← Back to News

Assessing the Impact of CRA Reporting Obligations on Legacy Products

Manufacturers are reminded that the CRA’s vulnerability reporting obligations, taking effect in September 2026, apply to all products with digital elements currently active on the Union market-not merely new products introduced after the legislation's entry into force.

If a vulnerability is actively exploited in a legacy product that remains in its support lifecycle after the September 2026 deadline, the manufacturer is legally required to report it via the Single Reporting Platform. ENISA recommends that organizations conduct comprehensive audits of their active product portfolios and update their end-of-life (EOL) and vulnerability disclosure policies accordingly.