Gwida indipendenti dwar ir-Regolament (UE) 2024/2847 · Status: fis-seħħ
Din il-paġna hija traduzzjoni awtomatika (IA) u ma ġietx riveduta minn persuna. L-artikoli tal-blog huma disponibbli bl-Ingliż biss.
← All news
CRA Insights27 August 2026

Products You Placed on the Market Years Ago Are Covered by the 11 September 2026 Reporting Duty

Products You Placed on the Market Years Ago Are Covered by the 11 September 2026 Reporting Duty

The most common assumption we hear about the Cyber Resilience Act is that nothing really bites until 11 ta' Diċembru 2027, and that products already sold are grandfathered in. Half of that is correct. The other half is an expensive misreading, because the reporting duty in Article 14 starts on 11 ta' Settembru 2026 and reaches backwards across your whole catalogue.

Status at publication, 27 August 2026

ENISA's Il-Pjattaforma Unika ta' Rappurtar is għadha ma bdietx topera. Its public URL has not been published, the list of national CSIRTs designated as coordinators is still to come, and no reporting API is offered at this stage. ENISA has scheduled the platform to be operational by 11 ta' Settembru 2026. Everything below applies from that date regardless of when your product was sold.

Three provisions, read in order

The answer sits in three places, and only makes sense read in sequence.

  • Article 71(2) sets the dates. The CRA applies from 11 December 2027, except that Article 14 applies from 11 ta' Settembru 2026 and Chapter IV, on notified bodies, has applied since 11 June 2026.
  • L-Artikolu 69(2) is the grandfathering clause everyone remembers. Products placed on the market before 11 December 2027 are subject to the requirements of the regulation only if, from that date, they undergo a modifika sostanzjali.
  • L-Artikolu 69(3) is the sentence that undoes the comfortable reading. By way of derogation from paragraph 2, the obligations laid down in Article 14 apply to all products with digital elements falling within the scope of the regulation that were placed on the market before 11 December 2027.

There is no cut-off date in that derogation and no carve-out for age. A connected device you shipped in 2019 and have not touched since is exempt from the Annex I essential requirements and from CE marking under the CRA, and is mhux exempt from the duty to report an actively exploited vulnerability found in it.

So what is actually in scope

Article 2 defines scope as products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It then excludes several categories outright: medical devices and in vitro diagnostics, vehicle type-approval under Regulation (EU) 2019/2144, products certified under the civil aviation regulation, marine equipment under Directive 2014/90/EU, identical spare parts, and products developed exclusively for national security or defence or designed to process classified information. Everything else that connects is in. Our L-għodda ta' klassifikazzjoni walks the scope and Annex III questions in order.

What legacy products still do not owe

The distinction matters commercially. For a product placed on the market before 11 December 2027 and not substantially modified after that date, you do mhux owe the Annex I essential cybersecurity requirements, a conformity assessment, technical documentation, an EU declaration of conformity or the CE marking. Our matriċi tal-konformità sets out which obligation attaches to which product state.

The Commission's implementation FAQ goes further, and this part is worth knowing before anyone panics about old code. It accepts that a manufacturer may be unable to investigate a vulnerability in a legacy product, because build environments cannot be recreated, dependencies are unavailable, or the people who knew the codebase have left. For such products, it states, the manufacturer must notify the vulnerability or incident but is not required by the CRA to comply with the other obligations, for example those on vulnerability handling. The duty is to tell the authorities and your users what you know, not to reopen a decade-old build.

The trigger is awareness, not the product

ENISA's SRP FAQ, updated 3 August 2026, makes the boundary explicit: the obligation applies once the manufacturer becomes aware, and does not extend to active exploitation it already knew about before the reporting obligation applied. So 11 September 2026 is not a deadline to clear a backlog. It is the date after which fresh awareness starts a clock.

Once it starts, the timings are fixed: an early warning within 24 siegħa, a notification within 72 siegħa, and a final report no later than 14-il jum after a corrective measure is available for a vulnerability, or within one month of the 72-hour notification for a severe incident. Nothing pauses the filing itself. The receiving CSIRT may delay onward dissemination on cybersecurity grounds under Commission Delegated Regulation (EU) 2026/881, adopted on 11 December 2025, and Article 16(2) lets you flag sensitivity in the 72-hour notification, but that restricts who sees what, not when you file. Article 14(8) adds a separate duty to inform impacted users, and if you do not do so in a timely manner the notified CSIRTs may inform users themselves where they judge it proportionate and necessary.

What to do in the next fortnight

Build the list: every in-scope product still in users' hands, including discontinued lines and models past their support period, since the regulation draws no distinction there. Then settle who files, from which entity, and to which CSIRT under the main establishment rule in Article 14(7). Our gwida tar-rappurtar covers what each stage must contain, and the state of play page tracks what is still outstanding before 11 September.

Published 27 August 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.