CRA Updates: What Is in Force Right Now (2026)
Frontend Development
September 22, 2026•4 min read

I hope you enjoy reading this post. If you want us to do your frontend development or design, click here.
Author: Pavlo Tyshchenko | COO at The Frontend Company


The EU Cyber Resilience Act stopped being a future problem on September 11, 2026: its reporting obligations are now in force. Manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, with an early warning due within 24 hours. The rest of the regulation - the essential requirements, conformity assessment, CE marking - applies from December 11, 2027. This page is the running tracker: what applies right now, what comes next, and what changed, updated monthly. New to the regulation? Start with our Cyber Resilience Act guide; this page tracks what changes after it.
What exactly came into force on September 11, 2026?
Article 14 of Regulation (EU) 2024/2847 - the manufacturers' reporting obligations - and nothing else from the main body of the regulation. Chapter IV, the provisions on notifying conformity assessment bodies, has applied since June 11, 2026, but that is machinery for notified bodies, not a duty on manufacturers. If you manufacture a product with digital elements placed on the EU market, two triggers now start hard clocks:
- An actively exploited vulnerability in your product. An early warning within 24 hours of becoming aware of it, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available.
- A severe incident having an impact on the security of your product. The same 24-hour early warning, an incident notification within 72 hours, and a final report within one month of that notification. An incident counts as severe when it affects, or could affect, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions - or when it has led, or could lead, to malicious code running in the product or in a user's network and information systems.
Reports go through the Single Reporting Platform that ENISA switched on the same day. One submission reaches the CSIRT designated as coordinator in the Member State of your main establishment and ENISA at the same moment; that CSIRT forwards it to the other Member States where the product is available. Manufacturers without an EU establishment follow the cascade in Article 14(7): the Member State of the authorised representative, failing that the importer, then the distributor, then the one with the largest number of users. Access runs through an EU Login account with multi-factor authentication; each manufacturer registers one primary assigned representative and up to 20 secondary ones, validated by the coordinating CSIRT. At launch the platform is web-only - no API - and English-only, with translated supporting material following.
Two things teams miss. The obligation covers products already on the market: Article 69(3) applies Article 14 to every in-scope product placed on the market before December 11, 2027, so an exploited vulnerability in something you shipped in 2023 is reportable today. And reporting to authorities is not the whole duty - Article 14(8) requires you to inform impacted users, and where appropriate all users, about the vulnerability or incident and the corrective measures, without undue delay.
Who has to do what right now?
- Manufacturers: the entire live obligation sits here. Stand up an intake-to-report pipeline that can hit a 24-hour clock: someone must own the decision “is this actively exploited?”, the platform account must exist before the first incident, and the channel should be tested before you need it. A vulnerability disclosure policy and a working PSIRT process stopped being best practice and became infrastructure.
- Importers and distributors: nothing yet. Their duties in Articles 19 and 20 - verifying the CE marking and documentation, informing the manufacturer and market surveillance authorities of vulnerabilities they learn about - are part of the December 11, 2027 package, because Article 71 brings only Article 14 forward.
- Open-source software stewards: the light-touch reporting duty in Article 24(3) also waits until December 11, 2027. Non-commercial open-source development stays out of scope entirely.
- Everyone shipping to the EU from outside it: the regulation follows the product to the market, not the company to its headquarters. A US or UK vendor with EU customers is a manufacturer under the CRA.
Not yet mandatory, but now urgent: the December 2027 essential requirements - secure-by-default configuration, security updates for the support period, and the SBOM in your technical documentation. Teams that treat the months left as a runway rather than a buffer will spend a fraction of what the last-quarter scramble will cost. The component-inventory half of that work is covered in our SBOM formats guide.
Need a reporting pipeline that hits the 24-hour clock?
We do CRA readiness and engineering for teams shipping software into the EU: a vulnerability-handling process built for the Article 14 clocks, SBOM generation wired into CI, and a secure-by-default review of the product you actually ship. Book a call to map your gaps.
The CRA timeline: what applies when
Date | What applies | Status |
|---|---|---|
December 10, 2024 | Regulation (EU) 2024/2847 enters into force | Done |
June 11, 2026 | Chapter IV: notification of conformity assessment bodies (notified bodies can be designated) | Done |
September 11, 2026 | Article 14: reporting of actively exploited vulnerabilities and severe incidents; ENISA Single Reporting Platform live | In force now |
December 11, 2027 | Full application: essential requirements, conformity assessment, CE marking, support-period duties, importer, distributor and open-source steward obligations | Under 15 months out |
Penalties scale with the violation. Article 64 sets three tiers: up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaching the essential requirements or the manufacturer obligations in Articles 13 and 14 - reporting included; up to €10 million or 2% for most other obligations; and up to €5 million or 1% for supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities. Two carve-outs: open-source stewards are not fined at all, and micro and small enterprises cannot be fined for missing the 24-hour early-warning deadline specifically.
Where are the implementing acts and standards?
The regulation leaves the technical detail to two mechanisms: implementing and delegated acts from the Commission, and harmonised standards that give manufacturers a presumption of conformity. The Commission's implementation tracker is the official list; the state of play as of September 22, 2026:
- Adopted: Implementing Regulation (EU) 2025/2392 of November 28, 2025 describes the core functionality of the important and critical product categories in Annexes III and IV - the document you classify your product against. A delegated act adopted on December 11, 2025 sets the conditions under which a CSIRT may delay disseminating a notification on cybersecurity grounds.
- Not adopted: no implementing act on the SBOM format and elements (Article 13(24)) and none on the format and procedure of notifications (Article 14(10)). Until they exist, “commonly used and machine-readable” is the whole SBOM format rule, and the platform's own forms and ENISA's SRP glossary define what a report has to contain.
- Guidance: the Commission's first application guidance, C(2026) 5252 of July 27, 2026, plus a living FAQ. Non-binding, but it settles the questions most teams have: how open source and remote data processing fall in or out of scope, what counts as a substantial modification, and how support periods work.
- Harmonised standards: none cited in the Official Journal yet, so no presumption of conformity exists for any product category. Standardisation request M/606, accepted by CEN, CENELEC and ETSI on April 3, 2025, covers 41 standards. In July 2026 the Commission published a draft amendment pushing the 2026 deadlines back by two months: horizontal (Type A) and vulnerability-handling (Type B) standards to October 31, 2026, product-specific (Type C) standards to December 31, 2026; the remaining horizontal standards keep October 30, 2027. ETSI opened public enquiry on 17 draft product standards on August 13, 2026, with comment windows closing between mid-September and mid-November.
- Watch item: the Digital Omnibus proposal of November 2025 would turn ENISA's platform into a single entry point for incident reporting across NIS2, GDPR, DORA and the CRA - report once, share many. It is still in the legislative process, and it would change the front door, not the CRA's deadlines or thresholds.
- Meanwhile, in practice: Germany's BSI TR-03183 series is the most concrete reference many teams work from, and it is now four documents: Part 1 (general requirements, version 1.0.0), Part 2 (SBOM, version 2.1.0, which names the accepted formats and fields), Part 3 (vulnerability reports and notifications, version 1.0.0) and Part H (conformity based on full quality assurance, version 1.1.0). Useful, but a national guideline - it is not a harmonised standard and carries no presumption of conformity.

Transform your UI for peak performance!
🔹
Unlock seamless, high-performance frontend solutions tailored to your business.
🔹
Get an interface that outshines competitors and delights your users.
Changelog
September 2026. Article 14 reporting obligations entered into force on September 11. ENISA launched the Single Reporting Platform the same day - web interface only, English UI, EU Login with MFA; voluntary reporting and an API to follow - with an FAQ, user manuals, tutorial videos, a glossary and factsheets. Standards: no harmonised standard cited in the Official Journal; 17 ETSI product-standard drafts in public enquiry; the 2026 drafting deadlines moved to October 31 and December 31 after the July draft amendment to M/606. Guidance: the Commission's first application guidance (July 27, 2026) and its FAQ are the current reference for scope questions. Page published September 22, 2026.
New entries go on top each month. Older entries stay - this page is the record.
For the full regulation walkthrough - who is covered, risk classes, the essential requirements, the readiness program - start with the Cyber Resilience Act guide. This page picks up where it ends.
FAQ

Pavlo Tyshchenko is COO at The Frontend Company, where he runs operations, delivery, and the internal systems the company runs on - AI workflows, knowledge infrastructure, and hiring. He writes about AI agents, process automation, and the engineering side of software compliance.
LEARN MORE



