From 11 September 2026, anyone manufacturing an IP camera, a home router, an industrial PLC or connected software must report actively exploited vulnerabilities to ENISA and their national CSIRT within 24 hours. This is Article 14 of the Cyber Resilience Act, the first binding obligation of the regulation, arriving fifteen months ahead of everything else.
What Article 14 actually requires
The Cyber Resilience Act, Regulation (EU) 2024/2847, takes full effect on 11 December 2027. But Article 14, the reporting obligation, applies from 11 September 2026. It covers “manufacturers of products with digital elements”: any hardware or software that connects, directly or indirectly, to a device or network.
The duty is triggered in two cases:
- Actively exploited vulnerability: reliable evidence that a malicious actor has exploited it in a system without the owner’s permission.
- Severe incident: a cybersecurity event affecting the manufacturer’s development, production or maintenance processes in a way that raises risk for users.
The timeline runs in three stages, and this is where most secondary sources oversimplify:
| Stage | Deadline | What it contains |
|---|---|---|
| Early warning | 24 hours from awareness | Minimal notification: an exploited vulnerability exists, which member states the product is sold in. No root cause or fix required yet |
| Notification | 72 hours from awareness | General nature of the vulnerability or incident, initial assessment, corrective measures taken or available |
| Final report | 14 days from when a corrective measure becomes available (vulnerabilities) — one month from the 72-hour notification (severe incidents) | Full description, severity, impact, remediation applied |
The detail most guides get wrong: the vulnerability final report doesn’t run from discovery, it runs from remedy availability. A team that sets a “day 14 from awareness” reminder risks filing empty against a deadline that doesn’t exist yet, or missing the real one if the fix arrives late.
Who is actually affected not just smart-home gadgets
The dominant narrative around the CRA is “it’s about smart home devices.” That’s only partly true, and it’s the least interesting part for a professional Italian reader.
Video surveillance. Connected IP cameras fall under “Important Class I products” in Annex III the same risk tier as smart locks, baby monitors and alarm systems, explicitly named as higher-risk consumer products in the regulation’s recitals. For an installer or system integrator selling cameras to a condominium or a business client, this means having a live-exploit detection process ready now, not built after the first missed notification.
Industrial automation. PLCs, SCADA systems, and computerised numeric controllers for machine tools fall under Industrial Automation & Control Systems (IACS) as listed in Annex III. The practical problem here differs from consumer IoT: on a factory floor, an automatic update can halt a production line, so the regulation itself allows exceptions to automatic updating in critical industrial environments but it does not exempt anyone from the 24-hour reporting duty.
Products already sold. And this is the detail that surprises people most: the obligation also covers products placed on the market before the regulation existed, as long as they remain in use and under active support. A manufacturer no longer actively developing a 2021 camera model, but still supporting units installed at active client sites, must still report an exploited vulnerability found in it. The regulation doesn’t distinguish “new CRA-compliant product” from “legacy product” it distinguishes a product still in use from one that’s been discontinued.
The practical problem: the platform isn’t ready
Here’s the freshest, most concrete fact in this piece. Reports go through ENISA’s Single Reporting Platform (SRP) a single electronic notification point meant to simultaneously reach ENISA and the designated coordinating national CSIRT. Days before the obligation took effect, the platform had no published web address, no submission API at launch, and according to ENISA’s own technical guidance, its 72-hour counter can display a report as overdue before 72 hours have actually elapsed since awareness.
For an Italian company, this means one very concrete thing: the legal obligation exists from day one, but the tool for complying with it is still being finished. That’s not a reason to delay internal preparation it’s a reason not to blindly trust the platform’s displayed countdown, and to log internally the exact moment of “awareness,” which is the actual legal starting point of the clock.
The Commission’s 27 July 2026 guidance
On 27 July 2026, the European Commission published non-binding application guidance, required under Article 26 of the regulation document C(2026) 5252, roughly 80 pages. Its most useful contribution defines “awareness”: the clock doesn’t start when a raw report arrives, but once, after a prompt initial assessment, there is “a reasonable degree of certainty” that the vulnerability is actually being exploited. It’s a short but real triage window not an excuse to stall, nor an automatic trigger at the first unverified suspicion.
Italy note
We’re keeping this article’s Italian section focused on why the readiness gap matters for Italian manufacturers and integrators rather than duplicating regulatory detail already covered above; a fuller breakdown of the Italian coordinating authority appears in the Italian version, pending verification of ACN’s exact coordinating role.
FAQ
What happens if a company misses the 24-hour deadline?
The regulation provides for fines of up to €15 million or 2.5% of worldwide annual turnover for manufacturer obligation breaches, including Article 14 .
Does this cover vulnerabilities that haven’t been exploited yet?
No. Article 14 only triggers for vulnerabilities with reliable evidence of active exploitation by a malicious actor, or for severe incidents. A vulnerability found through good-faith research or a bug bounty programme, with no evidence of exploitation, is not subject to the reporting duty.
Does a product sold in 2022 count?
Yes, if it’s still in use and under active manufacturer support. The regulation makes no time-based exemption for the reporting obligation.
Sources
cyberresilienceact.eu, independent Article 14 summary, updated 7 September 2026
Regulation (EU) 2024/2847 of the European Parliament and of the Council, 23 October 2024 (EUR-Lex)
European Commission, application guidance C(2026) 5252, 27 July 2026 (digital-strategy.ec.europa.eu)
ComplexDiscovery, “Cyber Resilience Act reporting starts Sept. 11 on an unfinished platform,” September 2026



