CRA Reporting Starts Today: A New Phase for Product Cybersecurity

  • Published: September 11, 2026
  • Read: 5 min
  • Source:

    Logo NXP Semiconductors

Share:

CRA Reporting Starts Today: A New Phase for Product Cybersecurity
The EU Cyber Resilience Act puts vulnerability management, reporting and coordinated response at the center of product cybersecurity. From 11 September 2026, new reporting obligations apply to manufacturers of products with digital elements. Source: NXP Semiconductors

From 11 September 2026, new reporting obligations under the EU Cyber Resilience Act, CRA, become applicable. For manufacturers of products with digital elements, this marks an important step toward more structured vulnerability management, clearer responsibilities and stronger cooperation across the technology supply chain. For the Wireless IoT ecosystem, the new requirements create a framework for improving product security throughout the entire lifecycle.

Today, 11 September 2026, marks an important milestone in the implementation of the EU Cyber Resilience Act. For manufacturers, the significance of this date is practical: once a reportable vulnerability or severe security incident becomes known, strict reporting timelines begin.

The new obligations bring more structure to vulnerability management for connected products. Cybersecurity is no longer limited to secure product design. Manufacturers also need the ability to identify, assess, communicate and respond to vulnerabilities efficiently throughout the product lifecycle.

CRA Reporting at a Glance

The CRA establishes clear timelines for reportable cases:

  • 11 September 2026: Reporting obligations for actively exploited vulnerabilities and severe security incidents begin.

  • Within 24 hours: Manufacturers must submit an early warning after becoming aware of a reportable case.

  • Within 72 hours: A more substantive vulnerability or incident notification follows.

  • Final report: For actively exploited vulnerabilities, this is required 14 days after corrective or mitigating measures become available. For severe incidents, the deadline is within one month after the initial report.

  • Customer information: Affected customers and, where appropriate, users must receive relevant information about mitigation or corrective measures.

The broader CRA framework will continue to phase in. The main obligations, including conformity assessment and CE marking requirements, become applicable from 11 December 2027.

A Stronger Framework for Wireless IoT Security

For the Wireless IoT ecosystem, the new requirements are particularly relevant.

RFID readers, wireless gateways, sensors, controllers, edge devices and other connected products increasingly combine hardware, firmware, software and communication interfaces. A vulnerability in one component can therefore have implications for a complete device or system.

The CRA places security and vulnerability management across the product lifecycle within a regulatory framework. For Wireless IoT manufacturers, this means understanding not only individual components, but also how hardware, firmware, software and connectivity interact within the finished product.

Accurate product information becomes increasingly important. SBOMs (Software Bills of Materials), product identifiers, software versions, deployment records and supplier contacts can help manufacturers determine quickly whether a newly discovered vulnerability affects a specific product or an installed system.

The result can be greater transparency and faster coordination throughout the supply chain.

How NXP’s PSIRT Supports Vulnerability Response

NXP has established a structured approach to vulnerability management at component-supplier level. The company’s Product Security Incident Response Team, PSIRT, serves as a public point of contact for potential vulnerabilities affecting NXP products. It coordinates with technical, product and security specialists to assess reported issues and support the appropriate response.

Depending on the case, this may include mitigation guidance, workarounds, software updates, customer communication or other corrective measures.

Such structures create an important bridge between component suppliers and product manufacturers. NXP assesses and handles security issues affecting its own products, while manufacturers of finished products remain responsible for evaluating the impact on their systems and fulfilling the obligations applicable to them.

For Wireless IoT, this reinforces cooperation between semiconductor suppliers, module manufacturers, device vendors and system providers.

What Product Manufacturers Should Have in Place

The start of CRA reporting makes preparation an operational advantage.

Manufacturers should already have clearly defined responsibilities for vulnerability assessment, technical investigation, regulatory reporting and customer communication. Escalation paths should be documented, and security contacts for important component and software suppliers should be readily available.

Supplier vulnerability channels should also be connected with internal security processes. Product, component and software information needs to be maintained so that potentially affected products can be identified quickly.

With a 24-hour early-warning window, these structures cannot first be created after an incident has occurred.

The objective is straightforward: when a security issue appears, the responsible teams should already know who needs to act, where the relevant information can be found and how the next steps are coordinated.

The Goal: Faster Response and More Resilient Products

The Cyber Resilience Act creates a common framework for strengthening the cybersecurity of connected products in Europe.

The goal is to identify and address vulnerabilities more effectively, improve communication between suppliers and manufacturers, and provide customers with relevant information more quickly.

For the Wireless IoT industry, this can strengthen trust in connected products and establish cybersecurity even more firmly as part of product development, deployment and long-term support.

Ultimately, the value of the CRA will not be measured simply by the number of reports submitted. Its impact will depend on whether it leads to better prepared manufacturers, stronger supplier cooperation, faster vulnerability response and more resilient connected products throughout their lifecycle.

Prepare for the next phase of the Cyber Resilience Act. NXP provides information and guidance to help product manufacturers understand CRA requirements, strengthen vulnerability-management processes and prepare connected products for long-term cybersecurity requirements.

Explore NXP’s Cyber Resilience Act resources:
https://www.nxp.com/applications/technologies/security/eu-cyber-resilience-act-cra:CYBER-RESILIENCE-ACT

For potential vulnerabilities affecting NXP products, contact the NXP Product Security Incident Response Team, PSIRT, through its public vulnerability reporting channel: https://www.nxp.com/support/support/product-security-vulnerability:PSIRT


Contact and Company information

Released by
NXP Semiconductors
Contact:
Venis Kalderon Schmölder