Last Updated on July 22, 2026 by Narendra Sahoo
Most compliance teams have filed the EU Cyber Resilience Act under “2027” — the date the regulation becomes fully applicable. That’s the wrong filing date. From 11 September 2026, manufacturers must already report actively exploited vulnerabilities and severe incidents affecting products with digital elements, more than a year before the rest of the regulation takes effect. This guide covers the four areas a CRA gap assessment needs to test before that clock starts — inventory, classification, documentation, and the reporting pathway itself — current as of July 2026.
|
11 Sept 2026
Article 14 reporting obligations go live — no grandfather clause
|
24 Hrs
Early-warning deadline once a qualifying event is discovered
|
€15M / 2.5%
Top fine tier — whichever of the two is higher
|
4 Tiers
Default, Important Class I & II, Critical — by function, not name
|
1️⃣ The Deadline That Arrives Before the CRA Is Even Fully in Force
A gap assessment run today has to answer a narrower, more urgent question than full CRA readiness: can this organisation detect, assess, and report a qualifying event within 24 hours, starting in September 2026? That’s a different deliverable than a multi-year compliance roadmap, and most manufacturers haven’t built it yet. The reporting clock is unforgiving once triggered — an early warning within 24 hours, a fuller notification within 72 hours, and a final report no later than fourteen days after a fix is available for vulnerabilities, or within one month for severe incidents.
💡 CRITICAL INSIGHT
These obligations apply to every in-scope product already on the EU market, including legacy products placed there long before the CRA existed. There is no grandfather clause — a product shipped in 2019 is in scope for a report filed in 2026 if it’s still in the field.
2️⃣ Build the Product Inventory First
Nothing else in a gap assessment works without an accurate product inventory. It should cover new and legacy products, software and hardware, embedded components, remote data processing solutions, supported versions, and unsupported versions still in use. Most manufacturers underestimate this step: a portfolio review frequently turns up products nobody remembers actively shipping, white-labelled variants sold under a partner’s brand, and components inherited through acquisitions that were never reassessed. A product list alone isn’t enough — manufacturers also need to identify the responsible legal entity behind each product, since which national CSIRT receives a given report depends on correctly identifying the manufacturer’s main establishment.
✅ INVENTORY CHECKLIST
| □ List every in-scope product, including legacy and unsupported versions still in the field |
| □ Flag white-labelled variants and components inherited through acquisitions |
| □ Map each product to the legal entity that qualifies as its manufacturer |
|
Not sure your product inventory is actually complete? VISTA InfoSec’s CRA compliance consultants build or validate your full product inventory and confirm which entity is the legal manufacturer for each item — before a regulator asks first. |
3️⃣ Classify Every Product Against Annex III
Once the inventory exists, every product needs a classification call: Default, Important Class I, Important Class II, or Critical, based on its core functionality rather than its name or marketing description. Skipping classification at the gap-assessment stage is the most common shortcut, and the most expensive one — the tier determines which conformity assessment module applies, which standards are relevant, and how deep the technical documentation needs to go.
Annex III and IV category definitions have been refined through 2025–26 implementing guidance — confirm current status against the latest published list before finalising a classification.
4️⃣ Importer and Distributor Obligations Under Articles 20 and 21
Article 20 sets out importers’ general obligations: confirming that the manufacturer has met the product-related essential requirements, that vulnerability-handling processes exist, that the conformity assessment was properly carried out, and that technical documentation has been drawn up before a product carries the CE marking. Article 21 covers a narrower and easily missed case — when an importer or distributor places a product under its own name or trademark, or substantially modifies a product already on the market. At that point, the importer or distributor takes on the full set of manufacturer obligations, including the Article 14 reporting duties.
👉 IN PRACTICE — A WHITE-LABEL DISTRIBUTION DEAL
A distributor rebrands a connected sensor under its own trademark for a regional market. On paper, the original OEM is still “the manufacturer.” Under Article 21, it’s the distributor’s name on the box that now carries the Article 14 reporting duty — a gap assessment that only reviews the OEM’s side of this chain leaves that distributor’s exposure completely unmapped.
5️⃣ Technical Documentation — Where the Backlog Usually Is
Technical documentation is where most gap assessments find their largest volume of unfinished work. The manufacturer must perform a cybersecurity risk assessment that informs how the essential requirements are implemented, and that risk assessment — along with the standards or measures chosen to meet those requirements — has to be part of the technical documentation itself, not held separately in someone’s inbox. Retention isn’t a minor footnote either: records must be kept for ten years or the product’s support period, whichever is longer. Organisations with an existing ISO 27001-aligned documentation practice usually find this easier — the record-keeping discipline transfers directly, even though the two frameworks serve different purposes.
Third-party components add a second layer: a manufacturer must exercise due diligence to confirm those components don’t compromise the finished product’s cybersecurity. This is where inventories fall short most often — software bills of materials are frequently incomplete or exist only for top-level dependencies, and due-diligence evidence for embedded components is often unwritten institutional knowledge rather than a documented control tied to a standard format like CycloneDX or SPDX.
✅ DOCUMENTATION CHECKLIST
| □ Confirm the risk assessment lives inside the technical file, not a separate inbox |
| □ Test whether documentation formats can survive the ten-year retention window |
| □ Build or complete an SBOM in a standard format (CycloneDX/SPDX) for every product |
| Want your documentation retention-tested before an auditor does it for you?
Book a free 40-minute consultation with VISTA InfoSec to walk through your current technical documentation against the CRA’s ten-year retention standard. |
6️⃣ Pressure-Test the Reporting Pathway Itself
Knowing the rules isn’t the same as being able to execute them under a 24-hour clock. A gap assessment should map the relevant Single Reporting Platform route: determine the manufacturer’s main establishment for Article 14(7) purposes, identify the fallback route for non-EU manufacturers, and confirm which national CSIRT acts as coordinator. ENISA has indicated the platform will be operational by 11 September 2026, with a testing period beforehand — which makes a dry run, not just a policy document, the real test of readiness.
|
T0
Event Detected
|
24 HRS
Early Warning
|
72 HRS
Notification
|
14 DAYS / 1 MO.
Final Report
|
⚠ DON’T CONFUSE THESE TWO CLOCKS
Article 14‘s reporting duties start on 11 September 2026; Article 13‘s broader process requirements for products placed on the market don’t take full effect until December 2027. A gap assessment that confuses the two risks either under-preparing for the reporting deadline or over-building processes the organisation doesn’t need yet — both are avoidable with a clear read of which article applies when.
7️⃣ Supply Chain and Contract Language
Supplier relationships are the part of a gap assessment most likely to get skipped, and they carry real exposure. Supplier contracts should be updated to reflect CRA obligations, with CRA compliance built into supplier due-diligence procedures. Suppliers of critical components that could affect a manufacturer’s ability to comply by December 2027 should be prioritised for review now. If your supply chain also touches essential or important entities under NIS2, the two due-diligence exercises overlap enough to run as one review rather than two.
|
Haven’t reviewed your supplier contracts for CRA exposure yet? VISTA InfoSec reviews supplier and OEM contracts for CRA-relevant due-diligence and notification clauses, prioritising critical-component suppliers first. |
8️⃣ The Six-Point CRA Readiness Checklist
✅ FULL READINESS CHECKLIST
| □ Inventory every in-scope product — new, legacy, supported, unsupported — and confirm the legal manufacturer for each |
| □ Classify each product as Default, Important Class I, Important Class II, or Critical |
| □ Map the Article 20/21 chain of manufacturer, importer, and distributor obligations |
| □ Audit technical documentation against the ten-year retention requirement |
| □ Dry-run the Single Reporting Platform pathway, including the 24-hour and 72-hour clocks |
| □ Review supplier contracts for CRA-relevant due-diligence and notification clauses |
9️⃣ What This Looks Like in Practice
👉 ILLUSTRATIVE EXAMPLE
A mid-sized industrial controls manufacturer assumed its CRA exposure was limited to two current product lines. A structured inventory exercise turned up eleven additional SKUs still active in distributor channels across three EU member states, including a discontinued gateway device still receiving security patches under a legacy support contract. None of the eleven had been through a classification review; two turned out to sit in Important Class I, changing which conformity route and documentation depth applied. A dry run of the reporting pathway surfaced a second, separate gap: nobody in the organisation had been assigned to actually receive and triage a Single Reporting Platform notification once one arrived. Both gaps were fixable within six weeks once identified — the expensive part wasn’t the fix, it was not knowing the gaps existed until someone looked for them.
How VISTA InfoSec Turns This Into a Tested Readiness Record
VISTA InfoSec’s CRA gap assessments follow the same practitioner-led, evidence-based methodology behind our other regulatory engagements, run in three phases:
|
1. Inventory & Classification Build or validate your product inventory and confirm classification against Annex III and IV, including legacy and white-labelled SKUs. |
2. Documentation & Reporting Dry-Run Audit technical documentation against the retention standard and rehearse the Single Reporting Platform pathway end to end. |
3. Remediation Roadmap A prioritised remediation roadmap that names owners and dates, ahead of the September 2026 reporting deadline. |
KEY TAKEAWAYS
| ✓ Article 14 reporting duties start 11 September 2026 — over a year before the CRA’s full application in December 2027 |
| ✓ There’s no grandfather clause — legacy products already on the EU market are in scope |
| ✓ Classification (Default / Important I / Important II / Critical) gates the conformity route and documentation depth |
| ✓ Article 21 obligations can shift onto an importer or distributor who rebrands or substantially modifies a product |
| ✓ A checklist isn’t evidence — a rehearsed Single Reporting Platform dry-run is what an assessor actually credits |
Frequently Asked Questions
The Bottom Line
The organisations that come through the first CRA enforcement wave cleanly are the ones treating this gap assessment as infrastructure, not paperwork: inventorying what they actually ship, classifying it honestly, and rehearsing the reporting pathway before a real vulnerability forces the question. An inventory can be built in weeks; fixing gaps found during a real incident takes a lot longer, and it happens under a 24-hour clock instead of on your own schedule.
| VISTA InfoSec • EU Cyber Resilience Act Compliance Specialists
Still Treating CRA Reporting as a 2027 Problem? The reporting clock starts 11 September 2026. VISTA InfoSec’s CRA Gap Assessment covers inventory, classification, documentation, and reporting readiness together — so you know exactly where you stand while fixing gaps is still cheap.
|
Narendra Sahoo (PCI QPA, PCI QSA, PCI SSF ASSESSOR, CISSP, CISA, CRISC, 27001 LA) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the US, Singapore & India. Mr. Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, & Compliance services. VISTA InfoSec specializes in Information Security audit, consulting and certification services which include GDPR, HIPAA, CCPA, NESA, MAS-TRM, PCI DSS Compliance & Audit, PCI PIN, SOC2 Compliance & Audit, PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry. VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.