CRA reporting obligations under Article 14 of the EU Cyber Resilience Act took effect September 11, 2026, and most IIoT vendors had their compliance timeline pointed at the wrong date. Any manufacturer of a digital-element product sold into the EU — PLCs, gateways, sensors, connected machinery already shipped — now has 24 hours to file an early warning after learning of active exploitation, and 72 hours for a full notification. The duty is retroactive, penalties run to €15 million or 2.5% of global turnover, and full CRA product compliance doesn’t arrive until December 2027, which is exactly why most teams assumed they had more runway.
Most compliance calendars at industrial IoT companies have one CRA date circled: December 11, 2027, when full product requirements and CE marking become mandatory. But the CRA reporting obligations arrived first, on September 11, 2026, and already apply to hardware sitting in factories and warehouses today. A manufacturer that learns of an actively exploited vulnerability in a gateway shipped in 2019 is on the same 24-hour clock as one shipping a new sensor next quarter.
The CRA entered into force in December 2024, and most compliance briefs since have treated 2027 as the date that matters. Legal trackers at Jones Day and the National Law Review flag the same pattern: teams treat reporting as a footnote to the bigger conformity deadline, when it’s actually the first bill coming due. The CRA reporting obligations don’t wait for a redesign or a certification cycle — they apply the day a company learns of active exploitation, on equipment shipped years before the rule existed.