Skip to content
News · Europa · Law & safety

Cyber Resilience Act Reporting Is Live: 24 Hours for Early Warning

11.09.2026 · Redakcja RoboMorrow
Verified: 11 September 2026. Article 14 reporting duties under the EU Cyber Resilience Act now apply. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the CRA Single Reporting Platform.

The Cyber Resilience Act has entered its first stage that directly changes the day-to-day work of companies selling connected hardware and software in the European Union. From 11 September 2026, Article 14 reporting obligations under Regulation (EU) 2024/2847 apply. This is not yet the full application of all CRA requirements, which arrives on 11 December 2027, but certain cybersecurity events now trigger legally defined deadlines measured in hours.

24 hours for an early warning, 72 hours for the main notification

When a manufacturer becomes aware of an actively exploited vulnerability in its product with digital elements or a severe incident affecting the security of that product, it must submit an early warning without undue delay and no later than 24 hours after becoming aware. A fuller notification, including broader information and an initial assessment, follows within 72 hours.

The final deadline depends on the event. For an actively exploited vulnerability, a final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month of the 72-hour notification. The European Commission and ENISA set out these timelines in their current CRA implementation material.

Not every vulnerability triggers the 24-hour clock

This distinction is important for robotics manufacturers. The CRA does not say that every newly discovered vulnerability automatically requires a 24-hour notification. For the vulnerability route, the trigger is active exploitation: reliable evidence that a malicious actor has exploited the vulnerability in a system without the system owner's permission. Severe incidents affecting the security of a product are a separate reportable category.

In practice, a manufacturer therefore needs more than a security contact mailbox. It needs a decision process: when evidence becomes credible, who classifies the event, how product telemetry is collected, who brings in legal and product teams, and who is authorised to submit the notification. With a 24-hour deadline, designing the process after an incident occurs may be too late.

One submission through ENISA's platform

Reporting is handled through the CRA Single Reporting Platform, established and maintained by ENISA. The platform is intended to avoid forcing a manufacturer to send the same notification separately to multiple national authorities. The notification is addressed to the relevant CSIRT in the Member State of the manufacturer's main establishment and is then shared according to the dissemination mechanism defined by the CRA.

ENISA confirms that the platform is available from 11 September 2026. At launch, it supports mandatory manufacturer reports for actively exploited vulnerabilities and severe incidents. ENISA's coordinator list also identifies CERT Polska as the designated CRA CSIRT coordinator for Poland.

Why robotics companies should care

The CRA covers products with digital elements when they are made available on the EU market and their intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Many modern robots fit that broad description: robot vacuums, robotic mowers, mobile cameras, service robots, AMRs and Physical AI systems often rely on Wi-Fi, cloud services, apps, over-the-air updates and remote diagnostics.

That does not mean every robot is regulated in exactly the same way. The CRA has a defined scope and exclusions, particularly where products are already covered by specific Union sector legislation. Manufacturers need to assess the actual product and how it is placed on the market. On 27 July 2026, the Commission published additional guidance addressing scope, substantial modification, support periods, reporting and cybersecurity risk assessment.

Older products can still fall under the reporting duty

A particularly important point is that Article 14 reporting is not limited to devices placed on the market after 11 September. The Commission explains that reporting obligations cover products with digital elements made available on the Union market, including products placed on the market before the CRA's full application date of 11 December 2027. If a manufacturer becomes aware after 11 September 2026 that such a product has an actively exploited vulnerability, the reporting duty can apply.

ENISA also clarifies that manufacturers do not have to retrospectively report active exploitation that they already knew about before Article 14 became applicable. The date of awareness therefore matters, which makes internal evidence and incident records important.

What this changes operationally for a robot manufacturer

The clearest change is the need to connect product, cybersecurity, service and legal teams. A robot's weakness may sit in its main firmware, companion app, open-source library, communications module, cloud backend or a component supplied by a partner. Companies need component visibility, a vulnerability intake mechanism, triage procedures and a way to identify affected versions and markets quickly.

For distributors and importers bringing robotics products from Asia into Europe, the rule also increases pressure on vendor support quality. A European sales channel cannot compensate for a manufacturer that lacks vulnerability-management processes, cannot ship security updates quickly or has no clear ownership for incident response.

This is the first major date, not the last

Article 14 reporting applies from 11 September 2026. The CRA becomes fully applicable on 11 December 2027, bringing much broader requirements around secure design, vulnerability handling, documentation, conformity assessment and user information. Today's deadline is therefore the practical start of one enforcement layer rather than the end of CRA implementation.

What it means for Poland and the EU

For European robotics, this is a meaningful shift. Cybersecurity for connected devices is no longer only a product feature or enterprise procurement checkbox. Manufacturers need a mechanism to detect, classify and report certain events under short deadlines. For business customers, incident-response maturity may become an additional vendor-selection criterion alongside price, uptime and service coverage.

For Polish companies, the practical conclusion is straightforward: if they manufacture or place under their own name a connected robot or software product that falls within the CRA scope, they need an Article 14 reporting process now, not in 2027. The first months of real use by ENISA, national CSIRTs and manufacturers will show how the system performs during actual incidents.

RoboMorrow verdict

PUBLISH. This is not another regulatory announcement. Article 14 applies from 11 September 2026. The strongest RoboMorrow angle is a practical robotics-industry guide: when the 24-hour clock starts, how an actively exploited vulnerability differs from an ordinary vulnerability, and why robot manufacturers need a working incident-response process today.