Skip to content
All frameworks

What is Cyber Resilience Act?

The EU's Cyber Resilience Act. It sets cybersecurity requirements for products with digital elements placed on the EU market, and obliges manufacturers to report actively exploited vulnerabilities and severe incidents.

Who it binds

Manufacturers of products with digital elements — hardware or software — placed on the EU market. Article 3(13) covers supply 'whether for payment, monetisation or free of charge', so giving a product away does not take you out of scope. Importers and distributors have lesser duties.

24h
early warning

For an actively exploited vulnerability or a severe incident.

72h
notification

The fuller report.

14 days
final report

From when a corrective OR mitigating measure becomes available — not from discovery.

Dates that matter

  • 11 September 2026Article 14 reporting obligations apply.
  • 11 June 2026Chapter IV, on notified bodies, applied.
  • 11 December 2027Full application.

What people get wrong

Two tracks, two different clocks

Actively exploited vulnerabilities and severe incidents are reported separately, on their own paragraphs of Article 14 and with different final-report anchors. The vulnerability track's 14 days runs from a corrective or mitigating measure being available — a published workaround starts it, not only a fix — so until a measure exists there is no deadline to have missed. The severe-incident final report runs one calendar month from the submission of the 72-hour notification.

Read twice, by two parties

Every stage was read against the Official Journal text, and then checked again in September 2026 against NCSC Ireland's own operational guidance for Article 14 — the coordinating CSIRT's side of the same filing channel. The two agree on all six deadlines, including the two this product had to correct: the 14 days running from a mitigating measure and not only a fix, and the severe-incident month running from the submission of the notification rather than from discovery.

Where national guidance is tighter, we say so rather than encode it

NCSC Ireland states that the detailed notification must follow within 48 hours of submitting the early warning. Article 14 says only 'within 72 hours of becoming aware' and carries no such rule — the two coincide only if the early warning goes in at the 24-hour limit. The countdown runs the Article's clock, and the guidance is shown beside it, attributed. Encoding guidance as if it were the statute would tell a manufacturer a legal window had closed when it had not.

It is product regulation, and reporting is one part of it

The CRA also sets essential cybersecurity requirements, conformity assessment, technical documentation and CE marking. Vivid Risk covers the Article 14 reporting register only. It does not assess a product against essential requirements and does not produce a Declaration of Conformity.

Two duties are named but have no clock

Article 14(6) lets a CSIRT request an intermediate report, and Article 14(8) creates a separate duty to inform impacted users. Neither has a fixed deadline an engine can model, which is exactly why three tracked stages and a countdown would otherwise read as the whole of Article 14.

What Vivid Risk does with Cyber Resilience Act

An Article 14 reporting register for actively exploited vulnerabilities and severe incidents, with all six stage deadlines verified against the Official Journal.

This covers the Article 14 REPORTING duty only. It is not CE marking, conformity assessment, technical documentation or product-safety compliance. It files nothing with ENISA, a CSIRT or any authority — it records what you filed.

Questions

Does Vivid Risk file my CRA reports?

No. It files nothing with ENISA, the Single Reporting Platform, any national CSIRT or any market surveillance authority. It is a private record of what you tell us you filed, and when. The button reads 'Record what I filed'.

Our product shipped years ago. Are we out of scope?

Not for reporting. Products placed on the market before 11 December 2027 are generally exempt from the CRA's technical design requirements, but NCSC Ireland is explicit that they are not exempt from Article 14: if the product is available on the EU market today it is in scope whenever it was built. The obligation bites on newly discovered active exploitation — exploits you already knew about before 11 September 2026 do not have to be reported.

The vulnerability is in a library we did not write. Whose report is it?

Yours. Where an actively exploited vulnerability or severe incident arises in an integrated third-party component, the manufacturer of the final product makes the notifications, once they become aware their specific product is impacted.

We make a physical product. Is this about CE marking?

Not the part Vivid Risk covers. The CRA does require conformity assessment and CE marking for products with digital elements — and for important and critical product classes that assessment runs through a notified body, not a self-declaration. This product covers the Article 14 incident and vulnerability reporting duty only, which is a cybersecurity obligation. Conformity assessment needs a notified body or an accredited assessor, which we are not.

One assessment, every framework

The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.