Regulation (EU) 2024/2847
The Cyber Resilience Act, for people who have to comply with it
Not a summary of the whole Regulation. The reporting duty in Article 14 applies from 11 September 2026, the rest from 11 December 2027, and these pages cover the part that arrives first: what has to be reported, by when, to whom, and how.Art. 71(2)
Every claim cites the article it comes from, and every citation opens the text on EUR-Lex. Each page carries the date it was last read against the Regulation.
- Article 14
What Article 14 of the Cyber Resilience Act requires: who reports, when the 24-hour, 72-hour and final clocks start, and which authority receives each filing.
- Filing on the platform
Every field the ENISA platform asks for at each of the three stages, who may submit, what its validation does not gate, and what its own counter gets wrong.
- Deadlines
Every date that matters in the Cyber Resilience Act, from entry into force to the reporting duty on 11 September 2026 and full obligations on 11 December 2027.
- Where to report
The coordinating CSIRT in all 27 member states, the Article 14(7) rule for working out which one is yours, and why choosing wrong can void a notification.
- Fines
Up to €15 million or 2.5% of turnover for the reporting duty, and what the other two bands cover. What the authority weighs, and where small companies stand.
- Non-EU manufacturers
If your company is outside the EU but you sell into it, the Cyber Resilience Act applies. Here is how to work out which national authority receives your report.
- Readiness
The Article 13 duties as a questionnaire, which eight of them block a filing, and the five documents a manufacturer needs by December 2027.
- Monthly digest
One email a month: how many vulnerabilities the CISA exploited catalogue added, and how many sit in components that appear in real inventories. Counts only.
- Product classes
Every important and critical product category in the Cyber Resilience Act, what each class means for conformity assessment, and why none changes a deadline.
- Document outlines
The vulnerability handling process, disclosure policy, SBOM policy, Annex VII documentation and Annex V declaration, as outlines citing the article for each.
Two things you can run rather than read
- Scope check
Five questions, no sign-up. A verdict with the article it rests on, the authority you would report to, and the dates that apply.
- SBOM check
Upload a CycloneDX or SPDX SBOM and see which components appear in the CISA Known Exploited Vulnerabilities catalogue. Nothing is stored.
- Generating an SBOM
Produce a CycloneDX or SPDX bill of materials for a container image, a source tree or a binary in a minute with syft, and make it part of every release.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.