Industry News

EU Cyber Resilience Act: 24-Hour Reporting Is Now Live

EDWartens Engineering Team
10 min read
EU Cyber Resilience Act: 24-Hour Reporting Is Now Live

The short answer

Since 11 September 2026, every manufacturer of a product with digital elements on the EU market must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA): an early warning within 24 hours, a fuller notification within 72 hours, and a final report afterwards. That includes a PLC-based machine, HMI, remote-access gateway or firmware built in India and sold into Europe, and it covers units already shipped. The technical yardstick behind the law is IEC 62443-4-1 and 62443-4-2, which is why those standard numbers now belong on the CV of any Indian controls engineer working for an exporter.

What happened on 11 September 2026

The European Commission confirmed on 11 September 2026 that the CRA's reporting obligations had started. The rest of the regulation (secure-by-design requirements, documentation, conformity assessment, CE marking for cybersecurity) applies from 11 December 2027. Reporting came first, fifteen months early, so that the EU sees what is being exploited before the full rules bite.

The key facts from the Commission and from law firm Jones Day's July 2026 briefing:

  • The duty applies to all products with digital elements on the EU market, including ones already sold. A machine you shipped to Poland in 2023 is in scope if a vulnerability in it is now being exploited.
  • Reports go through one channel: the CRA Single Reporting Platform run by ENISA, the EU's cybersecurity agency.
  • Fines go up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
  • The Commission published reporting guidance on 27 July 2026.
  • According to an Exterro summary, manufacturers do not have to report, retroactively, exploitation they already knew about before 11 September 2026. The clock runs from that date.

The reporting clock

StepDeadlineWhat it contains
Early warningWithin 24 hours of becoming awareThat an exploited vulnerability or severe incident exists, and which product
NotificationWithin 72 hoursMore detail: the product, the nature of the exploit or incident, what has been done
Final report (vulnerability)Within 14 days of a fix being availableDescription, severity, impact, the corrective measure
Final report (severe incident)Within one monthDescription, root cause as far as known, mitigation
The CRA reporting clock from first awareness to final report
The CRA reporting clock from first awareness to final report

Note the trigger: actively exploited. A theoretical bug found in a code review is not, on its own, a 24-hour report. A bug that someone is using against a customer's plant is.

Why an Indian machine builder should care

Europe is a serious market for Indian packaging machines, pumps and compressors with their own controllers, process skids, control panels, test rigs, EV chargers and IoT gateways. The CRA puts the duty on the manufacturer, meaning the company that places the product on the EU market under its name, wherever that company is based. Your European distributor or customer will not carry it for you, and the better ones are already asking suppliers how they will meet it.

There is an honest grey area for machine builders. If your machine contains a Siemens or Rockwell PLC, the PLC vendor is the manufacturer of that PLC and reports its vulnerabilities. Whether your complete machine, with your own HMI application, remote-access router and logic, is itself treated as a product with digital elements depends on how it is placed on the market. Ask your EU customer's compliance team or a qualified adviser for your specific products; do not guess. What is not grey: any device or software you design yourself, such as a gateway, a controller board, a configuration app or a firmware image, is yours.

What changes inside an Indian OEM

  1. Someone owns vulnerability intake. A named person or small team, an email address published for security reports, and a rule that any report from a customer or researcher reaches them the same day.
  2. You know what you shipped. A list, per customer and per machine serial number, of the PLC model and firmware, HMI and its runtime version, network devices, remote-access hardware and your own software versions. Without it you cannot answer "which of our machines are affected?" inside 24 hours.
  3. You can push a fix. A tested way to deliver a patched PLC project, HMI runtime or firmware to a site, and to record which sites have taken it.
  4. You rehearse. Run a table-top exercise once: a customer reports an exploit at 4 pm IST on a Friday. Who submits the early warning to ENISA before 4 pm on Saturday?

Where IEC 62443 fits

The CRA itself is written in legal language. The technical detail is coming through harmonised standards, and for industrial products the core reference is the IEC 62443 family. According to IBF Solutions, writing on 30 September 2026, the parts that matter most are:

PartScopeWhat it asks for, in short
IEC 62443-4-1Secure product development lifecycleSecurity management, threat modelling, secure design and coding, testing, defect and patch management, user guidance
IEC 62443-4-2Technical requirements for componentsAuthentication, access control, integrity, logging and similar capabilities for embedded devices, network devices, host devices and software
IEC 62443-3-3System security requirementsRequirements and security levels for a complete control system

These sit alongside the horizontal EN 40000 series (for all product types) and the OT product profiles being drafted in prEN 50770. IBF also reports that a Commission draft amendment in July 2026 proposed moving some standardisation deadlines back by two months, to 31 October 2026 for Type A and B standards and 31 December 2026 for Type C, while the 30 October 2027 deadline for Type B technical-measure standards stays unchanged. In plain terms: the detailed standards are still being finished, but the direction is fixed and it points at 62443.

If the 62443 vocabulary is new to you, read our explainers on IEC 62443 basics for SCADA engineers and zones and conduits first. This post is about the deadline; those are about the engineering.

What a PLC or HMI engineer should do differently from Monday

Most of the CRA lands on management and product teams, but much of what makes a product defensible is decided by the engineer writing the PLC project and commissioning the machine.

Checklist for PLC and HMI engineers working on machines exported to the EU
Checklist for PLC and HMI engineers working on machines exported to the EU
  • No default credentials leave the factory. HMI runtime users, web servers on controllers, router admin pages and VNC passwords get unique values per machine, recorded in the handover documents.
  • Use the controller's own protection. On Siemens S7-1200/1500 that means access-protection levels and a password on the project; on Rockwell Logix it means source protection and, where used, controller access controls. Know what each level actually blocks.
  • Turn off what you do not use. Controller web servers, unused protocols, FTP on HMIs, open remote-access ports.
  • Record versions. Firmware of the CPU, HMI runtime, drives and switches, written into the machine's as-built file, so that an advisory can be matched to serial numbers in minutes.
  • Keep clean project backups. Version-controlled, dated, and stored away from the plant network, so a fix can be built from a known source.
  • Document remote access. Which device, which account, who can enable it, and how the customer switches it off.
  • Read vendor advisories. Siemens ProductCERT and Rockwell's security advisories publish fixes for exactly the components you build with. Someone in your company should read them every week.

None of this is exotic. It is the content of a good secure-commissioning checklist, and it is what IEC 62443-4-2 expects a component to support.

What it means for jobs and skills in India

The CRA does not create a fixed number of jobs, and anyone quoting one is guessing. What it does is turn product security from a nice-to-have into a contractual question that European buyers ask Indian suppliers. That shifts demand in three ways:

RoleWhere in IndiaSkills that get you shortlisted
OT or product security engineerOEMs and machine builders exporting to Europe; engineering centres of European automation firms in Bengaluru, Pune, ChennaiIEC 62443-4-1 and 4-2, threat modelling, vulnerability handling, PLC and network basics
Controls engineer on export machinesPackaging, process skids, pharma equipment, test rigsSecure PLC and HMI configuration, version control, documented commissioning
OT security consultant or assessorSystem integrators and consultanciesIEC 62443-3-3, network segmentation, assessment without stopping production

The engineers who will benefit most are the ones who already know PLCs and networks and add security on top. A security analyst who has never seen a ladder rung struggles to judge whether an exploit can actually move a valve. A PLC programmer who understands 62443 can.

A sensible learning order

  1. Networking basics: IP addressing, VLANs, firewalls, how industrial protocols such as PROFINET, EtherNet/IP and Modbus TCP travel.
  2. The 62443 model: zones and conduits, security levels, the split between asset owner, integrator and product supplier.
  3. Hardening the controllers you already program.
  4. Assessment: how to find weaknesses in a running plant without stopping it.

Learn it free

Four of our free courses map directly onto the CRA work above:

Each course is free with an account, self-paced, with written notes, practice tasks and a final assessment. If you want a certificate to show an employer, the optional EDWartens Certificate of Completion carries a public verification code; it is our certificate, not an IEC or vendor credential. The full list is at /free-courses.

Frequently asked questions

Q: When did the EU Cyber Resilience Act reporting obligations start?
A: On 11 September 2026. From that date manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. The CRA's main obligations apply from 11 December 2027.

Q: Does the CRA apply to an Indian company that exports to Europe?
A: Yes, if it places a product with digital elements on the EU market under its own name. The duty sits with the manufacturer wherever it is based, and covers products already sold.

Q: What are the CRA reporting deadlines?
A: An early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix for a vulnerability or within one month for a severe incident.

Q: How big are the fines under the Cyber Resilience Act?
A: Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, according to Jones Day's July 2026 summary.

Q: Which IEC 62443 parts matter for the CRA?
A: IEC 62443-4-1 for the secure development lifecycle, 62443-4-2 for component requirements and 62443-3-3 for system requirements, alongside the EN 40000 series and the draft prEN 50770 OT profiles.

Q: Is the EDWartens certificate an IEC 62443 certification?
A: No. It is an EDWartens Certificate of Completion for our free course, with a public verification code. IEC 62443 certification of people or products is done by accredited bodies.

Learn this, free

The courses that teach this

Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.

Start Your Engineering Career at EDWartens

Join as a Junior Engineer at Wartens Automation Pvt Ltd. Get hands-on PLC SCADA training, a Wartens Experience Certificate, and a job guarantee with a fee refund (conditions apply).