Policy & regulation · Sep 14
EU Cyber Resilience Act Article 14 reporting took effect September 11. What software makers must do now
The CRA is not fully applicable yet, but its incident and vulnerability reporting clock is now running for covered products.
- Treat exploit awareness as a filing trigger, not just an engineering ticket.
- Prepare templates that capture product impact, exploit details, mitigations taken, and user actions.
- Keep today’s Article 14 reporting duty separate from the full CRA obligations due later.