Fifteen questions component suppliers ask about Article 14

Answered plainly, with the article numbers, so you can check them yourself. No sign-up, no gate, no download. If your question is not here, ask it and it will be.

Facts verified 11 Sep 2026. Obligations and platform status change — re-check anything here before it goes in a filing.

01

Does the EU Cyber Resilience Act apply to component suppliers?

Yes, if you place a product with digital elements on the EU market under your own name or trademark. The regulation is written around the product, not around the size of the company or its position in the supply chain. A sensor, drive, controller, gateway or comms module with software in it is a product with digital elements. Selling business-to-business rather than to consumers changes nothing. Your obligations as manufacturer start there.

02

We sell to OEMs and integrators — aren’t they the “manufacturer”?

Not for your product. Under the CRA the manufacturer is whoever places a product on the EU market under their own name or trademark. If your module ships with your badge on it, you are the manufacturer of that module, and your OEM customer is the manufacturer of the machine it goes into. Both duties exist at the same time. In practice your customers will also flow the requirement down to you in purchase agreements.

03

Our products shipped years ago. Are they grandfathered?

Not for reporting. The product requirements and CE marking apply from 11 December 2027, so existing designs get that transition. Article 14 reporting does not: Article 69(3) carves it out of the Article 69(2) transition, and it has applied since 11 September 2026 to products already in the field. If a unit you shipped in 2021 has a vulnerability that someone is actively exploiting today, the 24-hour clock runs.

04

What exactly does Article 14 require?

Two reporting duties, each in three stages, both live since 11 September 2026. When you become aware of an actively exploited vulnerability in your product, or of a severe incident affecting its security, you file an early warning within 24 hours, a fuller notification within 72 hours, and a final report after that. Reports go through the ENISA Single Reporting Platform to your CSIRT and to ENISA. What you need is a named person, a decided route, and a filled-in template. the SRP Readiness Sprint.

05

What counts as an “actively exploited vulnerability”?

Article 3(42) defines it as a vulnerability where there is reliable evidence that someone executed malicious code on a system without the system owner’s permission. Two things follow. Authorised testing does not count, so your own penetration test and a researcher’s good-faith work are both out. And a proof of concept on its own is not exploitation. What counts as “reliable evidence” in a marginal case is unsettled — no regulator has tested it yet — so decide now who in your company makes that call.

06

What has to be in the 24-hour early warning — and what doesn’t?

The early warning is a notification that something is happening, not an analysis of it. It states that an actively exploited vulnerability or a severe incident exists, and where relevant that you suspect unlawful or malicious acts caused it. That is the whole obligation at 24 hours. You do not yet owe root cause, an affected-version list, patch status, or customer impact. Filing thin and on time is compliant. Filing complete and late is not. the SRP Readiness Sprint.

07

What happens at 72 hours, and at 14 days?

At 72 hours you file the fuller notification: the general information you hold on the vulnerability or incident, its severity and impact, and where you have them, any corrective or mitigating measures. The 14-day final report applies to an actively exploited vulnerability, and its clock starts when a fix or a workaround becomes available — not when you first became aware. Severe incidents run to a different final deadline: one month after the 72-hour notification. the SRP Readiness Sprint.

08

What is the ENISA Single Reporting Platform, and how do we get access?

It is the single electronic system, required by Article 16, where manufacturers file their Article 14 reports. You submit once and the platform routes the report to the relevant national CSIRT and to ENISA, so you are not notifying Member States one at a time. ENISA launched it on 11 September 2026, the day the duty started. If your account, named reporter and deputy are not set up, that work is now overdue rather than upcoming.

09

Do we need a notified body — and why are none designated yet?

Most manufacturers do not. Third-party assessment applies to the important and critical categories in Annexes III and IV; everything outside those self-assesses. The rules on notified bodies started applying on 11 June 2026, but the Commission’s NANDO database still lists none for the CRA, because each Member State has to stand up a notifying authority before it can notify any body. Article 35(2) targets sufficient capacity by 11 December 2026. None of this touches Article 14 — reporting is your duty either way.

10

What’s the difference between Class I and Class II (“important”) products?

Annex III lists “important products with digital elements” in two classes, graded by how much harm a compromise would cause. Class I holds categories such as password managers, VPNs, network management systems, routers and boot managers. Class II is the higher tier, including operating systems, hypervisors, and firewalls or intrusion detection systems intended for industrial use. The practical difference is the conformity route: Class I may self-assess, but only by applying harmonised standards in full; Class II requires a notified body.

11

How does IEC 62443-4-1 relate to CRA compliance?

IEC 62443-4-1 is a secure development lifecycle standard. It is not a harmonised standard under the CRA, so applying it does not by itself give you the Article 27 presumption of conformity — and no CRA harmonised standard has yet been published in the Official Journal, so that presumption is not available to anyone. What 4-1 does give you is a process the CRA’s vulnerability-handling requirements map onto cleanly, Practices 6 and 7 in particular. If you already run 4-1, you are closer than you think. how the mapping works.

12

Can we build this into the quality system we already run (8D / ISO 9001)?

Yes, and it is the cheapest way to do it. Article 14 gives you a new trigger and three deadlines. Everything downstream of the trigger — containment, root cause, corrective action, verification, closure — is work your team already does on any customer complaint or nonconformance. An 8D maps onto it almost line for line. You do not need a second management system standing beside your QMS. You need a new entry point into the one you have. the 8D mapping.

13

What is a “support period” and what do we owe during it?

The support period is the time after you place a product on the market during which you must handle vulnerabilities found in it, including supplying security updates. Article 13(8) says it should reflect how long the product is reasonably expected to be in use, and should generally be at least five years — shorter only where the expected use is shorter. You have to determine it and make it clear to the buyer.

14

Do we need an SBOM?

Yes. Annex I, Part II requires you to identify and document the components in your product, including by drawing up a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies. You do not have to publish it; you hold it, and provide it to market surveillance authorities on request. SPDX and CycloneDX both satisfy the format requirement. That obligation lands in December 2027 — but you cannot triage a reported vulnerability in 24 hours without one.

15

What does First Article Security actually do — and what do you not do?

We help component suppliers stand up the vulnerability-handling and reporting process the CRA requires, inside the quality system you already run, mapped to IEC 62443-4-1 Practices 6 and 7. We are advisory only. We are not a notified body, not a certifier, and not a law firm, and you remain the manufacturer of record for everything you ship. Prices are fixed and published, because scoping surprises are a process failure. The starting point is a free 20-minute exposure check. book the 20-minute check.

Still the wrong question?

The one that matters is narrower than any of the above: if a report landed in your inbox this morning, who files the early warning, and through what account? Twenty minutes on a call and you will know. It costs nothing and you get the answer in writing either way.

Book the 20-minute exposure check