Skip to content

Cyber security

Vulnerability management under the Cyber Resilience Act: What manufacturers need to know and implement now

From 11 September, manufacturers must report any vulnerabilities they discover to the EU agency ENISA within 24 hours – including details of the measures taken to rectify them.

Technische Fachkraft arbeitet an einem geöffneten Schaltschrank in einer elektrischen Industrieanlage mit Schalt- und Verteilungstechnik im Außenbereich.

New reporting requirements for manufacturers of digital products from 11 September 2026

Under the EU’s Cyber Resilience Act (CRA), new reporting obligations for manufacturers of digitally connected products will come into force on 11 September 2026. From this date, manufacturers must report vulnerabilities discovered in products to the European Union Agency for Cybersecurity (ENISA) within 24 hours – including details of the affected products, the nature and severity of the vulnerability, and the measures taken to remedy it. ENISA will compile these reports and make them publicly available. Entries will remain visible indefinitely and may lead to reputational risks if a company is listed repeatedly.

Why have the requirements for vulnerability management been tightened?

The new requirements aim to strengthen cyber security throughout the entire supply chain and to establish standardised, traceable processes for managing vulnerabilities. Until now, manufacturers have been able to respond to detected vulnerabilities at their own discretion and without fixed deadlines. The CRA now creates a binding, transparent framework that also covers responsibility for purchased components and software.

Who is subject to the reporting obligation?

The reporting obligation applies to all manufacturers who place digital products with networked components on the market – ranging from consumer goods such as vacuum cleaners, fridges or cycle computers with Bluetooth interfaces to industrial machinery and safety-critical sensor technology. Products containing purchased software or hardware components are also affected. The key factor is that the product falls within the scope of the CRA.

What needs to be reported?

If a vulnerability is discovered, the following information must be submitted to ENISA within 24 hours:

  • Description of the vulnerability
  • Affected products and versions
  • Assessment of severity and potential impact (risk assessment)
  • Measures already taken or planned to address the issue

The vulnerability must also be reported if where it lies in a component purchased from a third party and incorporated into the company’s own product.

What are the potential consequences of non-compliance?

If vulnerabilities are not reported within the specified timeframe or are not adequately addressed, organisations face substantial fines of up to 15 million euros or 2.5 percent of their global annual turnover. In addition, permanent public listing on the ENISA website can result in significant reputational damage.

What exactly will change for manufacturers?

  • Proactive vulnerability management: Manufacturers must continuously monitor whether vulnerabilities arise in their own or third-party components. A reactive approach is no longer sufficient
  • Clear responsibilities: A coordination role is required within the organisation to manage vulnerabilities and ensure compliance with reporting obligations
  • Structured processes: Manufacturers require a documented vulnerability management system that covers the identification, assessment, handling and reporting of vulnerabilities – including arrangements for deputisation and clear lines of responsibility
  • Integration into existing management systems: A management system certified according to the ISO/IEC 27001 or IEC 62443-4-1 standards provides a sound basis, but must be supplemented to meet the specific requirements of the CRA (for example, the 24-hour deadline and the reporting procedure to ENISA)

How can manufacturers prepare?

  • Review processes and responsibilities: Existing processes for vulnerability management and incident response should be reviewed to identify any gaps in relation to the CRA requirements and adjusted accordingly
  • Strengthening asset and supplier management: A comprehensive overview of all components and suppliers used is essential for quickly identifying and pinpointing vulnerabilities and taking remedial action
  • Assessment by an independent third party: An external assessment carried out by TÜV NORD helps to evaluate the effectiveness of the processes and identify areas for improvement. Until the official introduction of harmonised standards, companies will receive a detailed audit report as evidence – an official certificate will only be available from December 2027

What should manufacturers pay particular attention to?

There is little time left before the reporting obligation comes into force. Organisations that have not yet established the necessary processes should act immediately.

The requirements also apply to small and medium-sized enterprises and may lead to significant resource constraints for them.

Different assessment providers may currently prioritise different areas, as no final standard has yet been published. The harmonised standards announced by ENISA provide guidance.

Expertise and support from TÜV NORD

TÜV NORD has decades of experience and expertise in the testing and certification of cybersecurity-related processes and products. Around 70 specialists – over 40 of whom are based in Germany – support manufacturers in assessing and further developing their vulnerability management processes.

Conclusion

Under the Cyber Resilience Act, vulnerability management will become a mandatory requirement for manufacturers of digital products and a key competitive factor. Those who take action now will not only ensure their own compliance, but also safeguard their reputation and market position, whilst mitigating financial risks.

A portrait of a person wearing a dark jacket and a white shirt against a light background.
About Matthias Springer

Matthias Springer is Senior Vice President of Functional Safety & Security at TÜV NORD. Photo: Frauke Schumann/TÜV NORD AG

#explore – TÜV NORD’s online magazine

This is an article from #explore. #explore is a digital journey of discovery into a world that is changing at a rapid pace. Increasing connectivity, innovative technologies and the all-encompassing digitalisation are creating new possibilities and turning the familiar upside down. But this also harbours dangers and risks: #explore shows a safe way through the connected world.