Cyber Resilience Act – the 24-hour reporting duty that started 11 September 2026
Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities within 24 hours. See what the CRA means for you – both as a manufacturer and as a buyer of smart locks and IoT equipment.
On 11 September 2026, the first hard obligation under the Cyber Resilience Act (CRA) took effect. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents — and they have 24 hours for the first step.
It is a regulation that has slipped past many organisations, because the bulk of its requirements only apply from December 2027. But the reporting duty applies now.
The timeline
Dec 2024 ── CRA enters into force
│
Sep 2026 ── ★ Reporting obligations (Art. 14) apply
│ Actively exploited vulnerabilities + severe incidents
│ CRA Single Reporting Platform goes live
│
Dec 2027 ── Remaining obligations apply
Security requirements, vulnerability handling, patching,
CE marking, technical documentation
Who is covered?
The CRA applies to manufacturers of products with digital elements — in practice, almost anything that connects to a network or to another device.
In the access control world that means:
Smart locks
Electronic cylinders, handles and padlocks with wireless communication
Gateways and bridges
Network modules, relays and devices connecting locks to the cloud
Sensors
Door sensors, alarm sensors and other IoT monitoring
Software
Apps, firmware and the software that drives the devices
If you manufacture or resell such products under your own name, you may be a manufacturer for the purposes of the regulation. If you buy them, you are not directly obliged — but it still matters to you. More on that below.
The deadlines: 24 hours, 72 hours, 14 days
Manufacturers report in three stages:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours after becoming aware | First notice of the actively exploited vulnerability or severe incident |
| Notification | 72 hours | Full notification with what is known at that point |
| Final report | 14 days after a corrective measure is available (vulnerabilities) |
Closing account. For incidents: one month from the 72-hour notification |
Reporting goes through the CRA Single Reporting Platform (SRP), operational since 11 September 2026. The notification reaches the CSIRT of the member state where the manufacturer has its main establishment, and is shared simultaneously with ENISA.
The problem: you cannot report what you cannot see
The 24-hour deadline is not really a legal challenge. It is a technical and organisational one.
To meet it, a manufacturer has to be able to:
- Detect that a vulnerability is in fact being actively exploited
- Assess whether it is severe enough to trigger the duty
- Escalate internally to someone with authority to file
- File — within a single day, including across a weekend
Step 1 is the hard one. A manufacturer without an SBOM, without a channel for external vulnerability disclosure, and without arrangements with component suppliers typically discovers the problem when a customer calls. By then the 24 hours are long gone.
What the CRA means for you as a buyer
Even if you only buy access control, the CRA changes your position in two ways.
1. Your supplier's reporting becomes your early warning. A manufacturer that complies with the CRA detects and discloses problems faster. One that does not, does not — and so neither do you.
2. NIS2 makes supplier management your responsibility. Supply chain security is an explicit NIS2 requirement. When supervision asks how you assess supplier risk, "we asked whether they were CRA-ready — here is the answer" is a better response than silence.
Questions for your supplier
Take these into your next tender or supplier review:
✅ Are your products in scope of the CRA, and when do you expect CE marking under it?
✅ Do you operate a public channel for receiving vulnerability reports?
✅ Can you provide an SBOM for the products we buy?
✅ How long will you ship security updates for this product — and what happens when support ends?
✅ How will you notify us if you report an actively exploited vulnerability affecting our installation?
✅ Which third-party components are included, and what is your plan when one reaches end-of-life?
The last point is worth dwelling on. A large share of vulnerabilities in IoT products originate in components the manufacturer did not write. When a component reaches end-of-life, the fixes stop arriving — but the product is still sitting in your door.
How it fits with NIS2 and CER
The three regimes interlock but land on different parties:
| Regime | Applies to | Concerns | Deadlines |
|---|---|---|---|
| CRA | The manufacturer | Product security | 24 h / 72 h / 14 days |
| NIS2 | The operator of the service | Cybersecurity in operation | 24 h / 72 h / 1 month |
| CER | Designated critical entities | Physical resilience | 24 h / 1 month |
If you are a utility using smart locks, one and the same vulnerability can trigger a CRA filing by your supplier and a NIS2 notification by you. They are not the same report, and they do not necessarily go to the same authority.
That is why it helps to have one place where the incident is recorded once and can then be worked against several regimes, each with its own countdown.
FAQ
When did the CRA reporting duty take effect?
11 September 2026. The remaining requirements – including security requirements, vulnerability handling and CE marking – apply from 11 December 2027.
What has to be reported?
Actively exploited vulnerabilities and severe incidents affecting the security of a product with digital elements. A vulnerability that is not being actively exploited does not trigger the Article 14 duty.
Are we covered if we only buy the equipment?
The reporting duty sits with the manufacturer. But if you resell a product under your own name or trademark, you may be a manufacturer under the regulation. And as a buyer you should still set requirements, because NIS2 makes supply chain security your responsibility.
Where are reports filed?
Through the CRA Single Reporting Platform, operational since 11 September 2026. The notification goes to the CSIRT of the member state where the manufacturer has its main establishment, and is shared with ENISA.
Contact us
Need to set the right requirements for your access control suppliers? Contact SnapKey.
Related articles
CER Directive – Complete Guide to Critical Infrastructure Compliance
Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.
The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running
The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.
Access Control for District Heating – Secure Access to Substations and Cabinets
Digital access control for district heating companies. Replace lockboxes with traceable access to heat substations, exchanger stations, and technical rooms.