The European Commission has published its first practical guidance on the Cyber Resilience Act about six weeks before manufacturers must begin reporting actively exploited vulnerabilities and severe incidents affecting the security of covered products.
The nonbinding guidance uses 67 examples, use cases and flowcharts to clarify scope, remote data processing, open-source software, substantial modifications, support periods, risk assessments and reporting. Most of the act will apply from Dec. 11, 2027, but its Article 14 reporting duties start Sept. 11, 2026.
Strict timelines for early warnings and final reports
A manufacturer becoming aware of a qualifying vulnerability or incident must submit an early warning “without undue delay and in any event within 24 hours.” A fuller notification is due within 72 hours. Final reports must follow within 14 days after a corrective or mitigating measure becomes available for a vulnerability or within one month of the 72-hour incident notification.
Market reach and exemptions for small enterprises
The duties apply to products with digital elements already made available on the EU market, including products placed there before the wider requirements take effect. For an otherwise in-scope product, the reporting duty turns on whether it has been made available on the EU market, not where its manufacturer is headquartered.
For a manufacturer outside the EU, ENISA points to the establishment of its authorized representative when identifying the national computer security incident response team coordinating the report.
Microenterprises and small enterprises remain subject to reporting, although the regulation excludes administrative fines for failures to meet the 24-hour early-warning deadline. The fine exception is limited to the initial deadline.
Platform operations and manual reporting workflows
ENISA says the Single Reporting Platform will be operational by Sept. 11 and expects a testing period beforehand. Its public address has not yet been published. People submitting reports on behalf of manufacturers and open-source software stewards will use an EU Login account. The CSIRT designated as coordinator will validate each representative in parallel with the reporting process.
Organizations may automate internal reporting workflows, but ENISA states that “no Application Programming Interfaces will be provided at this stage.” Its early-warning fields include the manufacturer, product and notification type.
At 72 hours, the template calls for general information about the vulnerability or incident and mitigation details, while incident reports also require an initial assessment. Severity, impact and corrective-action details are added to the final report.
Product scope and long-term obligations
The act applies to in-scope hardware and software products made available on the EU market, subject to specified exclusions. A product with digital elements also includes remote data processing designed by the manufacturer, or under its responsibility, when the product cannot perform one of its functions without the remote component.
The guidance also addresses longer-term product obligations. Manufacturers must determine and disclose support periods, while products placed on the market before Dec. 11, 2027 generally face the wider requirements only if they undergo a substantial modification after that date. Reporting arrives earlier and applies to covered products already on the market.
Upcoming standards and pending details
The Commission lists the first horizontal and product-specific standardization deliverables for the third quarter of 2026. The guidance remains nonbinding, while ENISA must still publish the reporting platform’s address and bring the system online before the first mandatory notifications are due.