From September 11, 2026, the Cyber Resilience Act's incident and vulnerability reporting obligations become enforceable — the first hard deadline in a regulation that will fully apply from December 2027. Any manufacturer placing a "product with digital elements" on the EU market must, from that date, notify an EU member-state CSIRT and ENISA within 24 hours of becoming aware of active exploitation of a vulnerability in its product, or of a severe incident affecting the product's security. A 72-hour follow-up notification and a final report — within 14 days for vulnerabilities, one month for severe incidents — complete the sequence. Switzerland is not an EU member, but the CRA applies to any manufacturer that places covered products on the EU market regardless of where the manufacturer is established, which puts Swiss medtech, industrial-automation, IoT, and embedded-software vendors squarely in scope if they sell into the EU. With three weeks remaining, the gap between "aware of the deadline" and "operationally ready to meet a 24-hour clock" is where most exposure sits.
What actually triggers the 24-hour clock
The obligation is narrower than a general breach-notification duty, but the trigger conditions are broad enough to catch most manufacturers off guard. Two events start the clock: reasonable certainty that a vulnerability in your product is being actively exploited in the wild, and reasonable certainty of a severe incident negatively affecting — or capable of negatively affecting — the product's availability, authenticity, integrity, or confidentiality. Neither requires proof of customer harm or a confirmed data breach; "reasonable certainty" of exploitation or impact is sufficient, and that threshold is deliberately lower than most Swiss organisations' existing incident-classification triggers, which typically only escalate once harm is confirmed. Manufacturers whose vulnerability-management programs treat "exploited in the wild" as informational threat intelligence rather than a regulatory trigger will find their internal escalation paths misaligned with the CRA's clock the first time it matters.
Reports go through the CRA Single Reporting Platform to the CSIRT of the member state where the manufacturer has its main EU establishment, with ENISA notified in parallel. For a Swiss manufacturer without an EU subsidiary, determining the correct competent CSIRT — typically tied to the location of an EU-based authorised representative or the market where the product is placed — is itself a task that needs resolving before September 11, not during the first live incident.
Where this collides with existing Swiss and EU obligations
The CRA does not replace NIS2, DORA, or GDPR notification duties; it stacks alongside them, each with its own trigger conditions, timelines, and recipient authority. A Swiss medtech manufacturer whose connected device is also a medical device under the EU MDR may face CRA vulnerability reporting, MDR post-market surveillance obligations, and — if patient data is involved — GDPR breach notification, from a single incident. Reed Smith's and DLA Piper's analyses of the 2026 EU regulatory landscape both flag this convergence as the dominant compliance-design problem of the year: the CRA adds a fourth notification pathway on top of an already crowded field, and the entities most exposed are exactly the cross-border manufacturers — medtech, industrial IoT, connected building systems — that Switzerland's export economy is built on.
Practically, this argues against building a CRA-specific reporting process in isolation. Organisations that treat the CRA notification as one output of a single, well-instrumented incident-response and vulnerability-management pipeline — rather than a bolt-on legal checklist triggered after the fact — will meet the 24-hour deadline far more reliably than those relying on ad hoc escalation once an incident is already underway.
The compliance gap is operational, not legal
Most Swiss manufacturers in scope already understand the CRA exists; the gap is turning a known obligation into a rehearsed workflow. A 24-hour early warning requires that engineering, security, and legal functions can jointly reach "reasonable certainty" and file a structured report to an unfamiliar EU platform within one business day, including weekends and holidays — a capability few organisations have tested end-to-end. Waiting for the first live incident to discover that the Single Reporting Platform account does not exist, that nobody owns the decision to declare "reasonable certainty," or that the authorised EU representative details are out of date is the realistic failure mode this regulation punishes.
◆ Key Takeaway
The CRA's 24-hour reporting duty becomes enforceable on September 11, 2026, for any Swiss manufacturer placing digital-element products on the EU market. The remaining three weeks should go into rehearsing the escalation-to-filing workflow, not re-reading the regulation.
- Confirm whether your products qualify as "products with digital elements" under the CRA and identify every EU market entry point they use.
- Register for the CRA Single Reporting Platform and identify the competent CSIRT for your EU authorised representative or market of placement before September 11.
- Define, in writing, who within your organisation has authority to declare "reasonable certainty" of active exploitation or a severe incident — this decision cannot wait for a committee during a live event.
- Map CRA reporting against existing NIS2, DORA, GDPR, and MDR notification duties to identify which incidents trigger multiple simultaneous filings.
- Run a tabletop exercise simulating a 24-hour early-warning filing, including weekend and holiday coverage, before the obligation becomes live.
- Review vulnerability-management thresholds so that "actively exploited in the wild" intelligence is routed to the CRA decision-maker, not just logged as a threat-intel note.
- Verify authorised-representative and legal-entity details held by EU CSIRTs are current, particularly for manufacturers without a direct EU subsidiary.
The CRA joins NIS2 and DORA as the third major EU regime in two years to compress incident-reporting timelines to hours rather than days, and that trend is not reversing. Swiss manufacturers that build one well-tested notification pipeline capable of routing a single incident to whichever regulators it legally requires will spend far less on compliance than those maintaining four separate, untested processes discovered to be broken one at a time.