Independent medical device and health tech news

EU Cyber Resilience Act: Article 14 reporting duties become enforceable on 11 September 2026

From 11 September 2026, manufacturers of connected products must report exploited vulnerabilities and severe incidents under Article 14 of the EU Cyber Resilience Act, with an early warning due within 24 hours. The duty applies to any product still on the EU market, even one no longer in active development.

Regulatory ·

What is changing on 11 September 2026?

From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT within strict deadlines: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days of a fix becoming available.

Who does this affect?

Any manufacturer whose connected product remains available on the EU market, regardless of whether the product is still under active development. A device shipped years ago can carry new legal obligations.

What should manufacturers do now?

Establish a coordinated vulnerability disclosure process, define who owns incident reporting, and make sure monitoring is in place to detect exploited vulnerabilities in time to meet the 24-hour early-warning window.

Frequently asked questions

When does the EU CRA Article 14 reporting duty start?

The mandatory vulnerability and incident reporting obligations under Article 14 of the EU Cyber Resilience Act become legally enforceable on 11 September 2026.

Does it apply to products already on the market?

Yes. The obligation depends on whether a product with digital elements is still available on the EU market, not on whether it is still being actively developed.

What are the penalties for non-compliance?

Failure to meet the reporting deadlines can result in fines of up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher.

Sources