Three changes are live. You can now record who files each Article 14 notification, declare which CRA roles your company holds, and follow a phased plan to December 2027.
Article 14 starts to apply on 11 September 2026. It is the only part of the Cyber Resilience Act that binds on that date. The rest of the Regulation applies from 11 December 2027. If you do one thing this week, name the three notification owners.
Record who files each Article 14 notification
Article 14 runs on three clocks. Until now the Vulnerability Handling Procedure captured one filer. It now asks for an owner per stage, so nobody has to work out who submits while the 24-hour clock runs.
- 24-hour early warning. The person who submits the first notification.
- 72-hour full notification. The person who completes it, and who may escalate to legal or an executive.
- 14-day final report. The person who signs off the closing submission.
Single Reporting Platform readiness
The same form now records whether your EU Login access is confirmed, who your primary and backup submitters are, where your offline notification worksheet is kept, and when you last ran a notification exercise. It also records how you establish the moment you became aware of a vulnerability, which is what starts the clock.
The three owners may be the same person. Many small teams will name one. The portal marks the item complete only when every owner carries a name and an email, so a half-filled form does not read as done.
Where to find it: Readiness, then Vulnerability Handling Procedure.
Tell us which CRA roles you hold
The Cyber Resilience Act gives different duties to different roles. Until now the portal assumed every company was a manufacturer. You can now declare one or more roles, and the obligations you are shown follow that answer.
| If you are a | Technical file | SBOM and secure development |
|---|---|---|
| Manufacturer | You compile it | Required |
| Importer | You check it | Not applicable |
| Distributor | You check it | Not applicable |
| Open-source steward | Not applicable | Not applicable |
Hold several roles and the most demanding one wins. A company that both manufactures and distributes still compiles a technical file.
One question you must answer honestly
Article 21 turns an importer or a distributor into a manufacturer when they sell a product under their own name or trademark, or when they modify it substantially. The portal asks you directly rather than guessing. Answer yes and the manufacturer duties come back.
Where to find it: Settings, then Company profile.
Follow a phased plan to December 2027
A new collapsible section on the Readiness page sets out the work in order, from scoping and classification through SBOM, the vulnerability pipeline, the support period and the technical file. Each phase names a typical owner, such as Legal and CISO or SecOps, and a target window.
Progress is read from your control register, so the roadmap reflects work you have already done. It keeps no separate tick list. Phases that do not apply to your declared roles are hidden.
Only the priority phase carries a real date, 11 September 2026. Every other window is a suggested pace measured from your account start date, not a legal deadline. An administrator can change the start date the windows count from.
Where to find it: Readiness, then Implementation roadmap.
What has not changed
Your readiness figures are the same today as they were yesterday. Until you declare a role, every account is treated as a manufacturer, exactly as before. Nothing you have already recorded was moved, cleared or re-scored.
Your existing notification contacts were carried into the new fields. The person you had named as the ENISA filer is now your 24-hour early warning owner, and your backup contact is now your backup submitter. Check them, then fill in the two stages that were never asked for.
Declaring a non-manufacturer role will change your percentage, because obligations that do not apply to you leave the count. That is the point of the change.
Source and scope
The role table, the notification owner stages and the phased plan are adapted from the OpenChain CRA Compliance Checklist (RC1, 19 August 2026), used under CC BY 4.0.
Completing a checklist is not a conformity assessment, an EU Declaration of Conformity, or evidence of lawful CE marking. Conformity depends on the applicable conformity-assessment procedure and its technical documentation. This note is not legal advice.