The European Union’s Cyber Resilience Act reporting obligations took effect on September 11, 2026, starting a real clock for manufacturers of connected products sold in the EU. An actively exploited vulnerability now requires an early warning within 24 hours of awareness and a fuller vulnerability notification within 72 hours. For Raspberry Pi-based products, the legal manufacturer is usually the company that ships the finished device—not the maker of the module inside it.
Featured image: Raspberry Pi Foundation/Wikimedia Commons (CC BY-SA 4.0, cropped).
The September deadline is narrower than full CRA compliance
The European Commission separates two dates. Reporting applies from September 11, 2026; the Act’s main product obligations apply from December 11, 2027. That later deadline covers the broader secure-development, support, documentation and conformity work. It does not postpone incident intake and escalation.
The legal text sets the reporting trigger at manufacturer awareness. Article 14 requires the 24-hour early warning to identify affected member states when known. The 72-hour notification adds the product, the general nature of the exploit and vulnerability, corrective or mitigating measures already taken, steps users can take, and a sensitivity indication where applicable.
A module supplier cannot own the finished-product clock
Under Regulation (EU) 2024/2847, a company that markets the finished product under its name or trademark is normally its manufacturer, and manufacturers must document product components through a software bill of materials. Raspberry Pi’s guidance adds that CRA compliance is shared across the supply chain. For a commercial device built around its board, the integrator therefore needs to own the finished product’s risk assessment, SBOM, vulnerability handling and reporting path.
That changes the operational question from “does the board vendor publish advisories?” to “can the finished-product manufacturer decide, document and report within one day?” A useful intake record needs the affected model and software version, when credible awareness began, evidence of exploitation, EU availability, current mitigations, supplier contacts and the owner authorized to submit the warning. Waiting for a complete root-cause analysis would conflict with the staged 24/72-hour design.

The engineering handoff must work before the next incident
A small hardware team should map each shipped model to its maintained software components and upstream suppliers, then connect security intake to an escalation owner. The inventory does not need to solve every 2027 conformity question today, but it must answer which product is affected and who can act before the first 24 hours expire.
The Commission says CRA violations can draw penalties of up to €15 million or 2.5% of worldwide annual turnover, depending on the provision. More immediately, an incomplete escalation path can consume most of the reporting window while engineering, support and management debate ownership. The September 11 change is therefore an operations deadline: connected-product makers need a working awareness timestamp, decision path and submission owner now.

