Most of Regulation (EU) 2024/2847 starts to apply on **11 December 2027**. The text itself carves out an exception: **Article 14 applies from 11 September 2026**.
For manufacturers placing products with digital elements on the EU market this means: while there is still time for the Annex I requirements and the technical documentation, **the reporting duty applies today.**
The deadlines
For an actively exploited vulnerability: an early warning within **24 hours** of becoming aware, a notification within **72 hours**, and a final report within **14 days**. For a severe incident the regulation sets the final report at one month.
Reports go to the CSIRT designated as coordinator and to ENISA.
When does the clock start?
The period starts when the manufacturer **becomes aware**. The real question is therefore organisational rather than technical: who records the moment of awareness, and where? Which address receives vulnerability reports, and who reads it at the weekend?
A team without a procedure will debate these questions during the incident. The clock keeps running meanwhile.
What has to be written down in advance
Who decides whether to report, who writes the report, who performs the technical review — and who **backs up** each of them. A procedure that depends on one person does not work on holidays or outside office hours; the deadlines do not wait.
The coordinated vulnerability disclosure contact point and the system that records the awareness timestamp also have to be fixed in advance.
Reporting alone is not enough
Annex I Part II also requires public disclosure of fixed vulnerabilities, distribution of security updates **separately** from functionality updates where technically feasible, and a machine-readable software bill of materials covering at least the top-level dependencies. That part contains 8 process requirements in total.
How Nechh Eco-Report handles it
The CRA Manufacturer Readiness Kit includes a notification procedure template for Article 14: the deadlines come from the regulation text, while the clock-zero definition, roles, backups and incident log fields are left to be filled in. No deadline that is not in the regulation has been added to the template.
Source: Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex; amended by Regulation (EU) 2025/327.
Publication note: This content is general information; it is not legal advice, a conformity assessment or a company-specific compliance evaluation. The final determination rests on the official text and, where needed, legal advice.
