The Cyber Resilience Act and Digital Product Passports address different issues. Do not treat them as one obligation or assume that every business has the same deadline. Start by identifying the product, your role and the particular legal provisions that apply.
Cyber Resilience Act: reporting is a distinct milestone
The Commission states that the CRA reporting obligations apply from 11 September 2026 for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The general application date for most CRA provisions is 11 December 2027, subject to the Regulation’s specific exceptions and transitional provisions. Commission reporting guidance; Regulation (EU) 2024/2847, including Articles 14, 69 and 71.
Do not substitute that timeline for a scope assessment. Check the Regulation’s exclusions, your economic-operator role and the applicable provisions for the products concerned.
Reporting stages have different triggers
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Without undue delay, within 24 hours of becoming aware | Without undue delay, within 24 hours of becoming aware |
| Notification | Without undue delay, within 72 hours of becoming aware, unless the required information was already provided | Without undue delay, within 72 hours of becoming aware, unless the required information was already provided |
| Final report | No later than 14 days after a corrective or mitigating measure becomes available, unless the required information was already provided | Within one month after submission of the incident notification, unless the required information was already provided |
The final vulnerability-report clock is not simply 14 days after discovery. For precise content, recipients and procedural requirements, consult Article 14 and the Commission’s reporting guidance.
Digital Product Passport: check product-specific implementation
The Ecodesign for Sustainable Products Regulation creates a framework for product requirements, including Digital Product Passports. Product information requirements are developed for particular product groups or relevant horizontal measures. The Commission explains that the information needed depends on the product. This is not a single statement that every product needs a passport immediately. Commission ESPR overview and implementation information.
Identify the relevant product group, adopted measure, application date and required information. Distinguish an adopted obligation from a work-plan priority or proposal. Also investigate any separate product-specific legislation that applies to your product.
Prepare two working records, not one generic deadline
For CRA preparation, nominate a reporting owner and deputy, a way to identify when awareness occurs, an escalation route, access responsibilities and a process for recording the investigation and measures taken. Test the handover between technical, legal and operational staff.
For product-passport preparation, record the measure being monitored, affected product families, required data, where that data comes from, who can validate it and which gaps remain. Avoid purchasing a solution before confirming the requirements it needs to support.
For both records, keep the official source, the date checked and the next action. A vendor presentation, draft proposal or generic checklist should not be mistaken for the final applicable rule.
Useful next steps
Use the register tool to organise references and decisions. Use topic feeds for new or updated guidance published on this website. Those feeds are not comprehensive regulatory monitoring or an assurance that every change will be detected.
Sources checked for this editorial correction on 7 September 2026. This page is independent general guidance, not legal advice or a substitute for the full provisions.
