Cyber Resilience Act: Start of reporting obligations
From September 11th 2026, manufacturers of products with digital elements will be subject to reporting obligations under the in the European Union (EU
) single market. They must report actively exploited vulnerabilities and severe incidents affecting their products. The Federal Office for Information Security (BSI
) will provide support in the form of step-by-step guides.
The reporting obligations are an important milestone in strengthening product security in accordance with the CRA
. Notifications are submitted in a unified formation Agency for <a href="https://bitcomme.com/terra-industries-leads-strategic-investment-in-nigerian-cybersecurity-startup-aeon/” title=”Terra Industries leads strategic investment in Nigerian cybersecurity startup Aeon”>Cybersecurity (ENISA
). These reports are addressed to the corresponding Computer Security Incident Response Team (CSIRT
) of an EU
Member State acting as a coordinator and to ENISA
. In Germany, the coordinating CSIRT
is CERT
-Bund within the BSI
For manufacturers whose main establishment is in the EU
, jurisdiction is generally determined by the Member State in which key cybersecurity decisions regarding the products are made. If a manufacturer does not have its main establishment in the EU
, jurisdiction is determined according to the CRA
‘s criteria in Article 14 (7). Relevant factors include the registered office of an authorised representative, importer or distributor, and the availability of the product in the respective EU
Member States.
Manufacturers may become aware of actively exploited vulnerabilities in their products through various channels, such as IT
security service providers or customers.
In the case of severe incidents affecting products with digital elements, these events may also be identified through external reports or the internal analysis of log data from applications and systems.
The CRA
-SRP
offers manufacturers a centralised, user-friendly and confidential notification channel. A single notification submittedStates in which the product containing digital elements is made available on the market at once
Prior registration on the CRA
-SRP
is not required. If necessary, registration and submission of a notification can be completed in a matter of minutes. The platform operates on state-of-the-art European IT
infrastructure in accordance with the latest security measures.
Further information on using the CRA
-SRP
is available on the BSI
website. Further information is also available from ENISA
.
Pressekontakt:
Bundesamt für Sicherheit in der Informationstechnik
Pressestelle
Tel.: 0228-999582-5777
E-Mail:presse@bsi.bund.de
Internet:
