Summary
- Cyber Resilience Act reporting obligations begin on 11 September, ahead of the regulation’s wider application in December 2027.
- Manufacturers must issue an early warning within 24 hours for actively exploited vulnerabilities and qualifying severe incidents, followed by fuller reporting.
- Moxa’s preparations show how compliance reaches engineering records, software bills of materials, security teams, legal functions, and management decisions.
Europe’s Cyber Resilience Act is about to move from long range compliance planning into operational incident handling, with manufacturers facing mandatory reporting deadlines for exploited vulnerabilities and severe security incidents from 11 September.
The first major application date arrives more than a year before most of the regulation becomes fully applicable in December 2027. Manufacturers of products with digital elements will have to submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting product security, followed by a fuller notification within 72 hours and, where required, a later final report.
That timetable turns vulnerability management into a process spanning engineering, product, security, legal, and management functions. Knowing that a flaw exists is no longer sufficient; manufacturers need to establish which products are affected, whether exploitation crosses the reporting threshold, what evidence is available, and who can authorise a notification while the regulatory clock is already running.
Industrial networking supplier Moxa has set out how it has prepared for the deadline, using software bills of materials, product and firmware traceability, a product security incident response team, and a secure development lifecycle to connect vulnerability detection with the records needed for regulatory decisions. Its preparations offer a practical view of how the CRA is moving cyber governance into the product lifecycle.
Reporting becomes an engineering requirement
The European Commission says manufacturers will report through a Single Reporting Platform managed by the EU Agency for Cybersecurity, ENISA. Notifications will be routed to the relevant computer security incident response team, with information shared where appropriate when affected products are available in more than one member state.
The obligation applies to actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements rather than every newly discovered weakness. Manufacturers still need a rapid technical assessment because they must establish whether available evidence indicates exploitation and whether the event meets the regulation’s threshold.
As Techopia examined when the reporting regime was taking shape, the deadline arrives before the CRA’s wider product security duties apply. Companies that still have more than a year to finish parts of their broader compliance programme consequently need working procedures now for one of the regulation’s most time sensitive requirements.
Moxa’s preparations illustrate why software bills of materials are becoming operational infrastructure rather than documents stored for occasional inspection. If a widely used component appears in a known exploited vulnerabilities catalogue, a manufacturer needs to identify which products and firmware releases contain it, where those products sit in their support lifecycle, and whether exploitation creates a reportable event. Weak component records can consume much of a 24-hour window before any regulatory decision is made.
Product security moves into routine governance
The CRA changes the economics of post-market security because manufacturers retain obligations after a digital product has shipped. Vulnerability handling, coordinated disclosure, patches, documentation, and support periods become part of product management rather than an optional security service added later.
Industrial suppliers face an additional complication because equipment can remain in factories, utilities, transport systems, and other operational environments for many years. Patching may require maintenance windows, safety checks, compatibility testing, or customer approval, which makes rapid vulnerability assessment very different from updating conventional office software.
Moxa says its model combines a product security incident response team with end-to-end software and firmware traceability, while its secure development processes are certified against IEC 62443-4-1. That certification does not establish CRA compliance across every product, but it demonstrates the organisational machinery required if reporting is to happen quickly without replacing technical evidence with assumptions.
A common European reporting portal should reduce some duplication, although most of the difficult work remains within the manufacturer. Engineering teams have to determine exposure, security staff assess exploitation, lawyers interpret reporting obligations, and managers decide what can responsibly be stated while an investigation remains incomplete.
The same deadline will increase pressure on customers to scrutinise suppliers’ vulnerability handling. Machine builders, system integrators, and operators of critical infrastructure often depend on component manufacturers for the information needed to assess their own risk, so slow or incomplete supplier responses can propagate through several layers of the technology supply chain.
Full CRA application in December 2027 will bring wider duties around secure development, vulnerability handling, conformity, and market surveillance. The September reporting deadline is an earlier test of whether businesses already have the product records and decision structures needed to make those rules work.
When the 24-hour clock begins, weak security tooling will be only one possible point of failure. Fragmented product inventories, unclear ownership, incomplete component records, and governance designed around monthly meetings may prove just as damaging when a regulator expects an answer within hours.












