09/11/2026 | Press release | Distributed by Public on 09/11/2026 03:13
Under the EU Cyber Resilience Act, the reporting of actively exploited vulnerabilities and severe incidents becomes mandatory today, even for products already on the market. In this article, we take a look at how these new reporting duties affect manufacturers -and how Raspberry Pi can help you stay compliant.
The Cyber Resilience Act (CRA) is the EU's primary legislation focused on the cybersecurity of digital products. It places binding requirements on manufacturers of connected products sold on the EU market. Under the CRA, a specific set of reporting obligations takes effect from 11 September 2026; if you sell hardware or software into the EU, this is something to think about.
Under Article 14, manufacturers must notify ENISA about actively exploited vulnerabilities and severe security incidents according to defined reporting schedules. The type of notification and its level of detail vary depending on the incident and where you stand in the reporting window.
An actively exploited vulnerability is any weakness or flaw that has been leveraged by a malicious actor. The reporting schedule for an actively exploited vulnerability is as follows:
A severe incident is any event that negatively affects, or is capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions; or where it has led or could lead to the introduction or execution of malicious code in the product or in a user's network and information systems.
The reporting schedule for severe incidents differs slightly:
Note that this is narrower than full CRA conformity (which includes CE marking, technical documentation, and essential cybersecurity requirements), which is still due to land on 11 December 2027. The 11 September date specifically marks the day that the vulnerability and incident reporting requirement comes into force.
If you're building products with Raspberry Pi hardware and need to understand how this affects your own CRA obligations, here's where to go: