Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

EU · Cyber Resilience Act (Reg 2024/2847)

Products with digital elements.

Applies to: Makers of products with digital elements. Built · reporting 11 Sep 2026

What the signed record shows

Vulnerability/event logging and records supporting Art 14 reporting.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Reporting platform status. Article 14 reporting starts on 11 September 2026: 24 hours for an early warning, 72 hours for the notification, 14 days for a final report on an actively exploited vulnerability, and one month for a severe incident. The ENISA Single Reporting Platform through which those reports are made is not yet live and becomes operational on 11 September 2026. ENISA updated its user registration and notification submission guidance on 3 August 2026 and its interface functions guidance on 14 August 2026.

Primary source: ENISA, Single Reporting Platform. Checked 15 August 2026.

Citation: Annex I Part II; Art 14

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements ("Cyber Resilience Act" / CRA). Provisions this mapper evidences from the per-event signed record:

Annex I, Part II
Vulnerability handling requirements (identify and document vulnerabilities and components; address and remediate without delay).
Art. 14
Reporting obligations: manufacturers must report actively exploited
vulnerabilities and severe incidents
early warning within 24 hours of becoming aware, notification within 72 hours, and a final report within 14 days (corrective measure available, for vulnerabilities) or within one month (for severe incidents). Application dates: the Art. 14 reporting obligations apply from 11 September 2026; the main obligations apply from 11 December 2027.

Taken from the Regulayer entry for this instrument, which is built against the primary text.

This is the duty on the business. For what a lawyer in Europe must disclose about using AI in a filing, see Europe: the EU AI Act, the CCBE guides, and what Germany tells its lawyers.