For UK manufacturers selling connected industrial equipment under their own name in the European Union, that alert can lead to a mandatory early warning through the Cyber Resilience Act (CRA) Single Reporting Platform. The early warning is due without undue delay and within 24 hours of awareness. A fuller notification follows within 72 hours of the same awareness point. The European Commission's current reporting page confirms both stages.
The operational risk sits in the hours between evidence becoming credible and the report reaching the platform. Product security, operations, legal, product management and the person authorised to submit may each hold part of the answer. A sequential approval route spends the same fixed clock several times.
The reporting duty arrives before the wider conformity regime
Article 14 reporting begins on 11 September 2026. Most CRA product-conformity, market-surveillance and enforcement provisions apply from 11 December 2027. The two dates govern different duties.
The early reporting duty also reaches the installed base. Article 69(3) applies Article 14 to in-scope products placed on the Union market before December 2027. The Commission's CRA implementation FAQ, updated on 4 September 2026, confirms that manufacturers must report qualifying events for those earlier products.
A UK business can be the manufacturer when it develops, commissions or integrates a product and markets it under its own name or trade mark. EU establishment is unnecessary for manufacturer status. The correct receiving Member State depends on the hierarchy in Article 14(7), including main establishment, authorised representative, importer, distributor and user location. That choice needs manufacturer-specific evidence.
Keep four timestamps separate
The first signal is the time an alert, report or piece of evidence enters the business. It should be preserved with its source, time zone, affected asset and original files.
Awareness is the legal trigger. The CRA uses that term without prescribing an internal job title or approval channel. The Commission's non-binding July 2026 guidance adds a practical interpretation: after an immediate assessment, awareness arises when the manufacturer has a reasonable degree of certainty that active exploitation or a severe product-security incident exists.
Management escalation is an internal control. It can happen before or after awareness and leaves the statutory timestamp unchanged. The manufacturer holds the duty, while an operations director may sponsor the cross-functional response.
Submission time proves when the early warning reached the platform. The platform records submission and later updates, so the receipt belongs with the evidence file.
The distinction between first signal and awareness needs care. A vague allegation may start an immediate assessment while remaining below the awareness threshold. Credible customer logs can supply enough evidence on receipt. The record should preserve both times and state why they coincide or differ.
Measure the clock budget at every handoff
The useful calculation is simple:
24 hours - elapsed time since recorded awareness = remaining early-warning clock budget
This measures operational exposure. Legal and technical evidence determine reportability.
Consider a fictional UK industrial-controller manufacturer. A customer sends credible logs at 10:00. Product security completes an immediate assessment at 12:00 and records reasonable certainty that a vulnerability in an EU-market product has been exploited maliciously.
One route holds the report for a 09:00 management meeting the next day. Twenty-one hours pass after awareness, leaving three hours for product confirmation, Member State scope, platform access, review and submission.
A parallel route records awareness at 12:00. The Assigned Representative begins the early warning, product management checks versions and EU markets, engineering protects the evidence, and legal advice addresses the remaining scope point. Submission at 15:00 uses three hours of the budget. Later facts can enter the 72-hour notification or a pre-final update.
The times are illustrative. The comparison exposes the cost of a sequential handoff using the same event and the same legal clock.
Run four work streams together
Event assessment establishes which Article 14 path may apply. An actively exploited vulnerability requires reliable evidence that a malicious actor exploited the vulnerability without the system owner's permission. A vulnerability record, public proof of concept or theoretical attack path alone does not establish that condition. A severe incident uses a different test. It can qualify through an actual or potential effect on the product's protection of important data or functions, or through the introduction or execution of malicious code. ENISA's current platform FAQ allows the malicious cause of a severe incident to be recorded as yes, no or unknown.
Product and market scoping identifies the manufacturer, product, version, component and, where available, the Member States where the product has been made available. Connected hardware, software and separately marketed components can fall within the definition of a product with digital elements. A remote service enters scope only where it meets the CRA's remote data-processing test. A component exploited elsewhere still needs product-specific evidence of exploitability in the final product.
Bounded specialist input addresses facts that can change the outcome, such as manufacturer identity in an original equipment manufacturer arrangement, the status of remote processing, component exploitability or the severe-incident threshold. The company should agree its internal triage timebox before an event. Advice then runs beside evidence preservation and filing preparation, within the legal deadline.
Filing work uses the staged design of the Single Reporting Platform (SRP). ENISA identifies fields required at 24 hours and fields that become required at 72 hours or final report. Product name and version are early fields, while mitigation, assessment and impact detail can mature. The Primary Assigned Representative owns platform administration and submission continuity can sit with named Secondary Assigned Representatives.
ENISA currently advises Assigned Representatives to hold working European Union Login accounts with multi-factor authentication, then register when a notification is needed. Validation runs in parallel and does not block the first 20 notifications while pending. A manufacturer should also identify its coordinating Computer Security Incident Response Team (CSIRT) route before an event, because choosing the wrong coordinator can invalidate the notification.
Keep your own deadline record
ENISA's launch guidance warns that its 72-hour counter is calculated as 48 hours after the early warning submission. Article 14 calculates the deadline from awareness. A late early warning therefore creates a gap between the interface timer and the legal clock.
The manufacturer's record should calculate 24-hour and 72-hour deadlines from the awareness timestamp. It should retain first signal, the immediate assessment, the awareness rationale, each platform version and every receipt. Final-report timing then splits by event: an actively exploited vulnerability runs to 14 days after a corrective or mitigating measure becomes available, while a severe incident runs to one month after the 72-hour notification.
User communication is a separate Article 14 duty. The manufacturer must inform impacted users and, where appropriate, all users about the event and measures they can take. Authority reporting and customer communication should share product and impact evidence while retaining their separate owners and records.
Use a CRA clock-control record
Open the record at the first signal and preserve the original evidence. Update it as the facts develop.
| Record | Minimum entry | Output |
|---|---|---|
| Intake | First-signal time, source, time zone and original evidence | Assessment starts with a traceable baseline |
| Awareness | Status, exact time, assessor and facts supporting reasonable certainty | 24-hour and 72-hour deadlines |
| Scope | Manufacturer, product, version, component, remote processing and, where available, Member States where the product has been made available | Current notification boundary |
| Event | Actively exploited vulnerability evidence, severe-incident evidence or essential condition absent | Immediate filing, parallel classification or monitoring route |
| Ownership | Product-security lead, operations sponsor, Primary and backup Assigned Representatives, specialist owner | Named next action for each work stream |
| Submission | Platform version, submission time, receipt and information still developing | Evidence of filing and next update |
| Review | Next evidence check, user-communication owner and escalation condition | Controlled continuation or closure |
Use the immediate filing route when the applicable manufacturer, product, Union-market and event conditions are sufficiently established. The Assigned Representative submits the staged information available and records the receipt.
Use the parallel classification route when an outcome-determinative fact remains uncertain. The product-security lead preserves the awareness basis, filing preparation continues, and the named specialist resolves the fact within the company's pre-agreed timebox and the legal deadline.
Use documented monitoring when an essential condition is positively absent. Record the evidence, owner and review trigger. New information that changes the absent condition reopens the assessment.
Assign those roles and test the handoffs before the first live alert. A short tabletop can reveal whether product records, EU market data and backup platform access are available while the full 24 hours remain.
AI disclosure: This article was generated with the assistance of AI systems and checked against cited public sources.


