compromise their security. The obligations will apply from 11 September 2026 also to products already placed on the market and falling within the scope of the CRA, thus anticipating the full application of the Regulation scheduled for December 2027.

The reporting model envisaged by the CRA follows the progressive evolution of the analysis, from the first early warning within 24 hours of awareness to the full report to be sent within 14 days of the availability of a corrective or mitigation measure. For a serious incident, the final report must be submitted within one month of the initial notification. The reporting process therefore does not end with the first report, but requires ongoing analysis and updating of information as knowledge of the event increases.
Another clarification concerns components developed by third parties, for which the exploited vulnerability must be evaluated against the product into which the component was integrated. However, the obligations relating to vulnerability management and, where applicable, communication to the entity producing or maintaining the affected component remain applicable. This clarification is relevant in products that depend on a large number of third-party components, because evaluation requires actual knowledge of the dependencies and how they are used in the product.
The guidelines strengthen the role of the cybersecurity risk assessment required by Article 13, requiring that the residual risk be assessed in relation to the appropriate security level for the product and its foreseeable use.
Risk tolerance and economic considerations alone do not justify failing to address significant risks, which must be assessed while also considering external dependencies and third-party components.
The ESRA platform provides manufacturers with a concrete information base to understand, assess, and manage cyber risk, transforming knowledge of the technological environment into useful elements to support the CRA compliance process.
ai.esra SpA – strada del Lionetto 6 Torino, Italy, 10146
Tel +39 011 234 4611
CAP. SOC. € 50.000,00 i.v. – REA TO1339590 CF e PI 13107650015
“This website is committed to ensuring digital accessibility in accordance with European regulations (EAA). To report accessibility issues, please write to: ai.esra@ai-esra.com”
ai.esra SpA – strada del Lionetto 6 Torino, Italy, 10146
Tel +39 011 234 4611
CAP. SOC. € 50.000,00 i.v. – REA TO1339590
CF e PI 13107650015
© 2024 Esra – All Rights Reserved