CRA Compliance

Five Months to September: What CRA Article 14 Compliance Actually Requires

By CVD Portal
Last updated 2026-08-2110 min read

The EU Cyber Resilience Act contains two essential deadlines. December 2027 requires full product conformity. On 11 September 2026, vulnerability reporting duties under Article 14 take effect. This obligation applies to all products already made available on the EU market.

Manufacturers must understand what compliance requires on that date. For full regulatory context, see the EU Cyber Resilience Act guide.

What September 2026 Requires

The September deadline does not require complete conformity assessments, CE marking, or Annex VII technical files. Those requirements apply in December 2027.

The September obligation requires a functioning vulnerability handling process. Manufacturers, importers, and distributors must be ready to report actively exploited vulnerabilities immediately upon awareness.

The Two Core Articles

Article 13: The Vulnerability Disclosure Policy

Article 13 requires manufacturers to provide a secure, publicly accessible reporting channel. This is the Coordinated Vulnerability Disclosure policy (VDP).

The VDP serves as the primary intake mechanism for vulnerability reports. Without a clear reporting point, manufacturers may miss early exploitation signals.

Article 14: The Reporting Cascade

When a manufacturer identifies an actively exploited vulnerability in a product, mandatory reporting follows this schedule:

  1. Within 24 hours: Submit an early warning to the Single Reporting Platform, which notifies ENISA and the national CSIRT.
  2. Within 72 hours: Submit a detailed notification covering severity, scope, indicators of compromise, and affected versions.
  3. Within 14 days (for vulnerabilities) or one month (for severe incidents): Submit a final report detailing root cause, corrective measures, and disclosure plans.

The disclosure strategy forms part of the final report to authorities.

What Operational Readiness Means

Meeting requirements on paper is not enough. Systems must perform under incident pressure.

Compliant manufacturers establish four key capabilities:

Tested intake processes. The VDP is published, monitored, and staffed. Teams acknowledge reports within 48 hours following standard practice.

Defined triage authority. Designated personnel hold standing authority to file 24-hour early warnings without waiting for executive approval.

Pre-built report templates. Teams maintain ready-to-use notification templates. Login access to the Single Reporting Platform is verified in advance.

Immutable audit trails. Every received report, triage assessment, and authority notification is logged with timestamps.

The SME Challenge

Large enterprises often maintain dedicated product security teams. Most small and medium manufacturers lack these resources.

Building intake portals, triage workflows, authority reporting, and audit logs requires substantial engineering time. Setting up compliant infrastructure before September requires immediate action.

How CVD Portal Solves the Gap

CVD Portal provides complete Article 13 and Article 14 infrastructure as a service. Getting started is free.

Manufacturers receive a branded portal with structured intake, 48-hour acknowledgment tracking, CVSS triage, ENISA-aligned report generation, audit logging, and CSAF 2.0 advisory publishing.

The platform provides ready-to-use infrastructure so teams can focus on operational readiness.

The Conclusion

The September 2026 deadline is mandatory for every supported product on the EU market. Teams that prepare now ensure compliance before enforcement begins.

Frequently asked questions

When do CRA Article 14 reporting obligations become enforceable?

11 September 2026 is when Article 14 reporting obligations become enforceable for products already on the market. Full CRA conformity is not until December 2027, which makes September the operational deadline.

What must be operational by September 2026?

Six capabilities. An Article 13 vulnerability disclosure policy that is publicly accessible, a triage process able to determine active exploitation within hours, a 24-hour early warning to ENISA and the national CSIRT, a 72-hour detailed technical notification, a 14 to 30 day final report with disclosure strategy, and a full audit trail of all vulnerability handling activity.

Why is the September 2026 deadline hard for SMEs?

Most SMEs selling hardware or software into the EU market have none of this infrastructure. Building it in-house, from VDP through structured intake, triage workflow, authority reporting and audit trail, requires months of engineering. The clock does not wait for infrastructure to be built.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Get Started for Free

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.