When Your Supplier's Flaw Becomes Your 24-Hour Problem

Since 11 September 2026, Article 14 of the Cyber Resilience Act applies to you if you place a product with digital elements on the EU market. You now have a legal duty to report actively exploited vulnerabilities and severe incidents to authorities on a fixed clock measured in hours. For an OEM this is best understood as a supply chain problem. The thing that starts your clock will often be something a supplier knows before you do.
This piece covers what the duty is and where your suppliers fit, and ends with five questions worth putting to your team.
What the duty is
There are two triggers. Either (1) a vulnerability in your product that someone is demonstrably exploiting, and/or (2) a severe incident affecting your product's security, meaning compromised confidentiality, integrity, availability or authenticity, or malicious code getting in. Article 14 then sets three deadlines, all running from the moment you become aware:
- Early warning within 24 hours
- Notification with an initial assessment within 72 hours; and
- Final report within 14 days of a corrective measure being available for vulnerabilities, or one month after the 72-hour notification for severe incidents.
Reports go simultaneously to the European Union Agency for Cybersecurity (ENISA) and to your national CSIRT, the Computer Security Incident Response Team designated as coordinator in your member state, through the Single Reporting Platform that ENISA operates.
All legacy products are in scope. Art. 69(3) applies the reporting duty to anything you placed on the EU market even before the CRA went into effect. If a vulnerability in it is actively exploited and you become aware, the same 24-hour clock runs.
Where the supply chain comes in
Art. 3(1) covers components placed on the market separately. A secure element, a microcontroller or a communications module sold to you commercially is a product in its own right, and its manufacturer carries its own Article 14 duty.
The catch is that your supplier's report does not free you from reporting obligations. The Commission's CRA guidance, adopted in July 2026, addresses this at paragraph 218: where a product contains an actively exploited vulnerability originating in an integrated component, the product manufacturer must notify it, and the component manufacturer must also notify it if that component was placed on the market. Multiple reporters can exist for one vulnerability. If exploitation from a reported component exists in your product — that is your trigger. If a supplied component carries a vulnerability that cannot be exploited in the way you have integrated it, you have no mandatory report to file; determining whether this is the case can be a demanding task within 24 hours for an engineer or procurement officer.
Art. 14(8) requires a manufacturer who becomes aware of an actively exploited vulnerability to inform impacted users, and as a customer integrating their component you have an arguable claim to be one. It attaches no numbered deadline, so notification timed in hours is something you should discuss specifying with suppliers rather than something the regulation supplies.
What to ask your team about CRA reporting
- Which of our products are in scope, including ones we have stopped shipping but still support?
- Who decides whether a component vulnerability is exploitable in our product, and how long does that decision take?
- Are we registered on the Single Reporting Platform, and which CSIRT is ours under Art. 14(7)?
- If a supplier told us at 19:00 on a Friday about a vulnerability, could we effectively evaluate its impact, and file an early warning by Saturday evening? Who signs it off?
- What do our supplier contracts actually say about notification timing, and is their obligation expressed in an exact timeframe, such as several hours?