On 11 September 2026, the reporting duties in Article 14 of the EU's Cyber Resilience Act became applicable. Subject to the Act's exemptions, any manufacturer of a product with digital elements made available in the EU, wherever the manufacturer is based, now has to tell the authorities when it learns that a vulnerability in one of its products is being actively exploited.

The same day, the EU cybersecurity agency ENISA switched on the Single Reporting Platform those reports must go through. ENISA describes what launched as the platform's "initial operating capability", and says its functions will be improved and expanded over the coming months.

Most of the Act does not apply until 11 December 2027. The reporting clock started fifteen months early, and one clause gives it a reach the rest of the law does not have.

The clock

The Act defines an actively exploited vulnerability as one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. From the moment a manufacturer becomes aware of one, it owes three things.

DeadlineWhat is due
24 hoursAn early warning, naming where known the Member States in which the product has been made available
72 hoursA vulnerability notification: general information on the product, the nature of the exploit and the flaw, corrective measures taken, mitigations users can apply, and how sensitive the manufacturer considers the information
14 days after a fix or mitigation is availableA final report: a description with severity and impact, any information about the attacker, and details of the security update

Severe incidents affecting a product's security run on the same 24-hour and 72-hour clock, with the final report due one month after the incident notification.

Manufacturers also have to inform affected users, and where appropriate all users, along with the mitigations they can take. If a manufacturer does not do so in time, the national coordinating team may tell users itself.

The clause that reaches backwards

Two transitional provisions sit side by side in Article 69.

The first says that products placed on the market before 11 December 2027 are subject to the Act's requirements only if they are substantially modified after that date. A device sold in 2022 and never significantly changed never has to meet the Act's security-by-design and vulnerability-handling requirements.

The second, by way of derogation, says that Article 14 applies to all in-scope products placed on the market before 11 December 2027.

Put together: a router sold years ago, still running on someone's network, now carries a 24-hour duty to report its exploitation. The Act imposes no matching duty to fix it. And because the final report is timed from the moment a corrective or mitigating measure becomes available, for a product that never gets one the text sets no deadline for that report at all.

That is not necessarily a flaw. Reporting is what gives national teams and ENISA visibility of exploitation across everything already deployed, including devices long out of sale. But it means the first obligation the Act places on manufacturers includes problems in products that its security requirements will never reach.

Where a report goes

Notifications are filed through the platform to the national computer security incident response team designated as coordinator in the Member State where the manufacturer has its main establishment, defined as where decisions about its products' cybersecurity are predominantly taken, and are simultaneously accessible to ENISA.

Manufacturers without an EU establishment follow a cascade: the Member State of the authorised representative acting for most of their products, then that of the importer placing most of them on the market, then that of the largest distributor, and finally the Member State with the most users.

The receiving team then passes the notification to its counterparts in every Member State where the product is sold. It can delay that on justified cybersecurity grounds, including while a coordinated disclosure is under way. In what the Act calls particularly exceptional circumstances, such as exploitation confined to a single Member State or information touching that state's essential interests, ENISA initially receives only the headline details.

To make the timescale concrete: MikroTik, whose RouterOS chain we covered last week, is based in Latvia. Confirmation of exploitation of the kind CERT Polska published would now start a manufacturer's 24-hour clock from the moment it became aware.

Fines, and who is spared

Breaching Article 14 falls in the Act's top penalty tier: fines of up to 15 million euros or 2.5 per cent of worldwide annual turnover, whichever is higher.

Two groups get relief. Microenterprises and small enterprises cannot be fined for missing the 24-hour early-warning deadlines, though the relief does not extend to the 72-hour notification. Open-source software stewards cannot be fined for any infringement of the Act.

The Act also says that the mere act of notifying does not expose a manufacturer to increased liability, a clause aimed squarely at the instinct to say nothing.

A platform switched on the same day

The platform went live on the day reporting became mandatory. The Act anticipates teething problems: it requires the European Commission to report on the platform's effectiveness, and on how coordinators use their power to delay passing notifications on, by 11 September 2028.

Once a fix is available, ENISA is to add notified vulnerabilities to the European vulnerability database, in agreement with the manufacturer. It must also produce a report on emerging trends every two years, the first within 24 months of the reporting duties starting.

What is not established

  • How becoming aware will be read in practice: whether a researcher's blog post, a customer complaint or a listing in another country's catalogue of exploited flaws starts the clock.
  • How often coordinating teams will delay passing notifications on, and on what grounds.
  • How the small-enterprise relief applies. It is written as a derogation from paragraphs 3 to 9 of Article 64, while the fines for breaching Article 14 are set out in paragraph 2.
  • Whether any notifications have been filed since 11 September. ENISA has not said.
  • How authorities will reach manufacturers of long-discontinued products, or whether market surveillance will pursue them.