EU Cyber Resilience Act Article 14 Reporting Obligations Take Effect, Hitting UK and Global Software Vendors
The EU Cyber Resilience Act (CRA)'s Article 14 reporting obligations came into force on 11 September 2026, marking the first live phase of a staggered rollout that will fully apply by December 2027. The new rules require organisations selling software or connected devices in the EU to report actively exploited vulnerabilities or "severe" incidents relating to their products within a short timeframe. Businesses headquartered outside the EU, including those in the UK, are caught if they sell digital products into the single market.
Why this matters
The CRA's Article 14 is the first mandatory bite of a framework that will reshape how technology products are brought to market across Europe. UK vendors lost the benefit of seamless regulatory alignment post-Brexit, so compliance now requires parallel tracking of EU and domestic regimes. The short reporting window for exploited vulnerabilities raises the stakes for in-house legal and security teams, with non-compliance carrying potential market-access consequences.
On the Ground
Technology regulatory and data-privacy teams will be advising clients on incident-response protocols, vulnerability disclosure policies, and contractual warranties in software supply chains. Trainees can expect to assist with gap-analysis memos comparing existing client policies against Article 14 thresholds, and drafting or reviewing supplier notification clauses.
Interview prep
Question you might get
“How does the CRA's Article 14 affect a UK software company that sells products into the EU but has no EU establishment?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeMy notes
saved