From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents under Article 14 of the EU Cyber Resilience Act.
Once an organisation becomes aware of a reportable vulnerability or incident, the first notification may be required within 24 hours, followed by a more detailed notification within 72 hours. Being technically prepared is therefore not enough: organisations also need clear responsibilities, escalation rules, documentation and reporting workflows.
Eurofins Electrical & Electronics can help you assess your current level of readiness and strengthen the processes needed to respond within these regulatory timelines.
We review your existing vulnerability and incident reporting process to determine whether it can support the CRA Article 14 requirements and associated reporting deadlines.
We identify gaps between your current practices and the expected reporting requirements, helping you prioritise the areas that require immediate attention.
We help you clarify who must detect, assess, approve, escalate and report a vulnerability or severe security incident—including the actions to take when key decision-makers are unavailable.
We support the development or improvement of practical documentation, including reporting procedures, responsibility matrices, escalation workflows and evidence-recording templates.
We help your technical, cybersecurity, legal and communications teams understand how information should circulate internally and how reporting decisions can be made within the required timeframe.
Depending on your organisation’s needs and current level of maturity, our support may include:
Article 14 reporting obligations apply from 11 September 2026, ahead of the CRA’s broader application from 11 December 2027. Preparing now can reduce uncertainty, clarify responsibilities and help your teams respond more effectively when a reportable event occurs.
Speak with our cybersecurity experts to review your current vulnerability reporting process and identify your priority actions.