CRA Reporting in Sweden: What the 11th September 2026 Deadline Requires

CRA Reporting in Sweden The 11 September 2026 Deadline

Key Takeaways

  • Article 14 applies from 11 September 2026. The rest of the Cyber Resilience Act from 11 December 2027
  • Two events are reportable. Any actively exploited vulnerability in your product and any severe incident affecting its security
  • Three stages, not one. Early warning in 24 hours, notification in 72 hours, then a final report 14 days after a fix for a vulnerability or a month after the 72 hour notification for an incident
  • Article 69(3) extends reporting to every in-scope product placed on the EU market before 11 December 2027 and the duty outlives the support period
  • You file once through ENISA’s Single Reporting Platform, which reaches ENISA and your coordinating CSIRT at once. In Sweden that is CERT-SE, inside Nationellt cybersäkerhetscenter at Försvarets radioanstalt since 1 July 2026
  • Article 64(2) puts Article 14 in the top penalty tier, at EUR 15 million or 2.5% of worldwide annual turnover

The Date Most Manufacturers Are Planning Around Is Fifteen Months Too Late

Ask a Swedish product team when the Cyber Resilience Act starts to bite and most will say December 2027. That is right for almost everything the Regulation asks. It is wrong for the obligation that arrives first. CRA reporting in Sweden begins on 11 September 2026.

The split is in the Regulation’s own timetable. Regulation (EU) 2024/2847 entered into force on 10 December 2024 and applies from 11 December 2027 under Article 71. Article 14 is carved out fifteen months earlier.

The design work waits. The duty to notice an attack on your product and tell the authorities within 24 hours does not. Anyone selling hardware, firmware, embedded systems or software into the EU is in scope including products already in customers’ cabinets.

What is CRA Reporting and Which Dates Bind?

CRA reporting is the Article 14 duty under Regulation (EU) 2024/2847 for manufacturers of products with digital elements to notify two kinds of event through one EU platform. One is any actively exploited vulnerability in the product. The other is any severe incident affecting its security. Both reach ENISA and a national CSIRT at once.

The two triggers do not share a threshold which is where most summaries go wrong. The Article 14(5) severity test applies to incidents. For vulnerabilities there is none. Article 14(1) covers any actively exploited vulnerability which Article 3 defines as one where reliable evidence shows a malicious actor exploited it without the owner’s permission.

A high-scoring vulnerability with no evidence of exploitation is not reportable. A low-scoring one being exploited is. Under Recital 68, good-faith testing and coordinated disclosure sit outside the duty.

The Dates That Actually Matter

10 December 2024Regulation (EU) 2024/2847 in force
11 June 2026Chapter IV on notified bodies applied
11 September 2026Article 14 reporting applies, products already sold included
11 December 2027The rest applies, Article 13 and Annex I
11 June 2028Existing type-examination certificates expire

Who Must Report and For Which Products?

The duty sits with the manufacturer and follows the EU market, not the company address. A manufacturer outside the Union carries the same Article 14 duty as one in Gothenburg. Open-source stewards are drawn in under Article 24(3).

Article 69(2) brings products placed on the market before 11 December 2027 under the Regulation only if substantially modified after that date. Article 69(3) derogates from that for Article 14 alone so reporting reaches every in-scope product sold before then. A controller you shipped in 2019 and never touched again is a reporting subject.

The Commission’s guidance of 27 July 2026 confirms the duty continues after a product’s support period expires. Several summaries say the opposite and the difference is most of your installed base.

Who Carries the Reporting Duty

  • Manufacturers : Anyone placing a product with digital elements on the EU market, wherever established
  • Non-EU Manufacturers : The same duty. Routing falls to the authorised representative, then importer, then distributor
  • Open-Source Stewards : In scope under Article 24(3) and exempt from fines under Article 64(10)

Article 13 and Article 14 Are Two Deadlines, Not One

Article 13 carries the work everyone pictures when thinking of the CRA. Designing to the Annex I essential requirements due diligence on third-party components, a software bill of materials and vulnerability handling across a support period of at least five years. All of it applies from 11 December 2027.

Article 14 is only the reporting and it applies from 11 September 2026. A manufacturer can be lawful under Article 13 that month because it does not apply yet and still breach Article 14 by missing a 24 hour early warning.

Who You Notify in Sweden and How the Platform Works

You file once. Article 16 requires ENISA to run a Single Reporting Platform and a submission goes at once to ENISA and to the CSIRT designated as coordinator for your main establishment. It passes without delay to the CSIRTs in other Member States where the product is sold.

Article 14(7) settles which CSIRT is yours by where decisions about your products’ cybersecurity are predominantly taken. Manufacturers with no Union establishment follow a fixed order.

Access runs on an EU Login account which can be created in advance. There is no reporting API yet. ENISA advises against broad pre-registration since the coordinating CSIRT validates reporters after first access.

Sweden’s Reporting Route Changed on 1 July 2026

Sweden’s national CSIRT is CERT-SE. Following a government decision of 20 November 2025, the cyber operations of Myndigheten för civilt försvar (MCF, formerly MSB) transferred on 1 July 2026 to Nationellt cybersäkerhetscenter (NCSC) at Försvarets radioanstalt (FRA). An incident plan still routing to MCF names the wrong home.

Sweden has not yet legislated its complementary provisions. SOU 2025:115 proposed Post- och telestyrelsen as market surveillance authority. That does not change your position, because a Regulation applies directly.

What to Do Before, From 11 September and Ongoing

Before the date, settle what does not need the platform. Decide which CSIRT is yours and write it into the incident plan. Create the EU Login accounts. Name who decides an event is reportable, plus a deputy, because the clock can start on a Friday evening.

From 11 September the hard part is the first decision, not the form. The Commission’s July 2026 guidance sets awareness at a reasonable degree of certainty.

Article 14(8) adds a duty easy to miss. You must also inform affected users of the vulnerability or incident and any mitigation they can apply. If you do not, the notified CSIRTs may tell your customers.

The Reporting Sequence

Within 24 hoursEarly warning to your CSIRT and ENISA
Within 72 hoursNotification, initial assessment, user mitigations
Vulnerability final report14 days after a corrective measure is available
Incident final reportOne month after the 72 hour notification

The Real Risk Is a Detection Gap

Nothing in Article 14 obliges you to build monitoring. It obliges you to report what you become aware of, which is why September is harder than it looks. Annex I vulnerability handling waits until December 2027, so the duty lands first and the machinery lands second.

A manufacturer that cannot enumerate the components in a shipped product will not learn one is exploited until a customer or researcher says so. Recital 34 names checks against the European vulnerability database as component due diligence.

Recital 68 gives the incident case its own mechanism. Malicious code introduced into the channel through which a manufacturer ships security updates is a build pipeline compromise, reportable in 24 hours.

Penalties for Non-Compliance

Article 64 sets three tiers and the amount turns on which obligation was breached, not how bad the vulnerability was. Breaches of the Annex I essential requirements and of Articles 13 and 14 sit in the top tier at up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Other duties sit at EUR 10 million or 2%.

Article 64(10) holds relief narrower than usually reported. Fines do not apply to microenterprises and small enterprises that miss the 24 hour deadline or to any infringement by an open-source software steward. Read the cross-reference first, because the derogation is drafted against paragraphs 3 to 9 while the Article 14 duty sits in paragraph 2.

The Top Tier Applies to Reporting

Article 64(2) places Article 14 alongside the Annex I essential requirements at up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher. Fines can sit on top of a withdrawal or recall.

CRA and NIS2 Reporting Are Not the Same Filing

The clock shape is almost identical. Under cybersäkerhetslagen (2025:1506), in force since 15 January 2026, a NIS2 entity files an early warning within 24 hours, a notification within 72 hours and a final report within a month. The channel is Cyberportalen, opened on 1 July 2026, with NCSC through CERT-SE as recipient.

NIS2 asks about your services. The CRA asks about your product, wherever it runs and whoever owns it. NIS2 covers entities above a size threshold in listed sectors. The CRA reporting duty has none. One event can trigger both and then needs two filings in two systems.

How to Maintain Compliance and Prevent Attacks

Treat September as the point where detection stops being optional. Build the component inventory now rather than in 2027, because it turns an external tip-off into an internal alert.

Then rehearse the filing. Run a tabletop against a plausible event and time the triage decision. Record when you became aware and why, because that timestamp is what an authority will test.

The Deadline Is Fixed Even Where the Tooling Is Not

As of 2 September 2026 the Single Reporting Platform is not open and no public address has appeared on ENISA’s platform page, though the Commission states it will be operational by 11 September. That does not move the obligation. Decide who your CSIRT is and who makes the call.

Frequently Asked Questions

Does the CRA require vulnerability management from September 2026?

Not as a written obligation. Annex I vulnerability handling, including the software bill of materials, applies from 11 December 2027. But you cannot meet a 24 hour reporting clock without knowing your components and watching them, so monitoring is a September dependency.

Which national CSIRT do I report to under the CRA?

Article 14(7) decides it. Your coordinating CSIRT is the one in the Member State where decisions about your products’ cybersecurity are predominantly taken or failing that where your largest Union workforce is. ENISA will publish the list of designated coordinators.

Does CRA reporting cover products already on the market?

Yes. Article 69(3) applies the Article 14 duties to every in-scope product placed on the EU market before 11 December 2027 and the Commission’s July 2026 guidance confirms that the duty continues even after a product’s support period has ended.

What if the Single Reporting Platform is not available?

The obligation does not pause. ENISA states that the platform is scheduled to be operational by 11 September 2026 and that its public address will be published on its own platform page before go-live. Every mandatory report must go through it.

When is a manufacturer deemed aware of an exploited vulnerability?

The Commission’s guidance of 27 July 2026 sets the test as a reasonable degree of certainty that a vulnerability in the product is being actively exploited. That certainty is often reachable only after a prompt initial assessment of the evidence.

Do small Swedish manufacturers get relief on the 24 hour deadline?

Possibly, but less than is usually claimed. Article 64(10) says fines do not apply to microenterprises and small enterprises that miss the 24 hour deadline, but it is drafted as a derogation from paragraphs 3 to 9 while Article 14 sits in paragraph 2.

This post is also available in: Svenska