Cyber Resilience Act: Reporting Obligations Enter into Force
As of 11 September 2026, the reporting obligations set out in Article 14 of Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), will become applicable. The CRA establishes a European regulatory framework aimed at ensuring a high and consistent level of cybersecurity for products with digital elements.
Although the full application of the CRA is scheduled for 11 December 2027, the reporting obligations under Article 14 will take effect on 11 September 2026. These obligations require manufacturers to notify the competent authorities of actively exploited vulnerabilities and any severe incidents resulting from them when they have an impact on security. This represents the first operational deadline introduced by the CRA for all manufacturers placing products with digital elements on the market.
AUTEC and Article 14 of the CRA
Article 14 introduces a new approach to product cybersecurity management: it is no longer sufficient to react after a problem has occurred. Instead, organizations must establish procedures, responsibilities, and communication channels in advance, before any report is received.
In this context, AUTEC has launched a compliance initiative aimed at structuring the management of cybersecurity reports and providing clear tools for customers and users. The dedicated “Cybersecurity” page serves as the central access point for the information and tools made available by AUTEC to support the responsible disclosure of vulnerabilities. The page includes:
- the information required to responsibly report vulnerabilities related to AUTEC products;
- AUTEC’s Coordinated Vulnerability Disclosure Policy;
- a dedicated vulnerability reporting form through which all required information can be submitted in a structured manner.
The contact address cybersecurity@autecsafety.com is also available for reporting vulnerabilities, incidents, or other cybersecurity-related issues concerning AUTEC products.
AUTEC recognizes the value of collaboration with the cybersecurity community and is committed to handling vulnerability reports promptly, confidentially, and impartially. Through its Coordinated Vulnerability Disclosure Policy, the company promotes responsible vulnerability disclosure and ensures the coordination of all activities necessary for the analysis, assessment, and remediation of reported vulnerabilities, with the objective of strengthening product security and protecting customers and users.
For AUTEC, the entry into force of Article 14 goes beyond establishing an external reporting channel. It also requires a structured internal process to receive, record, assess, and manage information related to cybersecurity vulnerabilities and incidents. This includes the technical analysis of reports received, the assessment of potential impacts on products, the coordination of corrective actions where necessary, and, when applicable, the notification of competent authorities within the timeframes defined by the CRA.
Conclusion
The entry into force of Article 14 represents an important step towards greater transparency in vulnerability management and contributes to strengthening the security of digital products throughout their entire lifecycle.
For manufacturers, this change is significant: the ability to promptly identify, manage, and communicate vulnerabilities in a structured manner is no longer merely a cybersecurity best practice adopted by the most forward-looking organizations. It is now a specific regulatory obligation established under European legislation.