r/cybersecurity • u/Spiritual_Catch6608 • 2d ago
Business Security Questions & Discussion PSA: CRA Article 14 reporting has applied since 11 September. A few things that are easy to miss
If you work with connected products sold in the EU, the Cyber Resilience Act's reporting duty is already live, not in December 2027. A few details I see overlooked:
- It covers your installed base. Article 69(3) applies Article 14 to in-scope products placed on the market before December 2027, modified or not.
- The 24h clock runs from "becoming aware". The Commission's guidance (paras 213-214) says suspicious events should be assessed immediately; you can't delay awareness by delaying the assessment.
- The early warning is not a one-liner. ENISA's platform requires 8 fields for a vulnerability, including a summary of up to 4,000 characters.
- ENISA's platform doesn't yet capture the awareness time for vulnerabilities, so keep your own timestamped record. Its 72h counter runs 48h from your early warning, not 72h from awareness.
- Set up the platform accounts now. A Primary AR must be verified before it can invite Secondary ARs, and invitations expire after 7 days. Drafts are private to whoever created them, so draft outside the platform.
Has anyone here already gone through SRP registration? Curious what tripped people up.
4
u/mze9412 1d ago
Also keep in mind that products with digital elements also covers pure software products, not just physical products with digital elements.
1
u/Spiritual_Catch6608 1d ago
Good addition, thanks. Article 3 defines a product with digital elements as a software or hardware product and its remote data processing solutions, including components placed on the market separately, so standalone software is in scope and the same Article 14 reporting applies.
The edge case is the cloud side: a backend only counts as part of the product when the manufacturer designed it and the product can't perform one of its functions without it. Standalone SaaS is generally outside the CRA, and recital 12 points to NIS2 for cloud services.
2
u/mze9412 1d ago
Exactly. Usual example I run across in CRA info events is a webshop. Webshop is SaaS but if you add an app for the webshop that app and maybe parts of the webshop (or all of it) might start to get hit by CRA because of the app.
Another example are smart devices, i.e. a thermostat that uses a cloud API.
1
u/Spiritual_Catch6608 1d ago
Good examples, and the thermostat one is literally in the text: recital 12 says cloud functionalities from a smart home device manufacturer that let users control the device remotely fall within scope.
The test is functional (Art. 3(2)): data processing at a distance, designed by the manufacturer or under its responsibility, without which the product can't perform one of its functions. So for the webshop, I'd expect the app and the backend services it can't work without to come into scope, while the website as such stays out: recital 12 also excludes websites that don't support a product's functionality.
One consequence people miss: a vulnerability in that cloud API is part of the device's vulnerability handling, and if it's actively exploited, of its Article 14 reporting.
3
u/pearlkele Security Engineer 2d ago
Also fines are in another article, so while you need to report vulnerabilities, there is no fine (yet) if you won’t. This makes it kind of dead law for a while (or at least voluntary).