The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, entered into force on 10 December 2024. Most of its obligations will apply from 11 December 2027.
A first deadline arrives well before that date.
From 11 September 2026, manufacturers of PLCs, HMIs, industrial gateways and connected products more broadly will have to notify certain cybersecurity incidents to ENISA (the European Union Agency for Cybersecurity) and to the competent CSIRT (the national Computer Security Incident Response Team of the Member State concerned).
This obligation falls on your equipment suppliers and on your industrial software publishers, not directly on you as an industrial operator.
But it does concern you: it determines how they will have to manage and communicate about vulnerabilities in the PLCs, HMIs, gateways and software (SCADA, MES, historian systems…) already installed on your sites.
What is the Cyber Resilience Act?
The CRA sets cybersecurity requirements for any « product with digital elements » placed on the European market: hardware, software, and components such as chips or operating systems sold separately. It covers the product’s entire lifecycle, from design to maintenance during the support period set by the manufacturer.
Before placing a product on the market, the manufacturer assesses cybersecurity risks and documents its compliance with the regulation’s essential requirements.
After the product is placed on the market, the manufacturer remains responsible. It must manage vulnerabilities throughout the announced support period, and report those that are actively exploited as well as severe incidents. This last obligation is the first to become effective.
Cyber Resilience Act: the first notification deadline, from 11 September 2026
From that date, your PLC, HMI and gateway suppliers, as well as your industrial software publishers, will have to report:
- Any actively exploited vulnerability affecting a product with digital elements,
- Any severe incident affecting the security of that product.
1. Who is concerned
The obligation applies to the manufacturer of the product, not the company using it. In practice, it is your PLC, HMI or gateway supplier who will have to notify, not you.
The regulation is not limited to hardware: industrial software (SCADA, MES, historian systems…) is also a « product with digital elements ». Its publisher is therefore subject to the same reporting obligations as a PLC or gateway manufacturer.
It also applies to products already installed before 11 December 2027.
The European Commission states this explicitly: a PLC installed on one of your sites for several years falls within scope, just like a new product.
If your company itself designs equipment that it sells, not only for its own use, it may also be considered a manufacturer under the regulation.
The exact category of the products is worth checking with a specialised legal advisor: the regulation provides for « important » and « critical » categories subject to stricter procedures (Annexes III and IV).
2. Deadlines your suppliers will have to respect
The regulation sets a precise notification timeline:
- An early warning within 24 hours of becoming aware of the incident or vulnerability,
- A full notification within 72 hours,
- A final report, no later than 14 days after a corrective measure becomes available, or within one month for a severe incident.
Micro and small enterprises cannot be penalised for failing to meet the 24-hour deadline alone.
3. How the notification is handled
Notification goes through the CRA Single Reporting Platform (SRP), set up by ENISA and operational from 11 September 2026. The supplier submits its notification to the CSIRT of its main Member State, as well as to ENISA.
Each Member State designates its own national CSIRT. In Belgium, for example, this is the Centre for Cybersecurity Belgium (CCB), which already publishes its own resources on the CRA. Depending on the supplier’s country of establishment, an equivalent contact exists.
What this means for you, as an industrial operator.
The CRA does not require you to notify anything yourself. But it changes what you can expect from your suppliers, and a few questions are worth asking now:
- Do your PLC, HMI and gateway suppliers, and your industrial software publishers, have a clear point of contact for reporting a vulnerability?
- Is your installed base mapped well enough to quickly identify which equipment would be affected if a supplier reports a vulnerability?
- Do your contracts specify the support period and security update commitments of your suppliers?
Answering these questions now, rather than on 11 September 2026, makes it easier to handle these conversations with suppliers without improvisation on the day a vulnerability needs to be communicated.
