Skip to main content Skip to search Skip to main navigation
Menu
Important Standards & legislation Score: 8/10

Cyber Resilience Act: New Reporting Obligations for Manufacturers Since September 2026

Since September 11, 2026, manufacturers of digital products must report vulnerabilities and security incidents via the CRA-SRP. An overview for the security industry.

What Happened?

Since September 11, 2026, the reporting obligations of the Cyber Resilience Act (CRA) have been in force across the European Union. Manufacturers of products with digital elements are now required to promptly report actively exploited vulnerabilities as well as severe security incidents affecting product safety. This new regulation is regarded as a key milestone in strengthening product security within the EU single market. The German Federal Office for Information Security (BSI) is supporting affected companies with step-by-step guidance for practical implementation.

The Details

Reports are submitted EU-wide via a standardized channel: the Single Reporting Platform, known as CRA-SRP, developed by the European Union Agency for Cybersecurity (ENISA). Recipients of the information are the respective competent coordinating Computer Security Incident Response Team (CSIRT) of the affected member state, as well as ENISA itself. For federal companies in Germany, CERT-Bund within the BSI acts as the coordinating CSIRT.

For manufacturers with their main establishment within the EU, responsibility is determined by the member state in which key decisions regarding the cybersecurity of the products are made. For companies without a main establishment in the EU, the criteria under Article 14(7) of the CRA apply. Decisive factors here include, among others, the location of an authorized representative, importer, or distributor, as well as the availability of the product in the respective markets.

Manufacturers may become aware of exploited vulnerabilities, for example, through IT security service providers or customer feedback. Severe security incidents can also be identified through external reports as well as internal analysis of application and system log data. The CRA-SRP serves as a central and confidential interface: a single report is sufficient to simultaneously inform the relevant teams in all EU member states where the respective product is distributed, via the competent CSIRT. Prior registration on the platform is not required, and reports can be submitted within a few minutes. The infrastructure is operated in compliance with current security standards in Europe.

Assessment

This development is of immediate relevance to the security industry, as modern security technology increasingly incorporates digital components – ranging from networked alarm systems and IP-based video surveillance systems to digital access control systems. Manufacturers of products such as electronically monitored deposit safes, digitally networked offertory boxes in churches, or modern Wardhub access control systems also fall under the new definition of "products with digital elements" and must comply with the CRA reporting obligations, provided their products contain digital elements.

The introduction of a uniform, centralized reporting channel via the CRA-SRP significantly increases transparency regarding digital security risks throughout the EU single market. Instead of separate, inconsistent national reporting procedures, a coordinated system emerges that informs authorities across the EU simultaneously, thereby improving responsiveness to security-relevant incidents.

Practical Tips

  • Manufacturers of digital security technology should check early on whether their products fall under the CRA reporting obligations and which jurisdiction applies to them.
  • Companies without a main establishment in the EU should carefully review the criteria under Article 14(7) of the CRA in order to correctly identify the competent reporting authority.
  • Internal processes for analyzing application and system log data, as well as for handling customer feedback and reports from IT security service providers, should be established or reviewed to ensure timely detection of vulnerabilities.
  • Since no prior registration on the CRA-SRP is required, it is advisable to become familiar with the reporting process early on in order to be able to act quickly in an emergency.
  • The step-by-step guidance provided by the BSI, as well as the information resources offered by ENISA, provide a practical basis for implementing the new requirements.

Outlook

With the launch of the CRA reporting obligations, an important building block of the European cybersecurity strategy is being implemented. Further details on using the platform and the formal procedures are provided by the BSI and ENISA on their respective websites. For manufacturers of security technology with digital components, the consistent implementation of these reporting obligations is likely to become a permanent part of the product lifecycle in the future – comparable to existing certification and compliance requirements in the industry.