Article 14 of the EU Cyber Resilience Act became applicable on September 11. From that date, a manufacturer whose product is available on the EU market has to report any actively exploited vulnerability it becomes aware of. An early warning is due within 24 hours, a fuller notification within 72 hours, and both are filed through a platform the EU cybersecurity agency ENISA switched on the same day.
What decides who is covered is not the license on the code. It is whether that particular version is supplied in the course of a commercial activity. The regulation defines a manufacturer as a person who develops a product with digital elements and markets it “under its name or trademark, whether for payment, monetisation or free of charge”. Commission guidance issued in July treats a paid edition and a free community edition of the same software as “different products”: the paid one is monetized and therefore placed on the market, the free one is not.
Key facts
- What must be reported: not only actively exploited vulnerabilities but severe incidents affecting the security of a product with digital elements.
- Where it goes: ENISA’s Single Reporting Platform, using the endpoint for the manufacturer’s main establishment in the EU, with a fallback order for manufacturers that have none.
- Who is covered: manufacturers supplying the EU market wherever they are based, including for products already on the market before September 11.
- Who is not, yet: open-source software stewards, whose related reporting obligations do not begin until December 11, 2027.
Twenty-Four Hours, Then Seventy-Two, Then Fourteen Days
The regulation sets a staged sequence. The early warning is due “without undue delay and in any event within 24 hours” of the manufacturer becoming aware of an actively exploited flaw. It also has to name the member states where the manufacturer knows the product was made available. A fuller vulnerability notification follows within 72 hours. A final report is due no later than 14 days after a corrective or mitigating measure is available. For severe incidents, the final report is due within a month of the 72-hour notification.
Each stage is submitted once through the Single Reporting Platform rather than separately to each national authority. ENISA built the platform under Article 16 and describes what went live on September 11 as its “initial operating capability”. The CSIRT that receives a notification passes it to the CSIRTs of other member states where the product is available, and ENISA receives it at the same time. A CSIRT may hold back that onward sharing in exceptional circumstances on justified cybersecurity grounds, and a delegated act the Commission adopted in December 2025 sets out the conditions.
Open Source Is Not the Dividing Line
The regulation sets out manufacturers and open-source software stewards as separate roles, and the July guidance is explicit that they attach to products rather than to companies. A legal person can be a manufacturer of one piece of free and open-source software and a steward of another, and the guidance says this “includes providing ‘community’ versions of the same FOSS”.
For a plugin or theme business built on the familiar pattern, the line runs through its own product line. The paid edition is monetized, so it is placed on the market and its publisher carries the manufacturer’s reporting duty. The free edition is not monetized, so on the Commission’s reading it is not placed on the market at all. Where the publisher is a legal person, the steward obligations attach to that free edition instead. Where it is an individual, the guidance puts the free edition outside the regulation altogether.
That is why the license is not the test. The same GPL code can sit on either side of the line depending on how each edition is supplied, which is the ordinary arrangement across the WordPress plugin market.
What Has Not Started Yet
Article 14 is titled “Reporting obligations of manufacturers”, and its operative text is addressed to manufacturers throughout. The word steward does not appear in it.
A separate provision, Article 24(3), extends the Article 14(1) duty on actively exploited vulnerabilities to stewards where they are involved in developing the product. Their severe-incident duty is narrower, reaching only incidents that affect the systems the steward provides for that development. That provision does not apply yet. The regulation has been in force since December 2024, but Article 24 does not become applicable until December 11, 2027. Article 14 is one of the provisions that applies earlier, from September 11, 2026. Stewards are also not subject to administrative fines for infringements of the regulation, though a market surveillance authority can still require them to take corrective action.
There is a second softening for the smallest manufacturers. The obligation applies to them in full, but those qualifying as microenterprises or small enterprises cannot be fined for missing the 24-hour deadline.
Where a fine does apply, Article 14 sits in the regulation’s top penalty tier, alongside the essential cybersecurity requirements. That tier runs to EUR 15 million, or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.
The main product-security obligations, including security by design, conformity assessment, CE marking and a mandatory software bill of materials, arrive on the same December 2027 date.
Hosting Services Are Not Automatically Products. The Software They Run Can Be.
The Commission’s guidance is explicit that a service is not automatically a product. Standalone software-as-a-service and other cloud solutions “designed and developed outside the responsibility of a manufacturer of a product with digital elements are not themselves products with digital elements”. Websites that do not support a product’s functionality are not either.
The exception is remote data processing: a service can count as part of the product where the product needs that processing to perform one of its functions and the software was designed and developed by the manufacturer, or under its responsibility. The Commission devoted a chapter of its July guidance to that test, working through infrastructure, platform and software service arrangements in turn.
A hosting company is not a manufacturer for the hosting itself. It can become one for software it develops and supplies under its own name, such as a control panel, an agent or an app, where that software otherwise falls within the regulation’s scope. And many of the control panels, backup agents, security tools and migration utilities it deploys are products supplied by manufacturers, who are now on a clock that starts the moment they learn a flaw is being exploited.
Sources
- Regulation (EU) 2024/2847, the Cyber Resilience Act - EUR-Lex (legal text)
- The CRA Single Reporting Platform is launched - ENISA
- Cyber Resilience Act - Reporting obligations - European Commission
- The Cyber Resilience Act - Summary of the legislative text - European Commission
- Cyber Resilience Act implementation - Frequently Asked Questions - European Commission
- Commission guidance on the application of Regulation (EU) 2024/2847 - European Commission