Cyber Resilience Act statistics
The numbers that decide what a manufacturer owes under the Cyber Resilience Act: the reporting deadlines, the dates, the fines, the product classes, and what the exploited-vulnerability catalogues have done since Article 14 began. Each line stands on its own and names its source.
Checked against its sources on . Free to quote with a link to this page.
Reporting deadlines
24 hours
An early warning of an actively exploited vulnerability is due within 24 hours of the manufacturer becoming aware of it.Art. 14(2)(a)
72 hours
A vulnerability notification with product details, the nature of the exploit and any corrective measures is due within 72 hours of becoming aware.Art. 14(2)(b)
14 days
The final report on an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available, not 14 days after awareness.Art. 14(2)(c)
1 month
The final report on a severe incident is due within one month of submitting the incident notification.Art. 14(4)(c)
2
Every report goes to two recipients at once: the CSIRT designated as coordinator and ENISA, through the single reporting platform.Art. 14(1)
4
A manufacturer outside the EU picks its coordinating CSIRT by a four-step order: authorised representative, then importer, then distributor, then where most users are.Art. 14(7)
Dates
10 Dec 2024
The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024.Art. 71(1)
11 Jun 2026
The rules on notified bodies and conformity assessment bodies have applied since 11 June 2026.Art. 71(2)
11 Sep 2026
The Article 14 reporting obligations have applied since 11 September 2026, including to products placed on the market before that date.Art. 71(2)
11 Dec 2027
The rest of the Regulation, including conformity assessment and CE marking, applies from 11 December 2027.Art. 71(2)
Penalties
€15M or 2.5%
Breaching the essential requirements or the manufacturer obligations in Articles 13 and 14 carries a fine of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.Art. 64(2)
€10M or 2%
Breaching the other operator obligations carries a fine of up to €10 million or 2% of worldwide annual turnover, whichever is higher.Art. 64(3)
€5M or 1%
Giving incorrect, incomplete or misleading information to notified bodies or market surveillance authorities carries a fine of up to €5 million or 1% of turnover.Art. 64(4)
No fines
Open-source software stewards cannot be given administrative fines under the Regulation.Art. 64(10)
Products and support
19
Annex III lists 19 categories of important products in class I, from password managers and VPNs to routers and smart home security devices.Annex III
4
Annex III lists 4 categories of important products in class II: hypervisors and container runtimes, firewalls and intrusion detection, and tamper-resistant microprocessors and microcontrollers.Annex III
3
Annex IV lists 3 categories of critical products: hardware devices with security boxes, smart meter gateways, and smartcards including secure elements.Annex IV
Same clocks
A product’s class changes its conformity assessment route, and changes none of the Article 14 reporting deadlines.Art. 14
5 years
The support period must be at least five years, unless the product is expected to be in use for less time.Art. 13(8)
10 years
Each security update must remain available for at least ten years after it is issued, or for the rest of the support period if that is longer.Art. 13(9)
Exploited vulnerabilities since Article 14 began (2026-09-11 to 2026-09-30)
1,730
CISA’s Known Exploited Vulnerabilities catalogue held 1,730 entries on 2026-09-30. Source: CISA KEV catalogue 2026.09.30.
25
25 vulnerabilities were added to the KEV catalogue in the first 20 days of Article 14 reporting, from 18 different vendors. Source: CISA KEV catalogue 2026.09.30.
3 of 25
Only 3 of those 25 were published in OSV.dev against an open-source package ecosystem, the kind of match an SBOM of dependencies would surface. All 3 were in the Linux kernel. Source: Declara analysis of CISA KEV, OSV.dev and FIRST EPSS.
2.1%
The median EPSS score of those additions was 2.1% on 1 October 2026, and 7 of 24 scored below 1%, though every one was known to be exploited. Source: Declara analysis of CISA KEV, OSV.dev and FIRST EPSS.
The reporting platform
No API
ENISA’s Single Reporting Platform launched without a submission API, so every report is entered by hand through its web interface. Source: ENISA Single Reporting Platform.
v1.3
Declara’s report drafts are aligned to ENISA’s CRA SRP Glossary, Version 1.3, 10 September 2026. Source: Single Reporting Platform field guide.
Is anything in your SBOM on the exploited list today?
The free check compares a CycloneDX or SPDX file against CISA KEV in memory, keeps nothing, and needs no account.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.