Boxfish Labs home
Boxfish Labs
  • Services
  • Solutions
  • Resources
  • About
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • Information Security Advisory
    • External CISO
    • External DPO
    • Data Residency & Sovereignty
    • Human-Centric Cybersecurity Awareness
    • Book a Call
    • View all services
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Who We Help
      • Startups
      • Scaleups
      • SMEs
      • Organisations
      • Educators
      • Individuals
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • View all resources
    • About us
    • Pledge
    • Social impact
    • Partnerships
    • Contact
    • View about Boxfish Labs
  • EN
  • DE
  • HU
Book a Call

Cyber Resilience Act Reporting Obligations: Who Must Report, When, and How

Learn who must report under the EU Cyber Resilience Act, which cybersecurity problems trigger reporting, the 24-hour and 72-hour deadlines, and how to prepare your team.

Boxfish Labs

September 3, 2026 • 14 min read
Cover graphic for Cyber Resilience Act reporting obligations: who must report, when, and how

From 11 September 2026, companies that sell certain software or connected products in the EU must report some serious cybersecurity problems quickly.

These are the reporting obligations under the EU Cyber Resilience Act. They apply when attackers are using a weakness in a product, or when a serious cyber incident affects the product’s security.

The first report can be due within 24 hours of the company becoming aware of the problem. This is why software companies, connected-device makers, SaaS providers, app companies, and product teams need to know what is expected before an incident happens, as set out in European Commission CRA reporting guidance.

The legal section containing these reporting rules is Article 14. You do not need to understand legal article numbers to prepare. The practical question is simple: if something serious happens in our product, do we know who decides, who reports, and what we need to say?

This article provides general information, not legal advice. Whether the Cyber Resilience Act applies, and whether an event must be reported, depends on the facts of the case.

What are the Cyber Resilience Act reporting obligations?

The Cyber Resilience Act is an EU law intended to improve the cybersecurity of many software products and connected devices made available in the EU.

Its reporting obligations do not mean that every software bug, service outage, or customer complaint must be reported. They focus on two situations:

  1. Attackers are using a security weakness in your product. For example, someone uses a login flaw to access customer accounts without permission.
  2. A serious cyber incident affects your product’s security. For example, someone compromises a software update, steals a key used to verify updates, or inserts harmful code into a product.

These reporting obligations apply from 11 September 2026. The wider Cyber Resilience Act rules apply later, from 11 December 2027, according to the European Commission overview of the Cyber Resilience Act.

Who must report a cybersecurity incident under the Cyber Resilience Act?

Usually, the duty falls on the company that sells or supplies the product under its own brand. The law calls this company the manufacturer.

This could include:

  • A software company selling an app, platform, or business tool
  • A company selling a connected device
  • A company offering a product developed by an external agency under its own brand
  • A company selling a white-label product under its own name
  • A company supplying a digital component separately, such as a plugin or software library

Using an external developer, cloud provider, or technology supplier does not automatically move responsibility to them. If your company puts the product on the EU market under its own name or brand, your company may be responsible.

Importers and distributors have other responsibilities under the Cyber Resilience Act, but the direct reporting duty is mainly aimed at the company responsible for the product, as summarised by the European Commission.

Which products are covered by the Cyber Resilience Act?

The Cyber Resilience Act covers many products with a digital connection that are supplied in the EU as part of commercial activity.

This can include:

  • Connected devices, such as routers, cameras, sensors, gateways, wearables, printers, and industrial equipment
  • Desktop, mobile, embedded, server, and cloud-connected software
  • Mobile apps that communicate with a device, service, or network
  • Software components supplied separately, such as plugins, libraries, modules, development kits, and operating-system components
  • Some remote services that are necessary for a product to perform a function

The details can be complex, particularly for SaaS products, digital services, open-source projects, components, and free products. Boxfish Labs can help you assess which of your products may be affected.

What cybersecurity problems must be reported?

You may need to report when your company becomes aware that:

  • Attackers are actually exploiting a security weakness in your product, or
  • A serious cyber incident is affecting the security of your product.

A high-risk technical weakness is not automatically reportable just because it could be exploited. There should be credible evidence that attackers are actually using it.

A serious cyber incident can include events that threaten the confidentiality, integrity, authenticity, or availability of important product functions or data. Examples may include a compromised software update, harmful code introduced into a product, a stolen update-signing key, or a serious supply-chain compromise.

A major service outage is not automatically reportable. The key question is whether it affects the security of the product, not only whether it causes disruption or lost revenue.

Do we need to report every software vulnerability?

No.

The Cyber Resilience Act does not require companies to report every software bug or security weakness. It focuses on weaknesses that attackers are actually using and serious incidents that affect product security.

A security weakness found internally may still need to be fixed quickly and communicated to customers where appropriate. It may also create duties under contracts, data-protection law, sector rules, or your own security policy. But it is not automatically a Cyber Resilience Act report.

When does the 24-hour reporting deadline start?

The deadline starts when your company becomes aware of the problem.

You should not wait until every detail is known. A credible customer report, security alert, internal log, supplier notice, or message from a security researcher may be enough to start an urgent internal review.

The practical approach is to record when your company first receives credible information, investigate immediately, and make sure a named person can decide whether a report may be required. The first warning can be due within 24 hours of awareness.

What are the 24-hour and 72-hour reporting deadlines?

The Cyber Resilience Act uses a staged reporting process.

DeadlineWhat you need to do
Within 24 hoursSend an early warning that a reportable problem may have happened
Within 72 hoursSend more detail about the product, the problem, its impact, and the steps taken
LaterSend a final report once the investigation and response have progressed

For a security weakness that attackers are actively using, the final report is due no later than 14 days after a corrective or risk-reducing measure is available. For a serious incident, the final report is due within one month of the 72-hour notification.

Where do companies report a Cyber Resilience Act incident?

If a report is required, the company submits it through the EU’s Cyber Resilience Act reporting system. The report is sent to the relevant national cyber incident response team and ENISA, the EU Agency for Cybersecurity.

Before an incident, make sure you know:

  • Which registered company will submit a report
  • Who can decide whether the reporting duty may apply
  • Who can submit a report outside normal working hours
  • Who has access to the reporting system
  • Who keeps the evidence and decision record

You do not need to become an expert in EU regulation to begin preparing. Boxfish Labs can help you understand what applies to your products and create a process that works under time pressure.

What should the first report contain?

The first report should be short, factual, and honest about what is still unknown. Do not delay a required notification because the root cause, the full attack method, or the number of affected customers is not yet clear.

Include, where available:

  • The affected product and known versions or parts
  • When and how your company became aware
  • Whether attackers may be using a security weakness, whether a serious incident may have happened, or both
  • A short description of the known security impact
  • The first steps taken to contain or reduce the risk
  • Whether malicious activity is suspected

Use simple labels such as “confirmed”, “preliminary”, “under investigation”, and “not yet known”.

Does the Cyber Resilience Act apply to free software and free apps?

It can.

The Cyber Resilience Act is not limited to products that customers pay for directly. A free app, software tool, plugin, connected device, or digital service may still be covered if it is supplied as part of commercial activity in the EU.

For example, the rules may be relevant if the free product supports a paid business, a commercial platform, or another revenue-generating service. A genuinely non-commercial project may be treated differently, but “free” does not automatically mean “outside the Cyber Resilience Act”, based on the Official Journal CRA text on market supply and commercial activity.

Not sure whether your product model is commercial for Cyber Resilience Act purposes? Boxfish Labs can help you assess it.

Does the Cyber Resilience Act apply to companies outside the EU?

Yes, it can.

The Cyber Resilience Act is not limited to companies registered in the EU. It can apply to a company based anywhere if it makes covered software, connected devices, apps, or digital components available to customers or users in the EU.

For example, a business based in the UK, United States, Switzerland, Canada, or elsewhere may need to assess the rules if it supplies a covered product in the EU.

The important question is not only where the company is based. It is whether the product is made available on the EU market and which company is responsible for supplying it.

Does the Cyber Resilience Act apply if we sell worldwide?

You should assess the EU part of your product distribution.

If the product is made available to customers or users in the EU, the Cyber Resilience Act may be relevant even if most customers are elsewhere. Start by identifying which products reach the EU, which versions are used there, and which registered company is responsible for supplying them.

What should we do if we suspect attackers are using a weakness in our product?

Do not ignore the warning sign.

You do not need complete proof before starting an urgent internal assessment. A credible customer report, suspicious logs, a message from a security researcher, or reliable threat information may be enough to trigger escalation.

Record when your company first received credible information, investigate immediately, and make sure a named person can decide whether reporting may be required. The first warning can be due within 24 hours of awareness.

What are the consequences of missing a Cyber Resilience Act reporting deadline?

Missing a required report can lead to action by national authorities.

The Cyber Resilience Act allows EU countries to impose fines for certain failures to meet its reporting obligations of up to €15 million or 2.5% of the company’s total worldwide annual turnover from the previous financial year, whichever is higher, under the Official Journal CRA rules on penalties. National authorities apply and enforce these rules.

There can also be practical consequences:

  • Customers may lose confidence if the company does not communicate clearly during a serious security event
  • Support, sales, and account teams may give inconsistent advice
  • The company may miss separate deadlines under data-protection law, customer contracts, insurance policies, or sector-specific rules
  • It may be difficult to show regulators that the company made a reasonable decision if there is no documented record

The aim is not to report every technical alert. It is to spot serious product-security events quickly and make a clear, documented decision.

Are we still responsible if we use cloud providers, agencies, or suppliers?

Your company may still be responsible.

A cloud provider, external developer, security supplier, or white-label partner may provide important logs, technical evidence, patches, or incident-response support. But if your company sells the product under its own name or brand, it may still be the company responsible for reporting.

Before an incident, know who can provide evidence quickly, approve and deploy a fix, communicate with customers, and make urgent reporting decisions.

Do we need to tell customers about an exploited vulnerability?

Often, yes.

Reporting to authorities and informing customers are different tasks. Customers may need practical advice, such as whether they are affected, whether they need to update software, change credentials, apply a temporary workaround, or monitor for suspicious activity.

For actively exploited vulnerabilities, the Cyber Resilience Act requires manufacturers to inform affected users without undue delay and, where appropriate, tell them how to reduce their risk, under the Official Journal CRA reporting requirements.

Do Cyber Resilience Act reports replace GDPR or NIS2 reporting?

No.

One cyber incident can create more than one reporting duty. For example, an exploited weakness in a software product may require a Cyber Resilience Act assessment. If personal data is affected, the company may also need to assess its GDPR obligations. Other rules, customer contracts, insurance requirements, and sector-specific obligations may also apply.

Use one coordinated incident process, but make sure each possible reporting duty has its own deadline, owner, and documented decision.

How can companies prepare for Cyber Resilience Act reporting?

You do not need to build a large compliance programme to begin. The immediate goal is to make sure your company can identify a possible reportable event, make a fast decision, and submit an early warning within 24 hours if required.

A focused 30-day preparation plan should help you start with four areas:

  1. Map products and company responsibility: identify priority EU products, the company responsible for each product, key versions, major dependencies, and the people who need to be contacted.
  2. Create a fast escalation route: decide what security signals must be escalated and who decides whether the reporting duty may apply.
  3. Prepare for reporting: make sure the right people, information, and access are ready before an incident.
  4. Test the response: check whether security, engineering, legal, support, and leadership can work together quickly during a serious product-security event.

Download the Cyber Resilience Act 30-Day Readiness Plan

The free Cyber Resilience Act 30-Day Readiness Plan gives software and connected-product teams a clear four-week overview of the actions to prioritise before the reporting obligations apply.

It helps you focus on the first questions to resolve:

  • Which products and registered companies may be affected?
  • How should possible incidents be escalated?
  • Who needs authority to make urgent decisions?
  • How can the team prepare to meet a 24-hour deadline?

Request the free 30-Day Readiness Plan

Get tailored Cyber Resilience Act support from Boxfish Labs

A high-level plan is a useful starting point. It does not decide whether your specific products are covered, which registered company is responsible, whether a real event meets the reporting threshold, or how your suppliers and teams should work together during an incident.

Boxfish Labs provides tailored Cyber Resilience Act readiness assessments and implementation support for software and connected-product teams. This can include product and company mapping, responsibility assessment, escalation design, reporting processes, customer communication processes, supplier coordination, documentation, and team exercises.

Book a Cyber Resilience Act readiness consultation with Boxfish Labs

Key takeaway

The Cyber Resilience Act requires fast reporting of two types of serious product-security event: security weaknesses that attackers are actually using, and serious incidents affecting product security.

For most companies, the important first step is not reading EU legislation line by line. It is understanding which products may be affected, who is responsible, how urgent security signals reach the right people, and who can make a decision when the 24-hour clock starts.

Boxfish Labs can help you turn that starting point into a practical process for your organisation.

Share this article

Need help applying this to your product?

Boxfish Labs helps teams understand Cyber Resilience Act reporting obligations and prepare for the 24-hour reporting deadline.

Book a discovery call
  • What are the Cyber Resilience Act reporting obligations?
  • Who must report a cybersecurity incident under the Cyber Resilience Act?
  • Which products are covered by the Cyber Resilience Act?
  • What cybersecurity problems must be reported?
  • Do we need to report every software vulnerability?
  • When does the 24-hour reporting deadline start?
  • What are the 24-hour and 72-hour reporting deadlines?
  • Where do companies report a Cyber Resilience Act incident?
  • What should the first report contain?
  • Does the Cyber Resilience Act apply to free software and free apps?
  • Does the Cyber Resilience Act apply to companies outside the EU?
  • Does the Cyber Resilience Act apply if we sell worldwide?
  • What should we do if we suspect attackers are using a weakness in our product?
  • What are the consequences of missing a Cyber Resilience Act reporting deadline?
  • Are we still responsible if we use cloud providers, agencies, or suppliers?
  • Do we need to tell customers about an exploited vulnerability?
  • Do Cyber Resilience Act reports replace GDPR or NIS2 reporting?
  • How can companies prepare for Cyber Resilience Act reporting?
  • Download the Cyber Resilience Act 30-Day Readiness Plan
  • Get tailored Cyber Resilience Act support from Boxfish Labs
  • Key takeaway
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Services
  • Solutions
  • Resources
  • About

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs