Skip to main content

CRA Article 14 reporting obligations approaching

Regulation (EU) 2024/2847

Cyber Resilience Act (CRA) EU Product Cybersecurity Regulation

The Cyber Resilience Act is the EU horizontal cybersecurity framework for products with digital elements. It entered into force on 10 December 2024. Article 14 reporting obligations apply starting 11 September 2026, and full product conformity requirements apply from 11 December 2027.

September 11, 2026 — Article 14 Obligations

GÜN
——SAAT
——DK
——SN

Main Requirements

11.12.2027

Max Penalty (Art. 35)

€15M / 2.5%

RED Standard

EN 18031:2024

Authority

ENISA / CSIRT

EN 18031 vs CRA Harmonised Standards:

EN 18031:2024 currently supports Radio Equipment Directive (RED) Article 3.3 requirements. Harmonised standards specifically for CRA are under active development by CEN-CENELEC.

This content is provided for general information and does not constitute legal advice, a conformity decision or certification.

Last reviewed: 5 August 2026

Direct Summary & Key Answers

Essential Facts for Hardware & IoT Manufacturers

When does CRA take effect?

CRA entered into force on 10 Dec 2024. Article 14 mandatory incident reporting begins on 11 Sept 2026. The full product compliance and CE marking regime applies starting 11 Dec 2027.

What are Article 35 penalties?

Non-compliance with essential cybersecurity requirements (Annex I) or reporting obligations results in fines up to €15,000,000 or 2.5% of annual worldwide turnover, plus market recalls.

How TegmenSoft streamines compliance?

TegmenSoft unifies automated CycloneDX/SPDX SBOM generation, OSV vulnerability correlation, ENISA Single Reporting Platform (SRP) drafts (<24h), and secure Ed25519 OTA firmware updates.

Article 35 Enforcement

CRA Administrative Fines & Market Sanctions Breakdown

Max: €15.000.000 / 2.5%
Violation CategoryCRA ReferenceMaximum Financial PenaltyMarket Consequences
Essential Cybersecurity Breach (Design, Vulnerability Handling, Article 14 Notification)Article 35(1), Annex IUp to €15,000,000 or 2.5% of worldwide annual turnoverProhibition of sale, mandatory withdrawal or recall from the EU market
Breach of Other Manufacturer / Economic Operator ObligationsArticle 35(2), Chapter IIUp to €10,000,000 or 2.0% of worldwide annual turnoverCorrective action orders within strict time limits
Misleading or Inaccurate Information to Notified BodiesArticle 35(3)Up to €5,000,000 or 1.0% of worldwide annual turnoverRevocation of EU-Type Examination Certificate

Article 14

Three-tier mandatory reporting cycle

Active exploitation detection triggers a three-phase notification process starting with a 24-hour early warning to the CSIRT and ENISA Single Reporting Platform.

Phase 01T+0

In-the-Wild Exploitation Discovered

Active exploitation of a vulnerability or a severe security incident is identified in the connected product fleet.

Phase 02T+≤ 24h

Early Warning Notification

An early warning containing initial details and affected market scope is submitted for human review and CSIRT / ENISA notification.

Phase 03T+≤ 72h

Detailed Notification

A comprehensive notification covering incident scope, technical severity, and initial mitigation steps is submitted.

Phase 04T+≤ 14d

Final Incident Report

After remediation updates are made available, a final report detailing vulnerability fixes, CVSS scoring, and update availability is provided.

Obligations

Core manufacturer obligations under CRA

The CRA requires structured processes across product design, software component inventory, free security updates, and technical record keeping.

Secure by Design

Products with digital elements must meet essential cybersecurity requirements throughout design, development, and maintenance.

CE Conformity Assessment

CRA-scoped products must undergo appropriate conformity assessment routes before bearing the CE mark for the EU market.

Software Bill of Materials (SBOM)

Manufacturers must document open-source and commercial dependencies in machine-readable format (CycloneDX / SPDX).

Declared Support Period

Manufacturers must declare a realistic support period and provide free security updates during that timeframe.

Market Surveillance & Penalties

Member state market surveillance authorities have enforcement powers including administrative fines and product withdrawals.

Regulatory Timeline

CRA Regulatory Milestones

Official enforcement dates for the EU Cyber Resilience Act.

10 Dec 2024

CRA Entry into Force

Regulation (EU) 2024/2847 published in the EU Official Journal and entered into force.

11 June 2026

Notified Bodies Framework

Notification provisions for conformity assessment bodies become applicable.

11 Sept 2026

Article 14 Reporting Mandate

Mandatory 24h early-warning reporting to ENISA and CSIRTs for actively exploited vulnerabilities begins.

11 Dec 2027

Main Product Conformity Regime

The main CRA product requirements and conformity assessment regime become fully applicable.

Critical Milestone: 11.09.2026 Mandatory reporting of actively exploited vulnerabilities begins on 11 September 2026.

Product Classification

CRA Risk Categories & Conformity Routes

Products with digital elements are categorized by function, determining their required conformity assessment pathway.

Default Products

Category 1 (Low Risk)

Typical Examples

Smart home toys, digital cameras, basic connected consumer devices

Conformity Assessment Pathway

Module A (Internal Production Control — Self-Assessment)

Important Class I

Category 2 (Medium Risk)

Typical Examples

Identity management systems, password managers, network interfaces, MCU microcode

Conformity Assessment Pathway

Self-assessment if harmonised standards apply, or Notified Body review

Important Class II

Category 3 (High Risk)

Typical Examples

Firewalls, routers, hardware security modules (HSM)

Conformity Assessment Pathway

Mandatory third-party examination by a Notified Body

Critical Products

Category 4 (Critical Infrastructure)

Typical Examples

Smart cards, specialized hardware and OS used in critical infrastructure

Conformity Assessment Pathway

European Cybersecurity Certification Scheme (EUCC) per delegated acts

Let's review your product architecture and CRA readiness.

Schedule a 30-minute technical review call with our engineering team to assess your component visibility, update workflows, and compliance timelines.

Book a Technical Call
EU Cyber Resilience Act (CRA) Guide: Timeline, Article 14 & Fines | TegmenSoft · TegmenSoft