The European Union’s Cyber Resilience Act reaches its first hard enforcement milestone on September 11, 2026, when reporting duties for actively exploited vulnerabilities and severe security incidents begin to apply. The obligation lands on manufacturers of products with digital elements, but the compliance burden reaches deep into retail, because a large share of the connected goods sold across Europe arrives through importers, distributors and online storefronts that carry legal duties of their own.
Regulation (EU) 2024/2847 does not become fully applicable until December 11, 2027. The reporting articles were carved out and front-loaded, which means retailers face a live obligation more than fifteen months before the rest of the regime bites. Law firm alerts published through July and August 2026, including guidance from Jones Day dated July 27 and a countdown alert from Crowell & Moring, have framed the date as the point at which the theoretical becomes operational.
In short
- September 11, 2026 is when CRA reporting duties for actively exploited vulnerabilities and severe incidents start to apply, per the European Commission’s own guidance.
- The clock is 24 hours for an early warning, 72 hours for a full notification, then a final report within 14 days or one month depending on the trigger.
- Reports go through ENISA’s Single Reporting Platform, which the Commission says will be operational by the same date, routing simultaneously to a national CSIRT and to ENISA.
- Penalties reach EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher, putting the CRA in the same tier as the EU’s other flagship enforcement regimes.
- Retailers that sell connected products under their own brand are treated as manufacturers, which converts a private-label range into a direct reporting liability.
What actually changes on September 11
Until now the CRA has been a design-stage regulation. Its essential cybersecurity requirements, conformity assessment routes and CE marking rules all attach to the December 2027 date, which gave manufacturers a long runway. The reporting obligations are different, because they attach to events rather than to product launches.
From September 11, a manufacturer that becomes aware of a vulnerability in its product being actively exploited must notify the authorities within 24 hours. The same applies to a severe incident that significantly affects the security of the product. According to the European Commission’s guidance, the notification clock starts once the manufacturer has a reasonable degree of certainty that exploitation or compromise has occurred.
Crucially, the obligation covers products already on the market. Legal analyses of the text, including the Jones Day guidance, note that in-scope products are captured regardless of when they were placed on the EU market. A smart doorbell shipped to European customers in 2024 sits inside the reporting perimeter from September 11 even though it was never assessed against the CRA’s design requirements.
There is one meaningful limit. Reporting is not retroactive: there is no duty to report active exploitation that a manufacturer already knew about before September 11, 2026. The obligation runs forward from the date, not backwards through the incident log.
What counts as an actively exploited vulnerability
The trigger is not the mere existence of a flaw. A vulnerability becomes reportable when there is evidence that a malicious actor has exploited it in a product without authorisation. That distinction matters operationally, because it puts the burden on detection and telemetry rather than on vulnerability scanning alone.
Severe incidents run on a parallel track. These are events that significantly affect the security of the product, which can include compromise of the manufacturer’s own development or distribution infrastructure where that compromise reaches the product. The two triggers share a timeline but not a definition.
The three-stage clock
The CRA does not ask for one report. It asks for a sequence, and each stage has its own deadline and its own content requirement. Missing the first stage cannot be cured by filing a complete report later.
| Stage | Deadline | Trigger point | What it must contain |
|---|---|---|---|
| Early warning | 24 hours | Awareness of active exploitation or severe incident | Initial flag that an event has occurred, including whether it appears to be malicious |
| Notification | 72 hours | Same awareness point | General information on the product, the nature of the exploit or incident, and any corrective measures taken or available |
| Final report (vulnerability) | 14 days after a corrective measure is available | Availability of a fix | Description of the vulnerability, severity, impact, and the corrective or mitigating measures |
| Final report (severe incident) | 1 month after the 72-hour notification | The notification itself | Description of the incident, root cause, applied mitigations |
The 24-hour window is the operationally hostile one. It runs on wall-clock time, not business hours, which means a Friday-evening detection produces a Saturday-evening deadline. Retail organisations with private-label electronics ranges rarely staff a weekend security duty rota, and that gap is the single most common readiness failure flagged in the legal commentary published this summer.
Which products and which sellers are in scope
The CRA covers “products with digital elements”, a deliberately wide category. Published scope summaries describe it as covering connected consumer devices, business hardware, mobile and desktop applications, operating systems, software libraries and components, wherever the intended or reasonably foreseeable use involves a direct or indirect data connection.
For a general merchandise retailer, that sweeps in far more than an electronics aisle. Smart bulbs, robot vacuums, connected kitchen appliances, fitness trackers, baby monitors, GPS pet collars, wifi routers, e-bike controllers and the companion apps that pair with them all sit inside the definition. So does a retailer’s own shopping app where it ships as a product rather than as a service.
The regulation sorts these into risk tiers that determine how conformity is demonstrated, and those tiers become directly relevant in December 2027 rather than this September. They matter now mainly as a map of where scrutiny will concentrate.
| Class | Conformity route | Illustrative products | Typical retail exposure |
|---|---|---|---|
| Default | Self-assessment | Most connected consumer devices | Very high: the bulk of smart home assortment |
| Important, Class I | Harmonised standards or third-party assessment | Password managers, VPNs | Low for physical retail, higher for software resellers |
| Important, Class II | Mandatory third-party assessment | Operating systems, firewalls | Low, mostly B2B and IT channel |
| Critical | Mandatory European certification | Smart meters, smart cards | Utility and payments channels, not general retail |
Scale gives the exposure its weight. Industry estimates put the number of connected devices in European households at roughly 1.2 billion by 2026, up from around 700 million in 2022, and analyst figures for the European smart home market in 2026 range from about USD 24bn to USD 36bn depending on how the category is drawn. Research cited in those forecasts places retail and e-commerce channels at close to 58% of smart home revenue, which is the share of the market that moves through the operators this regulation touches.
Where retailers and marketplaces sit in the chain
The CRA follows the standard EU product-law architecture, assigning graduated duties to manufacturers, importers and distributors. Retailers almost always occupy one of the latter two roles, and sometimes all three at once across different parts of the same assortment. Legal analyses of the text place importer duties in Article 19 and distributor duties in Article 20, with manufacturer obligations, including the reporting duties, in Articles 13 and 14.
Importers carry the heavier load. They may only place a product on the EU market after verifying that the manufacturer completed the conformity assessment, prepared the technical documentation, affixed the CE marking and supplied the required declarations and user information in a comprehensible language. Where an importer believes a product is non-compliant, it must not place it on the market until conformity is restored.
Distributors act with due care rather than verification. They must check that the CE marking is present and that the manufacturer and importer appear to have met their obligations, refrain from selling products they suspect are non-compliant, and immediately inform the manufacturer and the market surveillance authority of significant cybersecurity risks. They must also pass discovered vulnerabilities back up the chain.
This is the same enforcement logic that has been reshaping European marketplace liability more broadly, where regulators increasingly treat the platform as an accountable link rather than a neutral conduit. Our earlier analysis of how marketplace safety enforcement runs through customs data traced the same pattern from a different direction, with import records used to identify who is actually responsible for a listing.
| Role | Key article | Core CRA duty | Reporting exposure from Sept 11 |
|---|---|---|---|
| Manufacturer | Articles 13, 14 | Design, conformity, vulnerability handling | Direct: 24h / 72h / final report |
| Importer | Article 19 | Verify conformity before placing on market; retain declaration for at least 10 years | Indirect: inform manufacturer, take corrective measures, recall or withdraw |
| Distributor | Article 20 | Due care on CE marking and upstream compliance | Indirect: inform manufacturer and supervisory authority; ensure repair, recall or withdrawal |
| Own-brand seller | Treated under Articles 13, 14 | Full manufacturer obligations | Direct: the retailer files the report |
The own-brand trap
The most consequential provision for large retailers is the reclassification rule. Where an importer or distributor places a product on the market under its own name or trademark, or makes a significant modification to a product already on the market, it assumes the full obligations of a manufacturer.
That is not an edge case in European retail. Private-label connected goods are a standard margin play, from supermarket smart plugs to electronics-chain own-brand headphones and DIY-chain smart lighting. In each of those cases the retailer’s name is on the box, and from September 11 the 24-hour reporting clock is the retailer’s clock.
The practical difficulty is that the retailer typically does not build the firmware. A contract manufacturer in Asia does, which means the retailer’s ability to meet a 24-hour deadline depends entirely on a supplier contract that may say nothing about vulnerability disclosure timelines. Renegotiating those terms takes longer than the three weeks now remaining.
Where non-EU sellers land
A manufacturer outside the European Union that ships directly to EU consumers still falls inside the regulation’s scope, because the CRA attaches to placing a product on the EU market rather than to the seller’s establishment. Where no EU-established importer exists, the responsibility does not simply evaporate; it tends to migrate to whichever operator in the chain has an EU presence.
For cross-border marketplaces this creates the familiar structural problem. A platform hosting hundreds of thousands of third-party listings for connected devices has to determine, per listing, whether an accountable EU operator exists. That is the same identification problem that has driven several recent European enforcement actions against large marketplaces.
How the reporting platform is meant to work
The Commission has built the reporting flow around a single entry point rather than 27 national ones. Manufacturers submit once through the CRA Single Reporting Platform operated by ENISA, and the report is directed to the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment.
Information is made available to ENISA simultaneously, unless particularly exceptional circumstances apply. The receiving CSIRT then distributes the notification to the other CSIRTs in the territories where the product is available, which is how a single filing propagates across the internal market.
The Commission has said the platform will be operational by September 11, 2026, with functional and security testing underway through the summer. That timeline leaves very little room for a soft launch, and it is the operational dependency most likely to generate friction in the first weeks. The official reference material sits on the Commission’s CRA reporting guidance page.
For retailers acting as distributors, the platform is not the primary route. Their duty runs to the manufacturer and to the national market surveillance authority, which means they need a mapped escalation path rather than an ENISA account. Knowing which authority to contact in each member state where they sell is a prerequisite, not a detail.
What the penalties look like next to the EU’s other retail rules
The CRA’s headline sanction is administrative fines up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaches of the essential requirements and the core manufacturer obligations. Lower tiers apply to other infringements, and member states set the detailed penalty regimes within the ceilings the regulation defines.
Placed alongside the rest of the European compliance stack, the number is serious without being the largest on the board. The comparison matters because retail compliance budgets are finite and prioritisation follows expected cost.
| Regime | Maximum headline penalty | Primary target | Status |
|---|---|---|---|
| Cyber Resilience Act | EUR 15m or 2.5% of worldwide turnover | Products with digital elements | Reporting duties from Sept 11, 2026 |
| Digital Services Act | Up to 6% of worldwide turnover | Online platforms and marketplaces | In force, actively enforced |
| GDPR | EUR 20m or 4% of worldwide turnover | Personal data processing | In force since 2018 |
| EmpCo Directive (EU) 2024/825 | Up to 4% of turnover under national rules | Environmental and durability claims | Applies Sept 27, 2026 |
The DSA sets the reference point for how aggressively Brussels is prepared to price non-compliance in the commerce sector. When the Commission fined AliExpress a record sum under the Digital Services Act, as covered in our report on the EUR 550m DSA penalty over illegal goods, it established that platform-level failures on product legality carry nine-figure consequences.
Whether CRA enforcement follows a similar arc is not yet knowable. The reporting obligations start with no enforcement track record behind them, and market surveillance authorities in most member states are still building capacity. Early enforcement is more likely to look like information requests than fines.
Why the September 11 date collides with peak trading preparation
The timing is awkward for European retail. Mid-September is when assortment for the fourth quarter is locked, inventory is inbound and technology teams are under change freeze ahead of peak trading. Adding a new incident-reporting obligation in that window competes directly with revenue-critical work.
It also arrives inside an unusually dense stretch of the European regulatory calendar. Retailers have absorbed a sequence of obligations across packaging, product safety, environmental claims and platform accountability within a twelve-month span, and the CRA lands in the middle of it.
| Date | Measure | What starts |
|---|---|---|
| August 12, 2026 | Packaging and Packaging Waste Regulation | Core packaging obligations begin applying |
| August 28, 2026 | DSA Article 75 action plan deadline | Remedy plan due from a major marketplace |
| September 11, 2026 | Cyber Resilience Act | 24h / 72h vulnerability and incident reporting |
| September 27, 2026 | EmpCo Directive (EU) 2024/825 | Green claims substantiation, guarantee and durability labelling |
| December 11, 2027 | Cyber Resilience Act | Full application: design requirements, conformity, CE marking |
The packaging rules that took effect earlier this month, covered in our report on how the EU packaging regulation hit retail packaging with a PFAS ban, consumed a large share of compliance bandwidth through the first half of the year. The green claims rules arriving on September 27 will consume more.
Sixteen days after the CRA reporting date, the EmpCo Directive changes how retailers may describe products, a shift we examined in detail when the EU green claims ban was confirmed for September 27 with turnover-based fines attached. Two hard dates inside a single month is an unusual concentration.
What the readiness gap looks like right now
Most published commentary describes preparation as uneven rather than absent. Manufacturers of dedicated connected hardware, particularly larger firms already operating under NIS2 or sectoral security rules, tend to have coordinated vulnerability disclosure processes that can be adapted. The gap sits further down the chain.
Three failure modes recur in the guidance published this summer. The first is detection: a 24-hour clock that starts on awareness is meaningless without telemetry capable of producing awareness, and many consumer devices ship with limited fleet-level monitoring.
The second is contractual. Retailers with own-brand ranges depend on contract manufacturers for the underlying disclosure, and standard supply agreements rarely impose a sub-24-hour notification duty on the factory. Without that clause, the retailer’s legal obligation and its practical capability are misaligned.
The third is organisational. The obligation sits between security, legal, quality and commercial functions, and in most retail organisations no single owner exists. Legal alerts have consistently recommended naming that owner before the date rather than discovering the ambiguity during a live incident.
Legacy products are the quiet problem
Because the reporting duty covers products already placed on the market, an assortment sold three years ago and long since delisted can still generate an obligation. Retailers that treat product compliance as a launch-time exercise have no process that reaches back into discontinued ranges.
End-of-life software components compound this. A device whose firmware depends on a library that has stopped receiving security updates is more likely to produce an exploited vulnerability, and less likely to have a corrective measure available within the 14-day final-report window.
How this fits the wider European platform accountability push
The CRA is best read as one component of a broader European move to make the seller, rather than the consumer, responsible for what arrives at the door. The Digital Services Act did this for illegal content and illegal goods. The packaging and green claims rules did it for environmental representation. The CRA does it for security.
The common design is that liability follows the operator with an EU establishment and a commercial relationship with the buyer. That structure repeatedly lands on marketplaces, which is why platform obligations have been the most contested part of each regime.
The pattern is visible in current enforcement. Our coverage of how Temu faces an August 28 DSA action plan deadline after a EUR 200m risk-assessment penalty shows the Commission moving from investigation to structured remedy on a fixed timetable, which is the template CRA enforcement is likely to borrow once market surveillance authorities are resourced.
What compliance is likely to cost
No official impact figure exists for the reporting duty in isolation, and estimates circulating in vendor material should be treated with caution. The cost structure is nonetheless predictable in shape: a fixed setup component covering process design, platform access and contract amendment, plus a variable component driven by incident volume.
For a retailer with a modest own-brand connected range, the binding constraint is usually people rather than tooling. Providing genuine 24-hour coverage means either an existing security operations function that can absorb the duty or a retained external provider, and the second option prices in a way that scales poorly across small assortments.
That economics may quietly reshape private-label strategy. Where a smart plug range generates thin absolute margin, taking on manufacturer-tier reporting liability to capture it becomes harder to justify, and some retailers will conclude that selling the branded equivalent as a distributor is the better trade.
How the obligation interacts with peak-season assortment decisions
Buying teams working on 2027 ranges now face a question they did not face last cycle. A connected product carries a compliance tail that a non-connected equivalent does not, and that tail extends past the point at which the product is delisted.
The immediate effect is unlikely to be a retreat from connected goods, which remain among the faster-growing categories in European electronics retail. The more probable adjustment is consolidation toward fewer suppliers with demonstrable security processes, because supplier due diligence becomes cheaper when spread across more units.
Smaller vendors are the likely casualty. A niche manufacturer without a coordinated vulnerability disclosure process becomes a compliance risk that a large retailer must either underwrite or avoid, and avoidance is cheaper. Similar dynamics have followed each of the EU’s recent product regimes, where documentation burden favoured scale.
Retailers should expect suppliers to ask for the obligation to run the other way. Contract negotiations through the autumn will involve arguments about who absorbs the risk of a missed deadline, and the outcome will depend largely on relative bargaining power rather than on any principle in the regulation.
What retailers should have in place before September 11
The remaining window is short, which argues for triage rather than a full compliance programme. The guidance published across law-firm alerts this summer converges on a small number of concrete steps.
Determine the role, product by product
The first task is classification, not remediation. For each connected product line, establish whether the business is a manufacturer, an importer or a distributor, and flag every own-brand or significantly modified item as a manufacturer-tier obligation.
That inventory should cover discontinued ranges still in consumer hands, not just live assortment. The reporting duty does not respect a delisting date.
Build the escalation path before it is needed
Distributors need a documented route to the manufacturer and to the relevant market surveillance authority in each member state where they sell. Manufacturers and own-brand sellers need an ENISA Single Reporting Platform access path established in advance, because provisioning credentials during a 24-hour window is not viable.
Naming a single accountable owner matters more than the tooling. An incident that arrives on a Saturday needs a person, not a process document.
Fix the supplier contracts that can be fixed
Where own-brand goods are made under contract, the supply agreement needs a disclosure clause that gives the retailer notice fast enough to meet its own deadline. Renegotiating every agreement before September 11 is unrealistic, so the sensible approach is to prioritise the highest-volume connected lines.
Rehearse the 24-hour path once
A single tabletop exercise reveals more than a policy review. Running a hypothetical exploited-vulnerability scenario end to end exposes whether the detection signal exists, whether the right people can be reached outside business hours, and whether anyone actually knows how to file.
What to watch after September 11
The first observable signal will be volume. If the Single Reporting Platform receives a meaningful flow of early warnings in its opening weeks, that indicates detection capability is real and the regime is functioning as designed. Very low volume would suggest under-reporting rather than an unusually secure market.
The second is enforcement posture. Market surveillance authorities have discretion over how aggressively to pursue late or missing reports, and the first formal action, whenever it comes, will set expectations for the fifteen months before full application.
The third is contractual repricing. If retailers begin pushing 24-hour disclosure obligations into supplier agreements at scale, the cost of that risk transfer will surface in landed cost on connected goods. That is the mechanism by which a security regulation eventually reaches shelf price.
The December 11, 2027 date remains the larger event. When the CRA applies in full, connected products will need conformity assessment and CE marking against its cybersecurity requirements, which will reshape assortment rather than merely add a reporting duty. September 11 is the rehearsal.
Frequently asked questions
What exactly starts on September 11, 2026?
The Cyber Resilience Act’s reporting obligations begin to apply. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through ENISA’s Single Reporting Platform, with an early warning inside 24 hours, a fuller notification inside 72 hours, and a final report within 14 days or one month depending on the trigger.
Does the Cyber Resilience Act apply to retailers, or only to manufacturers?
Both, at different levels. The reporting duty sits with manufacturers, but importers carry verification duties under Article 19 and distributors carry due-care duties under Article 20, including an obligation to inform the manufacturer and the market surveillance authority of significant cybersecurity risks. A retailer selling connected goods under its own brand is treated as a manufacturer.
Do the rules cover products already sold before September 11?
Yes. Legal analyses of the regulation note that the reporting obligations cover in-scope products regardless of when they were placed on the EU market, including items sold well before the CRA existed. There is, however, no duty to report exploitation that was already known before September 11, 2026.
What are the penalties for failing to report?
The regulation sets administrative fines of up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaches of the essential requirements and core manufacturer obligations. Lower tiers apply to other infringements, and member states set the detailed regimes within those ceilings.
Which products count as “products with digital elements”?
Published scope summaries describe the category as covering connected consumer devices, business hardware, mobile and desktop applications, operating systems, software libraries and components, where the intended or reasonably foreseeable use involves a direct or indirect data connection. In retail terms that includes smart home devices, wearables, routers, connected appliances and companion apps.
How does a company actually file a report?
Through the CRA Single Reporting Platform operated by ENISA, which the European Commission says will be operational by September 11, 2026. A single submission is routed to the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment and made available to ENISA at the same time, with onward distribution to CSIRTs in other territories where the product is available.
What happens on December 11, 2027?
That is the date the Cyber Resilience Act applies in full. From then, products with digital elements placed on the EU market must meet the regulation’s essential cybersecurity requirements, complete the applicable conformity assessment, and carry CE marking on that basis.
Does the CRA apply to sellers based outside the EU?
The regulation attaches to placing a product on the EU market rather than to where the seller is established, so non-EU manufacturers shipping into the bloc are in scope. Where no EU-established importer exists, responsibility tends to fall on whichever operator in the distribution chain has an EU presence, which is why marketplaces face a listing-level identification problem.
How does the CRA relate to the DSA and NIS2?
They address different layers. The Digital Services Act governs platform responsibility for illegal content and goods, NIS2 governs cybersecurity of essential and important entities, and the CRA governs the security of products themselves across their lifecycle. A large marketplace selling own-brand connected devices can fall within all three.