Skip to content

The 24-hour reporting duty is in force. Check whether it applies to you

Cyber Resilience Act statistics

The numbers that decide what a manufacturer owes under the Cyber Resilience Act: the reporting deadlines, the dates, the fines, the product classes, and what the exploited-vulnerability catalogues have done since Article 14 began. Each line stands on its own and names its source.

Checked against its sources on . Free to quote with a link to this page.

Reporting deadlines

  • 24 hours

    An early warning of an actively exploited vulnerability is due within 24 hours of the manufacturer becoming aware of it.Art. 14⁠(2)⁠⁠(a)⁠

  • 72 hours

    A vulnerability notification with product details, the nature of the exploit and any corrective measures is due within 72 hours of becoming aware.Art. 14⁠(2)⁠⁠(b)⁠

  • 14 days

    The final report on an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available, not 14 days after awareness.Art. 14⁠(2)⁠⁠(c)⁠

  • 1 month

    The final report on a severe incident is due within one month of submitting the incident notification.Art. 14⁠(4)⁠⁠(c)⁠

  • 2

    Every report goes to two recipients at once: the CSIRT designated as coordinator and ENISA, through the single reporting platform.Art. 14⁠(1)⁠

  • 4

    A manufacturer outside the EU picks its coordinating CSIRT by a four-step order: authorised representative, then importer, then distributor, then where most users are.Art. 14⁠(7)⁠

Dates

  • 10 Dec 2024

    The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024.Art. 71⁠(1)⁠

  • 11 Jun 2026

    The rules on notified bodies and conformity assessment bodies have applied since 11 June 2026.Art. 71⁠(2)⁠

  • 11 Sep 2026

    The Article 14 reporting obligations have applied since 11 September 2026, including to products placed on the market before that date.Art. 71⁠(2)⁠

  • 11 Dec 2027

    The rest of the Regulation, including conformity assessment and CE marking, applies from 11 December 2027.Art. 71⁠(2)⁠

Penalties

  • €15M or 2.5%

    Breaching the essential requirements or the manufacturer obligations in Articles 13 and 14 carries a fine of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.Art. 64⁠(2)⁠

  • €10M or 2%

    Breaching the other operator obligations carries a fine of up to €10 million or 2% of worldwide annual turnover, whichever is higher.Art. 64⁠(3)⁠

  • €5M or 1%

    Giving incorrect, incomplete or misleading information to notified bodies or market surveillance authorities carries a fine of up to €5 million or 1% of turnover.Art. 64⁠(4)⁠

  • No fines

    Open-source software stewards cannot be given administrative fines under the Regulation.Art. 64⁠(10)⁠

Products and support

  • 19

    Annex III lists 19 categories of important products in class I, from password managers and VPNs to routers and smart home security devices.Annex III

  • 4

    Annex III lists 4 categories of important products in class II: hypervisors and container runtimes, firewalls and intrusion detection, and tamper-resistant microprocessors and microcontrollers.Annex III

  • 3

    Annex IV lists 3 categories of critical products: hardware devices with security boxes, smart meter gateways, and smartcards including secure elements.Annex IV

  • Same clocks

    A product’s class changes its conformity assessment route, and changes none of the Article 14 reporting deadlines.Art. 14

  • 5 years

    The support period must be at least five years, unless the product is expected to be in use for less time.Art. 13⁠(8)⁠

  • 10 years

    Each security update must remain available for at least ten years after it is issued, or for the rest of the support period if that is longer.Art. 13⁠(9)⁠

Exploited vulnerabilities since Article 14 began (2026-09-11 to 2026-09-30)

The reporting platform

Is anything in your SBOM on the exploited list today?

The free check compares a CycloneDX or SPDX file against CISA KEV in memory, keeps nothing, and needs no account.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.