{"id":33934,"date":"2026-08-13T09:00:00","date_gmt":"2026-08-13T07:00:00","guid":{"rendered":"https:\/\/www.digital-chiefs.de\/?p=33934"},"modified":"2026-08-18T17:22:33","modified_gmt":"2026-08-18T15:22:33","slug":"cra-forces-manufacturers-to-report-within-24-hours","status":"publish","type":"post","link":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/","title":{"rendered":"CRA forces manufacturers to report within 24 hours"},"content":{"rendered":"<p style=\"display:inline-block;background:#d65663;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">9 min read<\/p>\n<p><strong>On 11 September 2026, Article 14 of the Cyber Resilience Act comes into force.<\/strong> From that date, manufacturers must report actively exploited vulnerabilities and serious security incidents within fixed deadlines. For CIOs and CDOs, the real message is in procurement: the reporting obligation applies to the manufacturer. Organisations that source products from manufacturers whose processes are not yet in place will learn about an actively exploited vulnerability in their own environment too late-or not at all.<\/p>\n<div style=\"background:#f6f1e6;border-left:4px solid #d65663;border-radius:0 8px 8px 0;padding:22px 26px;margin:28px 0 34px;\">\n<p style=\"margin:0 0 14px 0;font-size:0.76em;font-weight:700;text-transform:uppercase;letter-spacing:0.16em;color:#c0414e;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:#23303f;line-height:1.6;\">\n<li style=\"margin-bottom:10px;\"><strong>Reporting obligation from 11 September 2026:<\/strong> Article 14 of the CRA applies from this date to manufacturers; the operator organisation is not subject to this reporting obligation.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>24 and 72 hours only for manufacturers:<\/strong> Early warnings and follow-up reports apply to the manufacturer, who must report to the coordinating CSIRT and ENISA.<\/li>\n<li><strong>Contracts need substance:<\/strong> Evidence, reporting channels, updates and a defined end-of-support replace a general assurance of compliance.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#0d1b2a;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.digital-chiefs.de\/en\/why-your-cloud-bill-never-gets-smaller\/\" style=\"color:#333;text-decoration:underline;\">Why Your Cloud Bill Never Gets Smaller<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.digital-chiefs.de\/en\/ai-regulation-up-to-3-percent-of-corporate-revenue\/\" style=\"color:#333;text-decoration:underline;\">AI Regulation: Up to 3 Percent of Corporate Revenue<\/a><\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">Four Weeks Until Article 14: Procurement\u2019s Position<\/h2>\n<p>The Cyber Resilience Act entered into force on 10 December 2024. The main obligations take effect on 11 December 2027. In between lies the deadline that is now occupying operations: Article 14 kicks in on 11 September 2026. In larger organisations, CIOs, CDOs and IT strategists control budgets, supplier relationships and architectural decisions. It is precisely here that the impact of the reporting obligation lands-even though the organisation itself is generally not subject to the reporting obligation.<\/p>\n<p><strong>What is the Cyber Resilience Act?<\/strong> The Cyber Resilience Act is an EU legal framework for the cybersecurity of products with digital elements. It obliges manufacturers to meet security requirements throughout the product lifecycle and to report actively exploited vulnerabilities and serious security incidents. The CRA entered into force on 10 December 2024. Article 14 applies from 11 September 2026, with the main obligations taking effect on 11 December 2027.<\/p>\n<p>For the CIO, the assignment of obligations is the central message. The reporting obligation falls on the manufacturer. The operator purchases products that run in networks, controls and specialist applications. If the manufacturer does not have its reporting and information channels under control, the operator lacks timely information about actively exploited vulnerabilities in its own environment. The action perspective therefore lies in contracts, supplier discussions and supply-chain governance.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">Who Reports, Where, and for What the Manufacturer is Liable<\/h2>\n<p>Manufacturers must report simultaneously to the coordinating CSIRT and to ENISA. A joint reporting platform is provided for this purpose. Technical details of this platform have not yet been publicly clarified. For operational purposes, the process within the supply relationship is key: the manufacturer remains the addressee of the reporting obligation and the point of contact for the buyer.<\/p>\n<p>The responsibility does not end at the manufacturer\u2019s bill of materials. The manufacturer remains accountable for the entire component, even if it sources parts externally. The deadlines of 24 and 72 hours apply to the manufacturer. They do not automatically apply to every supplier in the chain. If you, as a CIO, manage a multi-tier supply chain, you must clarify how information flows from sub-suppliers to the manufacturer and from the manufacturer into your own operations.<\/p>\n<p>Even the end of support only partially alters the allocation of responsibility. When a component reaches end-of-support, the manufacturer remains responsible for vulnerability remediation for at least five years. For architectures with long operational lifespans, this means: a product that falls out of active support does not fall out of the manufacturer\u2019s security responsibility. This timeframe must be factored into procurement decisions when evaluating product lifecycle and replacement strategy.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">Deadlines, Reporting Content, and Sanctions<\/h2>\n<p>Article 14 distinguishes between two scenarios: actively exploited vulnerabilities and severe security incidents. Both paths begin with an early warning within 24 hours. These deadlines apply to the manufacturer. For operators, these tight timelines do not constitute a separate statutory reporting obligation under Article 14, but they do set the pace at which information must circulate within the manufacturer\u2019s ecosystem if your own infrastructure is affected.<\/p>\n<p>For actively exploited vulnerabilities, additional information must follow within 72 hours, and a final report within 14 days of a corrective measure becoming available. For severe security incidents, the incident report must be filed within 72 hours, and the final report within one month of the incident report. If you, as a CIO, discuss incident and vulnerability processes with manufacturers, these stages form the baseline for the conversation: when does the customer learn of the early warning, when of the follow-up report, and when of the corrective action?<\/p>\n<div data-element=\"comparison_table\" style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;margin:16px 0 32px 0;\">\n<table style=\"width:100%;min-width:560px;border-collapse:collapse;font-size:0.95em;line-height:1.5;\">\n<thead>\n<tr>\n<th scope=\"col\" style=\"background:#f6f1e6;color:#0d1b2a;-webkit-text-fill-color:#0d1b2a;font-weight:600;text-align:left;padding:10px 14px;border-bottom:2px solid #d65663;font-size:0.85em;text-transform:uppercase;letter-spacing:0.04em;\">Deadline<\/th>\n<th scope=\"col\" style=\"background:#f6f1e6;color:#0d1b2a;-webkit-text-fill-color:#0d1b2a;font-weight:600;text-align:left;padding:10px 14px;border-bottom:2px solid #d65663;font-size:0.85em;text-transform:uppercase;letter-spacing:0.04em;\">What applies<\/th>\n<th scope=\"col\" style=\"background:#f6f1e6;color:#0d1b2a;-webkit-text-fill-color:#0d1b2a;font-weight:600;text-align:left;padding:10px 14px;border-bottom:2px solid #d65663;font-size:0.85em;text-transform:uppercase;letter-spacing:0.04em;\">To whom<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">10 December 2024<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Cyber Resilience Act enters into force<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers and other CRA addressees<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">11 September 2026<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Article 14: Reporting obligations for actively exploited vulnerabilities and severe security incidents<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers as reporting entities<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Within 24 hours<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Early warning for actively exploited vulnerability or severe security incident<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers, reporting to coordinating CSIRT and ENISA<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Within 72 hours<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Additional information for vulnerabilities or incident report for severe security incidents<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Within 14 days after availability of a corrective measure<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Final report for actively exploited vulnerability<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Within one month after the incident report<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Final report for severe security incident<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">11 December 2027<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Main obligations of the CRA take effect<\/td>\n<td style=\"padding:10px 14px;vertical-align:top;border-bottom:1px solid rgba(13,27,42,0.15);color:#0d1b2a;\">Manufacturers and other CRA addressees<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>The CRA provides for fines of up to \u20ac15 million or 2.5 percent of global annual turnover. The sanction applies to the entity subject to the obligation-in the reporting logic of Article 14, this is the manufacturer. For the purchasing CIO, the potential fine height shifts the balance of negotiation power: a manufacturer with unclear processes carries regulatory risk that translates into delivery, delay, and information risks within the supply relationship. Predictions about enforcement practices by authorities should not be factored into planning, as they are not substantiated. What is substantiated are the deadlines, the addressees, and the sanction framework.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">What now belongs in contracts and supplier discussions<\/h2>\n<p>General assurances of legal compliance are not enough. Supplier contracts must include evidence, reporting channels, updates, and a defined end of support. These points are documented as requirements. There are no official template texts for specific contract clauses. Procurement, legal, and security teams must translate these requirements into their own contractual language and apply them to existing supplier relationships.<\/p>\n<p>Evidence must clarify whether the manufacturer actually controls its CRA-relevant processes. Reporting channels must specify how the operator learns about an actively exploited vulnerability and who internally receives the information. Updates must define how corrective measures are provided and documented. A defined end of support clarifies when active support ends and how the at least five-year responsibility for vulnerability remediation after support ends is reflected in the relationship.<\/p>\n<p>In supplier discussions, a simple audit framework is useful. Who at the manufacturer is responsible for reporting to the coordinating CSIRT and ENISA? How does the information reach the customer channel in parallel? Which sub-suppliers are part of the overall component for which the manufacturer remains responsible? How long does support run, and how is the remediation obligation organized afterward? These questions remain within the scope of the documented requirements and avoid speculation about regulatory practices or implementation costs.<\/p>\n<p>Architectural decisions hinge on the same points. Products with unclear end-of-support, vague update paths, or missing reporting channels increase operational risk. Article 14 obliges the manufacturer to report actively exploited vulnerabilities and severe incidents to the coordinating CSIRT and ENISA. Affected users must also be informed in parallel. End of support and update paths are governed by other parts of the CRA. The CIO manages risk through selection, contract design, and escalation paths, even though the legal reporting obligation lies with the manufacturer.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">The counterpoint: Burden on small and medium-sized manufacturers<\/h2>\n<p>The DIHK warns of significant burdens on small and medium-sized enterprises due to CRA implementation. Many smaller manufacturers are unsure whether the CRA even applies to them. Some are considering withdrawing products from the market. For the CIO, this is not an abstract report on the middle market-it\u2019s a procurement problem as soon as a niche supplier exits or streamlines its portfolio.<\/p>\n<p>Larger organizations often rely on specialized components: control modules, sensors, industry-specific software, embedded systems. If a small manufacturer deems CRA obligations too onerous and discontinues a product, replacements, expertise, and migration paths disappear. The proactive approach lies in identifying critical niche suppliers early, verifying their CRA readiness, and preparing alternatives or transition strategies.<\/p>\n<p>This counterpoint therefore belongs in every supplier discussion with smaller providers. The key question is whether the manufacturer can meet the reporting and security requirements by September 11, 2026, and the main obligations from December 11, 2027. If the answer remains unclear, the risk of product discontinuation rises. The operator then bears the consequences in architecture and operational continuity, even if it itself is outside the reporting obligation.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">Alignment with BSI TR-03183 and Next Steps<\/h2>\n<p>The BSI technical guideline TR-03183 consolidates requirements across three parts: general requirements, software bill of materials, and vulnerability reporting. Parts 1 and 3 are available in version 1.0.0, while Part 2 is at version 2.1.0. The initial comment period closed on 30 November 2024. Since then, the BSI has treated Part 1 as a living document, and Part 3 was released in September 2025. Versions 0.9.0 and 2.0.0 are archived.<\/p>\n<p>For CIOs and IT strategists, the guideline serves as a reference framework when engaging with manufacturers supplying products that include digital elements. General requirements, software bill of materials, and vulnerability reporting define the core topics around which evidence and processes should be structured. Understanding the version statuses helps avoid misaligned expectations: all three parts are now finalized, with Part 1 continuously updated as a living document.<\/p>\n<p>The coming weeks-up to 11 September 2026-are ideal for targeted supplier engagement. Prioritize products with high operational relevance and long lifecycles. Request evidence, reporting channels, update commitments, and a defined end-of-support date. Clarify roles across the supply chain, as the 24- and 72-hour deadlines apply directly to manufacturers, who remain accountable for the entire component. Monitor smaller suppliers for signs of product discontinuation to mitigate risk before Article 14 takes effect and before the next compliance milestone on 11 December 2027.<\/p>\n<h2 style=\"margin-top:32px;margin-bottom:16px;\">Frequently Asked Questions<\/h2>\n<details style=\"background:#f9f9f9;padding:16px 20px;margin:12px 0;border-radius:4px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#1a1a2e;\">Who is subject to the reporting obligation under Article 14 from 11 September 2026 onwards?<\/summary>\n<p>The reporting obligation applies to the manufacturer. The operator is not covered by this obligation under Article 14. However, the impact remains significant for CIOs, as they purchase products from manufacturers subject to reporting and rely on their information channels.<\/p>\n<\/details>\n<details style=\"background:#f9f9f9;padding:16px 20px;margin:12px 0;border-radius:4px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#1a1a2e;\">Do the 24-hour and 72-hour deadlines also apply to every supplier in the chain?<\/summary>\n<p>No. The 24-hour and 72-hour deadlines apply to the manufacturer. They do not automatically apply to every supplier in the chain. The manufacturer remains responsible for the entire component, even if it sources parts externally.<\/p>\n<\/details>\n<details style=\"background:#f9f9f9;padding:16px 20px;margin:12px 0;border-radius:4px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#1a1a2e;\">Where must manufacturers report, and what are the specific deadlines?<\/summary>\n<p>Manufacturers report simultaneously to the coordinating CSIRT and to ENISA via a joint reporting platform. For actively exploited vulnerabilities, early warnings must be issued within 24 hours, further information within 72 hours, and a final report within 14 days of a corrective measure becoming available. For severe security incidents, early warnings must be issued within 24 hours, incident reports within 72 hours, and a final report within one month of the incident report.<\/p>\n<\/details>\n<details style=\"background:#f9f9f9;padding:16px 20px;margin:12px 0;border-radius:4px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#1a1a2e;\">What should supplier contracts include to ensure operational security?<\/summary>\n<p>Contracts should include evidence, reporting channels, updates, and a defined end of support. A general assurance of compliance is not sufficient. There are no official standard clauses. Even after support ends, the manufacturer remains responsible for addressing vulnerabilities for at least five years.<\/p>\n<\/details>\n<details style=\"background:#f9f9f9;padding:16px 20px;margin:12px 0;border-radius:4px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#1a1a2e;\">Why do smaller manufacturers pose a risk to procurement despite the CRA focusing on manufacturer obligations?<\/summary>\n<p>The DIHK warns of significant burdens on small and medium-sized enterprises due to CRA implementation. Many smaller manufacturers are unsure whether the CRA applies to them. Some are considering withdrawing products from the market. A CIO whose niche supplier exits then faces procurement and migration challenges within their own infrastructure.<\/p>\n<\/details>\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/08\/03\/google-sovereign-cloud-deutschland-thales-betreiber-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Thales subsidiary to operate Google\u2019s Sovereign Cloud<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/art-50-ki-vo-was-betreiber-ab-august-2026-tun\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Article 50 AI Act: What operators must do from August 2026<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #69d8ed;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#69d8ed;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">securitytoday<\/div>\n<p><a href=\"https:\/\/www.securitytoday.de\/2026\/08\/02\/bod-26-04-kev-und-epss-richtig-priorisieren\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">KEV under BOD 26-04 \u2013 EPSS prioritises the rest<\/a><\/p>\n<\/div>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;\"><em>Image source: AI-generated (August 2026)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.<\/p>\n","protected":false},"author":47,"featured_media":33874,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"\"CRA\" is an acronym, so I need to figure out what it stands for. In the context of SEO, CRA could stand for","_yoast_wpseo_title":"CRA reporting: manufacturers have 24 hours","_yoast_wpseo_metadesc":"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"featured_post_sortierung":0,"featured_post":0,"pre_headline":"","bildquelle":"","teasertext":"","language":"de","_evm_slot_owner":"","_evm_translation_lang":"","_wp_old_slug":["cra-is-likely-an-acronym-maybe-a-regulatory-body-i-should-check-if-its-known-in"],"footnotes":""},"categories":[7,678],"tags":[],"class_list":{"0":"post-33934","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","6":"hentry","7":"category-cyber-security","9":"entry"},"wpml_language":"en","wpml_translation_of":33871,"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CRA reporting: manufacturers have 24 hours<\/title>\n<meta name=\"description\" content=\"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CRA reporting: manufacturers have 24 hours\" \/>\n<meta property=\"og:description\" content=\"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\" \/>\n<meta property=\"og:site_name\" content=\"Digital Chiefs\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/digitalchiefs\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-13T07:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T15:22:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Bernhard Liebl\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@digital_chiefs\" \/>\n<meta name=\"twitter:site\" content=\"@digital_chiefs\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bernhard Liebl\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\"},\"author\":{\"name\":\"Bernhard Liebl\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/person\/6420de0b227b38e6859e2347ff5ed9ee\"},\"headline\":\"CRA forces manufacturers to report within 24 hours\",\"datePublished\":\"2026-08-13T07:00:00+00:00\",\"dateModified\":\"2026-08-18T15:22:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\"},\"wordCount\":1977,\"publisher\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg\",\"articleSection\":[\"Cyber Security\",\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\",\"url\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\",\"name\":\"CRA reporting: manufacturers have 24 hours\",\"isPartOf\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg\",\"datePublished\":\"2026-08-13T07:00:00+00:00\",\"dateModified\":\"2026-08-18T15:22:33+00:00\",\"description\":\"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage\",\"url\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg\",\"contentUrl\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg\",\"width\":1280,\"height\":720,\"caption\":\"Fast leere Sanduhr auf hellem Hintergrund.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\/\/www.digital-chiefs.de\/en\/home\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CRA forces manufacturers to report within 24 hours\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#website\",\"url\":\"https:\/\/www.digital-chiefs.de\/en\/\",\"name\":\"Digital Chiefs\",\"description\":\"Architekten des digitalen Deutschlands\",\"publisher\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.digital-chiefs.de\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#organization\",\"name\":\"Digital Chiefs\",\"url\":\"https:\/\/www.digital-chiefs.de\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2020\/05\/cropped-digital-chiefs-logo-klein.jpg\",\"contentUrl\":\"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2020\/05\/cropped-digital-chiefs-logo-klein.jpg\",\"width\":190,\"height\":190,\"caption\":\"Digital Chiefs\"},\"image\":{\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/digitalchiefs\/\",\"https:\/\/x.com\/digital_chiefs\",\"https:\/\/www.linkedin.com\/company\/digital-chiefs\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/person\/6420de0b227b38e6859e2347ff5ed9ee\",\"name\":\"Bernhard Liebl\",\"description\":\"Bernhard Liebl is an author and Co-Founder & CEO of planeed, a SaaS platform for Semantic Brand Architecture. He addresses the question of how brand knowledge can be structured, linked and made understandable and retrievable for search and AI systems. Drawing on his many years of experience in digital strategy and marketing, he writes for Digital Chiefs about AI Visibility, Generative Engine Optimization (GEO) and the question of which structural decisions support digital brand management in AI systems.\",\"url\":\"https:\/\/www.digital-chiefs.de\/en\/author\/bernhard-liebl\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CRA reporting: manufacturers have 24 hours","description":"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/","og_locale":"en_US","og_type":"article","og_title":"CRA reporting: manufacturers have 24 hours","og_description":"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.","og_url":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/","og_site_name":"Digital Chiefs","article_publisher":"https:\/\/www.facebook.com\/digitalchiefs\/","article_published_time":"2026-08-13T07:00:00+00:00","article_modified_time":"2026-08-18T15:22:33+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg","type":"image\/jpeg"}],"author":"Bernhard Liebl","twitter_card":"summary_large_image","twitter_creator":"@digital_chiefs","twitter_site":"@digital_chiefs","twitter_misc":{"Written by":"Bernhard Liebl","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#article","isPartOf":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/"},"author":{"name":"Bernhard Liebl","@id":"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/person\/6420de0b227b38e6859e2347ff5ed9ee"},"headline":"CRA forces manufacturers to report within 24 hours","datePublished":"2026-08-13T07:00:00+00:00","dateModified":"2026-08-18T15:22:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/"},"wordCount":1977,"publisher":{"@id":"https:\/\/www.digital-chiefs.de\/en\/#organization"},"image":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg","articleSection":["Cyber Security","Cyber Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/","url":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/","name":"CRA reporting: manufacturers have 24 hours","isPartOf":{"@id":"https:\/\/www.digital-chiefs.de\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage"},"image":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage"},"thumbnailUrl":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg","datePublished":"2026-08-13T07:00:00+00:00","dateModified":"2026-08-18T15:22:33+00:00","description":"CRA reporting duties start 11 September 2026. They hit manufacturers, not operators. What belongs in supplier contracts before the deadline.","breadcrumb":{"@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#primaryimage","url":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg","contentUrl":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2026\/08\/cra-meldepflichten-lieferanten-cio-september-2026-cover-hero.jpg","width":1280,"height":720,"caption":"Fast leere Sanduhr auf hellem Hintergrund."},{"@type":"BreadcrumbList","@id":"https:\/\/www.digital-chiefs.de\/en\/cra-forces-manufacturers-to-report-within-24-hours\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.digital-chiefs.de\/en\/home\/"},{"@type":"ListItem","position":2,"name":"CRA forces manufacturers to report within 24 hours"}]},{"@type":"WebSite","@id":"https:\/\/www.digital-chiefs.de\/en\/#website","url":"https:\/\/www.digital-chiefs.de\/en\/","name":"Digital Chiefs","description":"Architekten des digitalen Deutschlands","publisher":{"@id":"https:\/\/www.digital-chiefs.de\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.digital-chiefs.de\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.digital-chiefs.de\/en\/#organization","name":"Digital Chiefs","url":"https:\/\/www.digital-chiefs.de\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2020\/05\/cropped-digital-chiefs-logo-klein.jpg","contentUrl":"https:\/\/www.digital-chiefs.de\/wp-content\/uploads\/2020\/05\/cropped-digital-chiefs-logo-klein.jpg","width":190,"height":190,"caption":"Digital Chiefs"},"image":{"@id":"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/digitalchiefs\/","https:\/\/x.com\/digital_chiefs","https:\/\/www.linkedin.com\/company\/digital-chiefs\/"]},{"@type":"Person","@id":"https:\/\/www.digital-chiefs.de\/en\/#\/schema\/person\/6420de0b227b38e6859e2347ff5ed9ee","name":"Bernhard Liebl","description":"Bernhard Liebl is an author and Co-Founder & CEO of planeed, a SaaS platform for Semantic Brand Architecture. He addresses the question of how brand knowledge can be structured, linked and made understandable and retrievable for search and AI systems. Drawing on his many years of experience in digital strategy and marketing, he writes for Digital Chiefs about AI Visibility, Generative Engine Optimization (GEO) and the question of which structural decisions support digital brand management in AI systems.","url":"https:\/\/www.digital-chiefs.de\/en\/author\/bernhard-liebl\/"}]}},"_links":{"self":[{"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/posts\/33934","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/comments?post=33934"}],"version-history":[{"count":5,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/posts\/33934\/revisions"}],"predecessor-version":[{"id":33985,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/posts\/33934\/revisions\/33985"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/media\/33874"}],"wp:attachment":[{"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/media?parent=33934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/categories?post=33934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.digital-chiefs.de\/en\/wp-json\/wp\/v2\/tags?post=33934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}