Five questions, based directly on the official regulation text (Regulation (EU) 2024/2847). No guessing — every answer links back to the source article.
Based on your answers, you're a manufacturer of a product with digital elements placing it on the EU market — which means Article 14 vulnerability and incident reporting obligations apply to you from 11 September 2026.
The reporting deadlines are the same for every company, regardless of size — a common misconception is that small companies get 72 hours and large companies get 24 hours. That's not how it works. Every manufacturer follows the same cascade:
What company size does change: microenterprises get simplified technical documentation requirements, and the conformity assessment route depends on your product's risk class (default/important/critical) — not on your headcount.
Source: Regulation (EU) 2024/2847, Article 14 — read the official text on EUR-Lex →
Book a call with CRA Alert—
Worth re-checking this if anything changes: you start selling into the EU, you add an installable component, or the product's role changes.
Source: Regulation (EU) 2024/2847 — read the official text on EUR-Lex →
As a distributor reselling someone else's unmodified, already-branded product, the primary Article 14 reporting duty sits with the original manufacturer — not you. But you're still required to verify the manufacturer has met their CRA obligations before making the product available, and to act if you become aware it doesn't comply.
Source: Regulation (EU) 2024/2847, Article 3(17) and Article 20 — read the official text on EUR-Lex →