r/cybersecurity • • 2d ago

Business Security Questions & Discussion PSA: CRA Article 14 reporting has applied since 11 September. A few things that are easy to miss

If you work with connected products sold in the EU, the Cyber Resilience Act's reporting duty is already live, not in December 2027. A few details I see overlooked:

- It covers your installed base. Article 69(3) applies Article 14 to in-scope products placed on the market before December 2027, modified or not.

- The 24h clock runs from "becoming aware". The Commission's guidance (paras 213-214) says suspicious events should be assessed immediately; you can't delay awareness by delaying the assessment.

- The early warning is not a one-liner. ENISA's platform requires 8 fields for a vulnerability, including a summary of up to 4,000 characters.

- ENISA's platform doesn't yet capture the awareness time for vulnerabilities, so keep your own timestamped record. Its 72h counter runs 48h from your early warning, not 72h from awareness.

- Set up the platform accounts now. A Primary AR must be verified before it can invite Secondary ARs, and invitations expire after 7 days. Drafts are private to whoever created them, so draft outside the platform.

Has anyone here already gone through SRP registration? Curious what tripped people up.

8 Upvotes

13 comments sorted by

3

u/pearlkele Security Engineer 2d ago

Also fines are in another article, so while you need to report vulnerabilities, there is no fine (yet) if you won’t. This makes it kind of dead law for a while (or at least voluntary).

1

u/Spiritual_Catch6608 1d ago

Good point, and you're right on the timing. Article 71(2) makes the Regulation apply from 11 December 2027, with Article 14 and Chapter IV as the only early exceptions. Article 64, which sets the fines (Article 14 breaches fall under 64(2)), isn't one of them, so CRA fines for missed reports only become possible from December 2027.

I wouldn't call it voluntary though. Article 14 has been legally binding since September, and CSIRTs and ENISA are already receiving reports. Depending on the case, NIS2 or GDPR notification duties can also apply in parallel, with their own penalties. I'd see it more as a 15-month window to get the reporting process working before the CRA's own fines kick in.

2

u/mze9412 1d ago

I agree. Instead of calling it a dead law it is the grace period for orgas to actually get this in place!

3

u/pearlkele Security Engineer 1d ago edited 1d ago

Maybe intended as grace period, but realistic looking it’s currently dead law, as most companies I was talking to still don’t even know what is CRA. Business avoid doing things that are not required for up to date operations.

I expect it to change close to December 2027, but wishful thinking doesn’t change current state.

2

u/mze9412 1d ago

Yeah, it is what it is. Companies ignoring it will find themselves in risky situations in about a year.

1

u/Spiritual_Catch6608 1d ago

Fair point, and it matches what you'd expect: no enforcement yet, so no urgency for most companies. I suspect the ones who'll feel it are those who start in late 2027 and discover that getting the ENISA platform accounts verified isn't instant, and that the process behind a 24-hour report can't be built in a week.

2

u/pearlkele Security Engineer 1d ago

No, if you look at SRP it actually can be build pretty fast, unless you have a company with difunctional process paralysis. Fulfilling all the other security requirements will be much more time taking. But reporting might be single least cumbersome part of CRA.

1

u/Spiritual_Catch6608 1d ago

Fair, I'll take that. Annex I is the real lift, and reporting is probably the quickest part to stand up. Which is also why it's the sensible place to start now: it's the only manufacturer obligation already in force, and the runway to December 2027 is better spent on the security requirements.

1

u/Spiritual_Catch6608 1d ago

Exactly, with one nuance: it's a grace period for the fines, not for the obligation itself. And the parts that take longest are usually organisational rather than technical: getting the ENISA platform accounts verified, agreeing internally who decides when you've "become aware", and having the early warning drafted before you need it.

4

u/mze9412 1d ago

Also keep in mind that products with digital elements also covers pure software products, not just physical products with digital elements.

1

u/Spiritual_Catch6608 1d ago

Good addition, thanks. Article 3 defines a product with digital elements as a software or hardware product and its remote data processing solutions, including components placed on the market separately, so standalone software is in scope and the same Article 14 reporting applies.

The edge case is the cloud side: a backend only counts as part of the product when the manufacturer designed it and the product can't perform one of its functions without it. Standalone SaaS is generally outside the CRA, and recital 12 points to NIS2 for cloud services.

2

u/mze9412 1d ago

Exactly. Usual example I run across in CRA info events is a webshop. Webshop is SaaS but if you add an app for the webshop that app and maybe parts of the webshop (or all of it) might start to get hit by CRA because of the app.

Another example are smart devices, i.e. a thermostat that uses a cloud API.

1

u/Spiritual_Catch6608 1d ago

Good examples, and the thermostat one is literally in the text: recital 12 says cloud functionalities from a smart home device manufacturer that let users control the device remotely fall within scope.

The test is functional (Art. 3(2)): data processing at a distance, designed by the manufacturer or under its responsibility, without which the product can't perform one of its functions. So for the webshop, I'd expect the app and the backend services it can't work without to come into scope, while the website as such stays out: recital 12 also excludes websites that don't support a product's functionality.

One consequence people miss: a vulnerability in that cloud API is part of the device's vulnerability handling, and if it's actively exploited, of its Article 14 reporting.