Vulnerability reporting obligations under CRA come into force in the EU
Original title: Стаття 14 Cyber Resilience Act: нові обов'язки щодо звітування про вразливості в ЄС
As of 11 September 2026, Article 14 of the Cyber Resilience Act (EU Regulation 2024/2847) becomes applicable in the EU, establishing horizontal cybersecurity requirements for products with digital elements. Manufacturers and distributors of products must comply with new requirements for reporting identified vulnerabilities to competent authorities and, where necessary, to users.
What changed
- Introduction of vulnerability reporting obligation: manufacturers and distributors of products with digital elements must report identified vulnerabilities to relevant authorities within established timeframes.
- Application across the entire EU: Article 14 CRA requirements apply horizontally to all products with digital elements, regardless of sector.
Who is affected
Manufacturers and distributors of products with digital elements placing products on the EU market.
Summary generated by a language model; the official text prevails. Not legal advice.