Skip to content
Back to Blog
Smart Factory
2026-10-057 min read0

EU Cyber Resilience Act Reporting Duties Began September 11, 2026 — A Vulnerability-Response Playbook for SME Exporters of Industrial IoT, Controllers, and Equipment Software

The EU Cyber Resilience Act's reporting obligations began on September 11, 2026, requiring 24-hour and 72-hour reporting of exploited vulnerabilities and severe incidents even for industrial IoT, controllers, and equipment software already on the EU market. This guide covers scope, reporting steps, a roadmap to full application in December 2027, and support programs SMEs can use.

KITIM Consulting Team

The First CRA Obligation Took Effect on September 11

The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) applies in stages. Manufacturers' reporting obligations (Article 14) began on September 11, 2026, while the remaining duties — essential cybersecurity requirements, conformity assessment, and CE marking — apply in full from December 11, 2027.

Two points deserve attention. First, the reporting obligations also cover products already placed on the EU market before December 11, 2027, so this is not only about new products. Second, every "product with digital elements" supplied to the EU is in scope, wherever the manufacturer is located. NIS2 places duties on the companies that operate equipment; the CRA places them on the manufacturers that build the equipment and its software.

Is Your Product in Scope — Industrial IoT, PLCs, HMIs, Gateways, and Embedded Software

A product with digital elements is hardware or software whose intended use involves a direct or indirect data connection to a device or network. The items most often overlooked are:

  • Firmware and control software embedded in equipment
  • Remote maintenance modules and the cloud services a product needs to function (remote data processing)
  • Monitoring or MES-integration software sold on its own
  • Products listed in Annex III (important) and Annex IV (critical) face stricter procedures, including third-party assessment. The final annexes list items such as routers and switches, operating systems, firewalls, and microcontrollers with security-related functions. Industrial automation and control systems, unlike in the legislative draft, do not appear as a separate entry as far as we can determine. Classification depends on a product's core functionality, however, so you should confirm it against the annex text itself.

    In OEM/ODM supply, the company that places the product on the EU market under its own brand is the legal manufacturer. Because only the actual developer can provide vulnerability information and patches, buyers are likely to impose response deadlines by contract.

    What to Report, by When, and to Whom

    Two things must be reported: actively exploited vulnerabilities and severe incidents affecting the security of the product.

  • Within 24 hours: early warning after becoming aware
  • Within 72 hours: detailed notification
  • Final report: for exploited vulnerabilities, within 14 days after a corrective or mitigating measure becomes available; for severe incidents, within one month of the 72-hour notification
  • Reports go simultaneously to the competent CSIRT and ENISA through the single reporting platform operated by ENISA. For non-EU manufacturers, the competent Member State is determined by where the EU authorised representative is established (or, failing that, the importer and so on). Affected users must also be informed of the issue and of any mitigating measures.

    Breaches of the reporting obligations fall into the fine bracket of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Micro and small enterprises are exempt from fines only for missing the 24-hour early warning deadline.

    Four Things You Need Before You Can Report in 24 Hours

  • SBOM: Without a per-product list of open-source and third-party components, you cannot even become "aware" of a vulnerability.
  • Vulnerability intake channel and CVD policy: Publish a contact point for external reports and the principles for handling them.
  • Triage and reporting procedure: Document PSIRT roles, night and holiday contact chains, and the line to your EU representative or importer.
  • Shipment history and patch delivery path: Track which version went to which customer and how patches will reach them.
  • A 14-Month Roadmap to Full Application in December 2027

    At full application, manufacturers must provide secure-by-design development, secure default configuration, security updates throughout the support period (in principle at least five years), and technical documentation. Most products can follow self-declaration of conformity, but Class I important products need third-party assessment unless harmonised standards are applied, while Class II important products and critical products need third-party assessment (or EU certification) regardless — so the standardisation timeline is worth tracking.

  • Q4 2026: Identify in-scope products and clarify manufacturer and importer roles
  • Q1 2027: Put SBOM and vulnerability management into operation, and integrate with the risk assessment under the EU Machinery Regulation, which applies from January 20, 2027
  • Q2–Q3 2027: Close design gaps and build the security update mechanism
  • Q4 2027: Technical documentation, conformity assessment, and CE marking
  • For equipment with AI functions, it is more efficient to review AI Act requirements at the same time and design the technical file once.

    Support Programs for SMEs and How KITIM Can Help

    Testing and certification costs can be partly covered through programs such as the Export Voucher and the Overseas Standard Certification Acquisition Support Program. Coverage and ceilings change every year, so checking the latest call for applications is a prerequisite. If you already hold ISO/IEC 27001 or IEC 62443 certification, its procedures and risk assessment framework can serve as the backbone of your CRA response. Security update functions and SBOM automation can also be framed as development scope in R&D projects or smart manufacturing supplier support programs.

    KITIM helps you plan overseas certification, R&D project design, and export regulation response together. If you need support ranging from a CRA scope assessment to matching with government programs, please reach out through the KITIM consulting inquiry page.

    Cyber Resilience ActCRAVulnerability ReportingIndustrial IoTProducts with Digital ElementsSBOMCE MarkingMachinery Export
    매일 자동 업데이트

    이 분야 정부지원사업, AI가 찾아드립니다

    3분 기업진단만 완료하면 귀사에 맞는 공고를 적합도 점수와 함께 추천합니다. 무료입니다.

    AI 맞춤 공고 무료로 받기

    Need Consulting?

    Our technology innovation consultants will propose the optimal solution for your company.