Regulation (EU) 2024/2847

The Cyber Resilience Act, for people who have to comply with it

Not a summary of the whole Regulation. The reporting duty in Article 14 applies from 11 September 2026, the rest from 11 December 2027, and these pages cover the part that arrives first: what has to be reported, by when, to whom, and how.Art. 71⁠(2)⁠

Every claim cites the article it comes from, and every citation opens the text on EUR-Lex. Each page carries the date it was last read against the Regulation.

  1. Article 14

    What Article 14 of the Cyber Resilience Act requires: who reports, when the 24-hour, 72-hour and final clocks start, and which authority receives each filing.

  2. Filing on the platform

    Every field the ENISA platform asks for at each of the three stages, who may submit, what its validation does not gate, and what its own counter gets wrong.

  3. Deadlines

    Every date that matters in the Cyber Resilience Act, from entry into force to the reporting duty on 11 September 2026 and full obligations on 11 December 2027.

  4. Where to report

    The coordinating CSIRT in all 27 member states, the Article 14(7) rule for working out which one is yours, and why choosing wrong can void a notification.

  5. Fines

    Up to €15 million or 2.5% of turnover for the reporting duty, and what the other two bands cover. What the authority weighs, and where small companies stand.

  6. Non-EU manufacturers

    If your company is outside the EU but you sell into it, the Cyber Resilience Act applies. Here is how to work out which national authority receives your report.

  7. Readiness

    The Article 13 duties as a questionnaire, which eight of them block a filing, and the five documents a manufacturer needs by December 2027.

  8. Monthly digest

    One email a month: how many vulnerabilities the CISA exploited catalogue added, and how many sit in components that appear in real inventories. Counts only.

  9. Product classes

    Every important and critical product category in the Cyber Resilience Act, what each class means for conformity assessment, and why none changes a deadline.

  10. Document outlines

    The vulnerability handling process, disclosure policy, SBOM policy, Annex VII documentation and Annex V declaration, as outlines citing the article for each.

Two things you can run rather than read

  • Scope check

    Five questions, no sign-up. A verdict with the article it rests on, the authority you would report to, and the dates that apply.

  • SBOM check

    Upload a CycloneDX or SPDX SBOM and see which components appear in the CISA Known Exploited Vulnerabilities catalogue. Nothing is stored.

  • Generating an SBOM

    Produce a CycloneDX or SPDX bill of materials for a container image, a source tree or a binary in a minute with syft, and make it part of every release.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.