EU Cyber Resilience Act: 24-Hour Reporting Is Now Live

The short answer
Since 11 September 2026, every manufacturer of a product with digital elements on the EU market must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA): an early warning within 24 hours, a fuller notification within 72 hours, and a final report afterwards. That includes a PLC-based machine, HMI, remote-access gateway or firmware built in India and sold into Europe, and it covers units already shipped. The technical yardstick behind the law is IEC 62443-4-1 and 62443-4-2, which is why those standard numbers now belong on the CV of any Indian controls engineer working for an exporter.
What happened on 11 September 2026
The European Commission confirmed on 11 September 2026 that the CRA's reporting obligations had started. The rest of the regulation (secure-by-design requirements, documentation, conformity assessment, CE marking for cybersecurity) applies from 11 December 2027. Reporting came first, fifteen months early, so that the EU sees what is being exploited before the full rules bite.
The key facts from the Commission and from law firm Jones Day's July 2026 briefing:
- The duty applies to all products with digital elements on the EU market, including ones already sold. A machine you shipped to Poland in 2023 is in scope if a vulnerability in it is now being exploited.
- Reports go through one channel: the CRA Single Reporting Platform run by ENISA, the EU's cybersecurity agency.
- Fines go up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
- The Commission published reporting guidance on 27 July 2026.
- According to an Exterro summary, manufacturers do not have to report, retroactively, exploitation they already knew about before 11 September 2026. The clock runs from that date.
The reporting clock
| Step | Deadline | What it contains |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | That an exploited vulnerability or severe incident exists, and which product |
| Notification | Within 72 hours | More detail: the product, the nature of the exploit or incident, what has been done |
| Final report (vulnerability) | Within 14 days of a fix being available | Description, severity, impact, the corrective measure |
| Final report (severe incident) | Within one month | Description, root cause as far as known, mitigation |

Note the trigger: actively exploited. A theoretical bug found in a code review is not, on its own, a 24-hour report. A bug that someone is using against a customer's plant is.
Why an Indian machine builder should care
Europe is a serious market for Indian packaging machines, pumps and compressors with their own controllers, process skids, control panels, test rigs, EV chargers and IoT gateways. The CRA puts the duty on the manufacturer, meaning the company that places the product on the EU market under its name, wherever that company is based. Your European distributor or customer will not carry it for you, and the better ones are already asking suppliers how they will meet it.
There is an honest grey area for machine builders. If your machine contains a Siemens or Rockwell PLC, the PLC vendor is the manufacturer of that PLC and reports its vulnerabilities. Whether your complete machine, with your own HMI application, remote-access router and logic, is itself treated as a product with digital elements depends on how it is placed on the market. Ask your EU customer's compliance team or a qualified adviser for your specific products; do not guess. What is not grey: any device or software you design yourself, such as a gateway, a controller board, a configuration app or a firmware image, is yours.
What changes inside an Indian OEM
- Someone owns vulnerability intake. A named person or small team, an email address published for security reports, and a rule that any report from a customer or researcher reaches them the same day.
- You know what you shipped. A list, per customer and per machine serial number, of the PLC model and firmware, HMI and its runtime version, network devices, remote-access hardware and your own software versions. Without it you cannot answer "which of our machines are affected?" inside 24 hours.
- You can push a fix. A tested way to deliver a patched PLC project, HMI runtime or firmware to a site, and to record which sites have taken it.
- You rehearse. Run a table-top exercise once: a customer reports an exploit at 4 pm IST on a Friday. Who submits the early warning to ENISA before 4 pm on Saturday?
Where IEC 62443 fits
The CRA itself is written in legal language. The technical detail is coming through harmonised standards, and for industrial products the core reference is the IEC 62443 family. According to IBF Solutions, writing on 30 September 2026, the parts that matter most are:
| Part | Scope | What it asks for, in short |
|---|---|---|
| IEC 62443-4-1 | Secure product development lifecycle | Security management, threat modelling, secure design and coding, testing, defect and patch management, user guidance |
| IEC 62443-4-2 | Technical requirements for components | Authentication, access control, integrity, logging and similar capabilities for embedded devices, network devices, host devices and software |
| IEC 62443-3-3 | System security requirements | Requirements and security levels for a complete control system |
These sit alongside the horizontal EN 40000 series (for all product types) and the OT product profiles being drafted in prEN 50770. IBF also reports that a Commission draft amendment in July 2026 proposed moving some standardisation deadlines back by two months, to 31 October 2026 for Type A and B standards and 31 December 2026 for Type C, while the 30 October 2027 deadline for Type B technical-measure standards stays unchanged. In plain terms: the detailed standards are still being finished, but the direction is fixed and it points at 62443.
If the 62443 vocabulary is new to you, read our explainers on IEC 62443 basics for SCADA engineers and zones and conduits first. This post is about the deadline; those are about the engineering.
What a PLC or HMI engineer should do differently from Monday
Most of the CRA lands on management and product teams, but much of what makes a product defensible is decided by the engineer writing the PLC project and commissioning the machine.

- No default credentials leave the factory. HMI runtime users, web servers on controllers, router admin pages and VNC passwords get unique values per machine, recorded in the handover documents.
- Use the controller's own protection. On Siemens S7-1200/1500 that means access-protection levels and a password on the project; on Rockwell Logix it means source protection and, where used, controller access controls. Know what each level actually blocks.
- Turn off what you do not use. Controller web servers, unused protocols, FTP on HMIs, open remote-access ports.
- Record versions. Firmware of the CPU, HMI runtime, drives and switches, written into the machine's as-built file, so that an advisory can be matched to serial numbers in minutes.
- Keep clean project backups. Version-controlled, dated, and stored away from the plant network, so a fix can be built from a known source.
- Document remote access. Which device, which account, who can enable it, and how the customer switches it off.
- Read vendor advisories. Siemens ProductCERT and Rockwell's security advisories publish fixes for exactly the components you build with. Someone in your company should read them every week.
None of this is exotic. It is the content of a good secure-commissioning checklist, and it is what IEC 62443-4-2 expects a component to support.
What it means for jobs and skills in India
The CRA does not create a fixed number of jobs, and anyone quoting one is guessing. What it does is turn product security from a nice-to-have into a contractual question that European buyers ask Indian suppliers. That shifts demand in three ways:
| Role | Where in India | Skills that get you shortlisted |
|---|---|---|
| OT or product security engineer | OEMs and machine builders exporting to Europe; engineering centres of European automation firms in Bengaluru, Pune, Chennai | IEC 62443-4-1 and 4-2, threat modelling, vulnerability handling, PLC and network basics |
| Controls engineer on export machines | Packaging, process skids, pharma equipment, test rigs | Secure PLC and HMI configuration, version control, documented commissioning |
| OT security consultant or assessor | System integrators and consultancies | IEC 62443-3-3, network segmentation, assessment without stopping production |
The engineers who will benefit most are the ones who already know PLCs and networks and add security on top. A security analyst who has never seen a ladder rung struggles to judge whether an exploit can actually move a valve. A PLC programmer who understands 62443 can.
A sensible learning order
- Networking basics: IP addressing, VLANs, firewalls, how industrial protocols such as PROFINET, EtherNet/IP and Modbus TCP travel.
- The 62443 model: zones and conduits, security levels, the split between asset owner, integrator and product supplier.
- Hardening the controllers you already program.
- Assessment: how to find weaknesses in a running plant without stopping it.
Learn it free
Four of our free courses map directly onto the CRA work above:
- OT and ICS Cybersecurity with ISA/IEC 62443: the standard family, zones and conduits, security levels and the roles of supplier and integrator.
- Cybersecurity for PLC Programmers: hardening Siemens and Rockwell controllers, the practical half of this article.
- ICS Security Foundations: the starting point if security is new to you.
- OT Security Assessment: testing a plant without stopping it, for those heading into consulting.
Each course is free with an account, self-paced, with written notes, practice tasks and a final assessment. If you want a certificate to show an employer, the optional EDWartens Certificate of Completion carries a public verification code; it is our certificate, not an IEC or vendor credential. The full list is at /free-courses.
Frequently asked questions
Q: When did the EU Cyber Resilience Act reporting obligations start?
A: On 11 September 2026. From that date manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. The CRA's main obligations apply from 11 December 2027.
Q: Does the CRA apply to an Indian company that exports to Europe?
A: Yes, if it places a product with digital elements on the EU market under its own name. The duty sits with the manufacturer wherever it is based, and covers products already sold.
Q: What are the CRA reporting deadlines?
A: An early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix for a vulnerability or within one month for a severe incident.
Q: How big are the fines under the Cyber Resilience Act?
A: Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, according to Jones Day's July 2026 summary.
Q: Which IEC 62443 parts matter for the CRA?
A: IEC 62443-4-1 for the secure development lifecycle, 62443-4-2 for component requirements and 62443-3-3 for system requirements, alongside the EN 40000 series and the draft prEN 50770 OT profiles.
Q: Is the EDWartens certificate an IEC 62443 certification?
A: No. It is an EDWartens Certificate of Completion for our free course, with a public verification code. IEC 62443 certification of people or products is done by accredited bodies.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.




