INTELLIGENCE · CYBER RESILIENCE ACT

CRA reporting obligations are now operational.

As of 11 September 2026, manufacturers have reporting duties for actively exploited vulnerabilities and severe incidents affecting products with digital elements. This is a technical-readiness briefing, not legal advice.

11 SEP 2026

Reporting obligations apply

The Commission states manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements.

24 / 72 HOURS

Operational response matters

Official guidance describes an early-warning requirement within 24 hours and a full notification within 72 hours of awareness.

11 DEC 2027

Full application later

The Commission's implementation timeline states the CRA's full application is scheduled for 11 December 2027.

Blockchain product teams should map the boundary.

Where a blockchain product includes software, wallets, nodes, gateways, APIs, embedded components or other products with digital elements, teams should determine whether and how CRA obligations may apply with qualified legal/security support.

Need product-security evidence architecture?

We can help structure technical evidence, incident workflows and architecture documentation alongside your legal/compliance specialists.

Discuss readiness →
Get proposalBuy / license