EU Cyber Resilience Act Reporting Rules Take Effect for Manufacturers
Manufacturers of products with digital elements made available on the European Union market are now subject to Cyber Resilience Act (CRA) reporting obligations that took effect on 11 September 2026. The European Commission says in its reporting guidance that manufacturers must provide an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident affecting the security of their product, followed by a fuller notification within 72 hours. The CRA's wider obligations become fully applicable on 11 December 2027.
The earlier reporting date matters because Article 14 applies to products with digital elements already made available on the EU market before 11 December 2027. The Commission's implementation FAQ, updated on 4 September 2026, says manufacturers of those earlier products may still have to report a qualifying vulnerability or incident even when other CRA requirements do not yet apply to the product. The reporting obligation is triggered when the manufacturer becomes aware of the actively exploited vulnerability or severe incident after the reporting provisions have entered into application.
For an actively exploited vulnerability, the CRA requires a final report no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month of the 72-hour notification. Article 14 also requires manufacturers to inform impacted users and, where appropriate, all users about the vulnerability or incident and any measures they can take to reduce its impact.
The Single Reporting Platform operated by the European Union Agency for Cybersecurity (ENISA) became operational on 11 September 2026 and is the channel for mandatory CRA notifications. ENISA's FAQ, updated on 12 September 2026, says assigned representatives require an EU Login account with multi-factor authentication. The initial platform release does not provide an application programming interface for submissions, although organisations may automate their internal reporting workflows.
Commercial software products commonly combine first-party code with third-party and open-source components. Commission guidance says a manufacturer must report an actively exploited vulnerability originating in an integrated component when the vulnerability is contained in and actively exploited in the manufacturer's own product. If the vulnerable component cannot be exploited in that product, or the vulnerability has not been actively exploited in it, that vulnerability does not create a mandatory Article 14 vulnerability report for that manufacturer.
For Drupal-related businesses, CRA scope depends on the product and the organisation's role rather than on Drupal use alone. A business that places an in-scope software product built with Drupal or other dependencies on the EU market may therefore need to determine whether an actively exploited upstream vulnerability is exploitable in its own product. Websites that do not support the functionality of a product with digital elements are not themselves products with digital elements, while standalone software-as-a-service and other cloud services are not themselves covered unless they meet the CRA definition of a remote data-processing solution.
The 11 September 2026 reporting commencement does not apply to open-source software stewards. The Commission and ENISA state that the reporting obligations in Article 24(3) apply to those stewards from 11 December 2027. The Commission's open-source guidance separately distinguishes open-source software stewards from manufacturers that place free and open-source software on the market in the course of a commercial activity.
For manufacturers within scope, the immediate operational change is the connection between product-security triage and statutory reporting deadlines. Teams need to establish when the manufacturer became aware of reliable evidence of active exploitation or a severe incident, determine whether the affected vulnerability is contained in the product, identify the relevant Computer Security Incident Response Team, and move from the 24-hour early warning to the 72-hour notification when required. For commercial products built on Drupal or other open-source stacks, product-level exploitability remains central to determining whether an upstream security issue becomes a reportable CRA event.
References
-
-
Cyber Resilience Act Implementation - Frequently Asked Questions, European Commission (4 September 2026)
-
Frequently Asked Questions: CRA Single Reporting Platform (8 September 2026)
-
