Compliance
Compliance Essentials: Navigating CRA Reporting Obligations from 11 September 2026
Manufacturers of products with ‘digital elements’ must prepare for new reporting timelines under the EU’s Cyber Resilience Act beginning 11 September 2026—know what incidents to report, when, and how.
By NomadicTax Research Team • 5-8 min read • September 2, 2026
## What Is the Cyber Resilience Act (CRA)?
The CRA is the EU regulation aimed at ensuring products with digital elements meet cybersecurity requirements. Reporting obligations under the CRA require manufacturers and importers to notify authorities about **actively exploited vulnerabilities** and **severe incidents**. It establishes deadlines and a single reporting platform for compliance.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai))
## Key Reporting Requirements & Deadlines
| Obligation | Timeline from Awareness | Applicable Scenario |
|---|---|---|
| **Early warning on actively exploited vulnerabilities** | Within **24 hours** of awareness | Security weakness that attackers are using and causing harm but no fix yet.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai)) |
| **Full notification** | Within **72 hours** | Provides fuller incident details, including scope and affected parties.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai)) |
| **Final report** | **14 days** after corrective measure available (for vulnerabilities); **30 days** for severe incidents.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai)) |
All reports are submitted through the CRA Single Reporting Platform (SRP) and addressed to the relevant **CSIRT** where the product’s main establishment is located. If exceptional circumstances apply, providers can involve ENISA.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai))
## Who Is Affected?
- Manufacturers of any product with digital elements, whether hardware or software, that enters the EU market.
- Importers are responsible until the product is placed on the Internal Market.
- Even if the company is based outside the EU, products sold within the EU generally fall under the jurisdiction of these rules.
## Practical Steps for Ensuring Compliance
- **Create internal incident response protocols**: Set up processes to detect, assess, and document vulnerabilities or incidents so that reports can be submitted within deadlines.
- **Map product supply chains**: Determine where manufacturing, software development, updates, and imports occur to establish jurisdiction and responsibility.
- **Train staff and raise awareness**: Ensure that legal, technical, and cybersecurity teams understand the obligations and deadlines.
- **Designate responsible persons**: Assign team members for report filing, liaising with CSIRTs, and maintaining records in case of audit.
## Intersection with Tax and Customs
- Notification obligations may require coordination between compliance and tax/legal teams, particularly where regulatory provisions impact liability or product classification.
- While CRA focuses on cybersecurity, companies should watch for overlapping rules under customs or import/export regimes, especially for products entering the EU.
## Timeline & Status
The CRA’s reporting requirements and SRP become **operational on 11 September 2026**. All affected manufacturers should be ready by then.([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?utm_source=openai))
Failure to meet the deadlines may result in regulatory penalties. These rules are binding for all Member States once enacted. Stay updated with both EU‐level guidance and local implementing authorities.