Since September 11, 2026, makers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the EU platform CRA-SRP. Germany's federal cyber agency BSI acts as the national contact point and offers guidance for compliance.
Since September 11, 2026, reporting duties under the Cyber Resilience Act apply to makers of products with digital elements sold in the EU single market. They must report actively exploited vulnerabilities and severe security incidents as soon as they become aware of them. Reports are filed uniformly across the EU through the Single Reporting Platform, built by the EU cybersecurity agency ENISA. Recipients are the responsible national computer security incident response team and ENISA itself. In Germany, the federal computer emergency team inside BSI fills this role. No prior registration is required, and a report can reportedly be filed within minutes.
The duty marks a shift in European product safety policy. For the first time, makers of hardware and software with digital components must actively report incidents, not only operators of critical infrastructure as under the earlier NIS2 directive. Companies should check whether internal processes for detecting, assessing and reporting vulnerabilities on time already exist. Firms relying on suppliers outside the EU must also determine which national team is responsible in their case. For makers without a main base in the EU, responsibility depends on the location of their authorized representative, importer or distributor.
It remains unclear how strictly BSI and other national bodies will enforce the new deadlines in practice and where exactly the threshold for a severe incident lies. Smaller makers may feel the added administrative burden, even though the platform itself is described as simple to use. How reporting practice develops over coming months, and whether fines follow early cases, remains to be seen.
What this means for decision-makers
- Check whether your products fall under the definition of digital elements covered by the Cyber Resilience Act.
- Set up internal reporting channels so vulnerabilities can be filed through the CRA-SRP on time.
- Clarify which national response team is responsible for your company, especially if based outside the EU.
This story was produced automatically from the source named above and checked by software before publication. The image is symbolic and shows neither the event nor a real person. How this paper is made
