In-the-Wild Exploitation Discovered
Active exploitation of a vulnerability or a severe security incident is identified in the connected product fleet.
⚡ CRA Article 14 reporting obligations approaching · Details →
The Cyber Resilience Act is the EU horizontal cybersecurity framework for products with digital elements. It entered into force on 10 December 2024. Article 14 reporting obligations apply starting 11 September 2026, and full product conformity requirements apply from 11 December 2027.
September 11, 2026 — Article 14 Obligations
Main Requirements
11.12.2027
Max Penalty (Art. 35)
€15M / 2.5%
RED Standard
EN 18031:2024
Authority
ENISA / CSIRT
EN 18031 vs CRA Harmonised Standards:
EN 18031:2024 currently supports Radio Equipment Directive (RED) Article 3.3 requirements. Harmonised standards specifically for CRA are under active development by CEN-CENELEC.
This content is provided for general information and does not constitute legal advice, a conformity decision or certification.
Last reviewed: 5 August 2026
CRA entered into force on 10 Dec 2024. Article 14 mandatory incident reporting begins on 11 Sept 2026. The full product compliance and CE marking regime applies starting 11 Dec 2027.
Non-compliance with essential cybersecurity requirements (Annex I) or reporting obligations results in fines up to €15,000,000 or 2.5% of annual worldwide turnover, plus market recalls.
TegmenSoft unifies automated CycloneDX/SPDX SBOM generation, OSV vulnerability correlation, ENISA Single Reporting Platform (SRP) drafts (<24h), and secure Ed25519 OTA firmware updates.
| Violation Category | CRA Reference | Maximum Financial Penalty | Market Consequences |
|---|---|---|---|
| Essential Cybersecurity Breach (Design, Vulnerability Handling, Article 14 Notification) | Article 35(1), Annex I | Up to €15,000,000 or 2.5% of worldwide annual turnover | Prohibition of sale, mandatory withdrawal or recall from the EU market |
| Breach of Other Manufacturer / Economic Operator Obligations | Article 35(2), Chapter II | Up to €10,000,000 or 2.0% of worldwide annual turnover | Corrective action orders within strict time limits |
| Misleading or Inaccurate Information to Notified Bodies | Article 35(3) | Up to €5,000,000 or 1.0% of worldwide annual turnover | Revocation of EU-Type Examination Certificate |
Article 14
Active exploitation detection triggers a three-phase notification process starting with a 24-hour early warning to the CSIRT and ENISA Single Reporting Platform.
Active exploitation of a vulnerability or a severe security incident is identified in the connected product fleet.
An early warning containing initial details and affected market scope is submitted for human review and CSIRT / ENISA notification.
A comprehensive notification covering incident scope, technical severity, and initial mitigation steps is submitted.
After remediation updates are made available, a final report detailing vulnerability fixes, CVSS scoring, and update availability is provided.
Obligations
The CRA requires structured processes across product design, software component inventory, free security updates, and technical record keeping.
Products with digital elements must meet essential cybersecurity requirements throughout design, development, and maintenance.
CRA-scoped products must undergo appropriate conformity assessment routes before bearing the CE mark for the EU market.
Manufacturers must document open-source and commercial dependencies in machine-readable format (CycloneDX / SPDX).
Manufacturers must declare a realistic support period and provide free security updates during that timeframe.
Member state market surveillance authorities have enforcement powers including administrative fines and product withdrawals.
Regulatory Timeline
Official enforcement dates for the EU Cyber Resilience Act.
10 Dec 2024
Regulation (EU) 2024/2847 published in the EU Official Journal and entered into force.
11 June 2026
Notification provisions for conformity assessment bodies become applicable.
11 Sept 2026
Mandatory 24h early-warning reporting to ENISA and CSIRTs for actively exploited vulnerabilities begins.
11 Dec 2027
The main CRA product requirements and conformity assessment regime become fully applicable.
Critical Milestone: 11.09.2026 Mandatory reporting of actively exploited vulnerabilities begins on 11 September 2026.
Product Classification
Products with digital elements are categorized by function, determining their required conformity assessment pathway.
Typical Examples
Smart home toys, digital cameras, basic connected consumer devices
Conformity Assessment Pathway
Module A (Internal Production Control — Self-Assessment)
Typical Examples
Identity management systems, password managers, network interfaces, MCU microcode
Conformity Assessment Pathway
Self-assessment if harmonised standards apply, or Notified Body review
Typical Examples
Firewalls, routers, hardware security modules (HSM)
Conformity Assessment Pathway
Mandatory third-party examination by a Notified Body
Typical Examples
Smart cards, specialized hardware and OS used in critical infrastructure
Conformity Assessment Pathway
European Cybersecurity Certification Scheme (EUCC) per delegated acts
Schedule a 30-minute technical review call with our engineering team to assess your component visibility, update workflows, and compliance timelines.
Book a Technical Call