This is an info Alert.
SnapKey Logo
  • Solutions
      • Solutions
      • SnapKey Residential
      • SnapKey Utility
      • SnapKey Public
      • SnapKey Logistics
      • SnapKey Sensors
      • Guest Check-in
      • Reactivatable Keys
      • Self-service Rentals
  • Industries
      • Industries
      • Utility companies
      • Residential buildings
      • Office buildings & Coworking spaces
      • Logistics
      • Holiday homes
      • Public restrooms
      • Construction sites
      • Unmanned stores
      • Temporary lockers
      • Virtual Keybox
  • Resources
      • Resources
      • Knowledge
      • Videos
      • API documentation
      • Trust & Security
      • System status
  • Partners
  • Company
      • Company
      • About us
      • Why SnapKey
      • Contact
auth.sign_inBook a demo

Cyber Resilience Act – the 24-hour reporting duty that started 11 September 2026

Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities within 24 hours. See what the CRA means for you – both as a manufacturer and as a buyer of smart locks and IoT equipment.
20. September 2026
6 min

On 11 September 2026, the first hard obligation under the Cyber Resilience Act (CRA) took effect. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents — and they have 24 hours for the first step.

It is a regulation that has slipped past many organisations, because the bulk of its requirements only apply from December 2027. But the reporting duty applies now.


The timeline

Dec 2024  ── CRA enters into force
              │
Sep 2026  ── ★ Reporting obligations (Art. 14) apply
              │   Actively exploited vulnerabilities + severe incidents
              │   CRA Single Reporting Platform goes live
              │
Dec 2027  ── Remaining obligations apply
                  Security requirements, vulnerability handling, patching,
                  CE marking, technical documentation

Who is covered?

The CRA applies to manufacturers of products with digital elements — in practice, almost anything that connects to a network or to another device.

In the access control world that means:

Smart locks

Electronic cylinders, handles and padlocks with wireless communication

Gateways and bridges

Network modules, relays and devices connecting locks to the cloud

Sensors

Door sensors, alarm sensors and other IoT monitoring

Software

Apps, firmware and the software that drives the devices

If you manufacture or resell such products under your own name, you may be a manufacturer for the purposes of the regulation. If you buy them, you are not directly obliged — but it still matters to you. More on that below.


The deadlines: 24 hours, 72 hours, 14 days

Manufacturers report in three stages:

Stage Deadline Content
Early warning 24 hours after becoming aware First notice of the actively exploited vulnerability or severe incident
Notification 72 hours Full notification with what is known at that point
Final report 14 days after a corrective measure is available
(vulnerabilities)
Closing account. For incidents: one month from the 72-hour notification

Reporting goes through the CRA Single Reporting Platform (SRP), operational since 11 September 2026. The notification reaches the CSIRT of the member state where the manufacturer has its main establishment, and is shared simultaneously with ENISA.


The problem: you cannot report what you cannot see

The 24-hour deadline is not really a legal challenge. It is a technical and organisational one.

To meet it, a manufacturer has to be able to:

  1. Detect that a vulnerability is in fact being actively exploited
  2. Assess whether it is severe enough to trigger the duty
  3. Escalate internally to someone with authority to file
  4. File — within a single day, including across a weekend

Step 1 is the hard one. A manufacturer without an SBOM, without a channel for external vulnerability disclosure, and without arrangements with component suppliers typically discovers the problem when a customer calls. By then the 24 hours are long gone.


What the CRA means for you as a buyer

Even if you only buy access control, the CRA changes your position in two ways.

1. Your supplier's reporting becomes your early warning. A manufacturer that complies with the CRA detects and discloses problems faster. One that does not, does not — and so neither do you.

2. NIS2 makes supplier management your responsibility. Supply chain security is an explicit NIS2 requirement. When supervision asks how you assess supplier risk, "we asked whether they were CRA-ready — here is the answer" is a better response than silence.

Questions for your supplier

Take these into your next tender or supplier review:

✅ Are your products in scope of the CRA, and when do you expect CE marking under it?
✅ Do you operate a public channel for receiving vulnerability reports?
✅ Can you provide an SBOM for the products we buy?
✅ How long will you ship security updates for this product — and what happens when support ends?
✅ How will you notify us if you report an actively exploited vulnerability affecting our installation?
✅ Which third-party components are included, and what is your plan when one reaches end-of-life?

The last point is worth dwelling on. A large share of vulnerabilities in IoT products originate in components the manufacturer did not write. When a component reaches end-of-life, the fixes stop arriving — but the product is still sitting in your door.


How it fits with NIS2 and CER

The three regimes interlock but land on different parties:

Regime Applies to Concerns Deadlines
CRA The manufacturer Product security 24 h / 72 h / 14 days
NIS2 The operator of the service Cybersecurity in operation 24 h / 72 h / 1 month
CER Designated critical entities Physical resilience 24 h / 1 month

If you are a utility using smart locks, one and the same vulnerability can trigger a CRA filing by your supplier and a NIS2 notification by you. They are not the same report, and they do not necessarily go to the same authority.

That is why it helps to have one place where the incident is recorded once and can then be worked against several regimes, each with its own countdown.


FAQ

When did the CRA reporting duty take effect?

11 September 2026. The remaining requirements – including security requirements, vulnerability handling and CE marking – apply from 11 December 2027.

What has to be reported?

Actively exploited vulnerabilities and severe incidents affecting the security of a product with digital elements. A vulnerability that is not being actively exploited does not trigger the Article 14 duty.

Are we covered if we only buy the equipment?

The reporting duty sits with the manufacturer. But if you resell a product under your own name or trademark, you may be a manufacturer under the regulation. And as a buyer you should still set requirements, because NIS2 makes supply chain security your responsibility.

Where are reports filed?

Through the CRA Single Reporting Platform, operational since 11 September 2026. The notification goes to the CSIRT of the member state where the manufacturer has its main establishment, and is shared with ENISA.


Contact us

Need to set the right requirements for your access control suppliers? Contact SnapKey.

Contact us
Related articles
CER Directive – Complete Guide to Critical Infrastructure Compliance

Understand the CER Directive (EU 2022/2557) and learn how SnapKey helps secure your critical infrastructure with advanced access control and compliance.

The CER Directive after 17 July 2026 – designated as a critical entity? The clock is running

The deadline for designating critical entities expired on 17 July 2026. If your organisation has been notified, you have 9 months for the risk assessment and 10 months to comply. Here is what CER requires of your physical security.

Access Control for District Heating – Secure Access to Substations and Cabinets

Digital access control for district heating companies. Replace lockboxes with traceable access to heat substations, exchanger stations, and technical rooms.


SnapKey Logo

SnapKey is your digital key for all types of locks. Easily open doors and locks directly from your smartphone, and enjoy fast, secure and flexible access without physical keys or extra apps. Perfect for private homes, businesses and shared spaces.

Solutions
SnapKey ResidentialSnapKey UtilitySnapKey PublicSnapKey LogisticsGuest Check-in
Developers
API documentationAPI referenceWebhooksChangelogSystem status
Company
About usWhy SnapKeyBecome a partnerKnowledgeVideosContact us
Legal
Terms & ConditionsPrivacy PolicyTrust & Security
Contact
SnapKey ApS+45 3242 9050info@snapkey.dk

© All rights reserved.