EU Cyber Resilience ActArticle 14applies from 11 September 2026

Are you in scope for the CRA 24-hour reporting duty, and could you actually report in time?

From 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers of products with digital elements to report an actively exploited vulnerability or a severe incident affecting product security to ENISA and their coordinating CSIRT: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report later. The clock starts at awareness, and it covers products you already shipped, not only new ones. Penalties reach €15 million or 2.5% of worldwide turnover.

This is a free 3-minute self-check. Answer honestly; it computes entirely in your browser and nothing you enter leaves your machine. It is informational, not legal advice.

1. Are you in scope?

Do you develop or manufacture a product with digital elements (software, or hardware that contains software) that is made available on the EU market under your name or trademark?
If you only use, distribute or import someone else's product, your duties differ and are narrower. This check is written for manufacturers.
Is the product still supported or on the market (i.e. not fully withdrawn and end-of-support before 11 September 2026)?
Article 14 binds products already on the market, not only new ones. There is no duty to report exploitation you already knew about before 11 September 2026.

2. Could you meet the obligation today?

Rate each capability. "Partial" means it exists but is informal, undocumented, or untested.