Industry NewsAugust 24, 2026

Machine Builders CRA Vulnerability Reporting Deadline

Frederik Kok, Senior Cyber Security Expert at Mitsubishi Electric Europe is urging machine builders to act now to ensure that they are ready for the Cyber Resilience Act’s (CRA) upcoming vulnerability reporting deadline.

Frederik Kok, Senior Cyber Security Expert at Mitsubishi Electric Europe is urging machine builders to act now to ensure that they are ready for the Cyber Resilience Act’s (CRA) upcoming vulnerability reporting deadline.

First introduced by the European Union (EU) on 10 December 2024, the CRA establishes mandatory cybersecurity requirements that manufacturers and retailers must incorpor ate into the planning, design, development and maintenance of products with a digital element to continue selling them in EU markets.

While the main obligations of the Act are not due to apply until 11 December 2027, the deadline for the mandatory obligation to report actively exploited vulnerabilities and severe incidents is fast approaching on 11 September 2026. From this date, machine builders must follow a strict, three-tiered reporting deadline with the European Union Agency for Cybersecurity (ENISA) and relevant cyber security incident response teams, with specific actions to be taken with 24 hours, 72 hours, and 14 days of an incident.

In light of this, Frederik Kok, Senior Cyber Security Expert at Mitsubishi Electric Europe B.V., is calling on machine builders to take swift action to ensure that they are ready for the mandatory September deadline.

“While machine builders who are already compliant with the EU’s NIS2 Directive will be in a strong position to meet the CRA’s vulnerability reporting requirements, many more besides will need to build the necessary reporting capabilities from the ground up,” he explains.

“It’s understandable why the upcoming deadline may seem like a daunting prospect for these organisations, and we recognise that navigating the various requirements might be a difficult task. As such, we stand ready to support machine builders in ensuring compliance and avoiding severe penalties, which could equate to up to €15 million, or 2.5% of their global annual turnover, depending on which is higher.

Machine builders are advised to visit the website of the European Union Agency for Cybersecurity (ENISA), which is responsible for establishing and operating the CRA Single Reporting Platform (SRP). ENISA has also launched a webpage with frequently asked questions on reporting obligations and the development of the Single Reporting Platform: Single Reporting Platform (SRP) | ENISA.

Furthermore, as a CVE Numbering Authority (CNA), Mitsubishi Electric is authorised within the global CVE programme to assign CVE identifiers to vulnerabilities affecting products within its scope, and to publish vulnerability information in a standardised, internationally recognised format.
“Mitsubishi’s status as a CNA embodies our practical experience in vulnerability management, and means that we are well placed to support machine builders in meeting their obligations under the CRA,” Frederik continues.

“With a little over a month to go, I would urge machine builders to get in touch with us now to avoid falling afoul of September’s vulnerability reporting deadline.” Kok says.

Frederik Kok, Senior Cyber Security Expert, Mitsubishi Electric Europe

Free Subscription

Receive email with each new issue of Industrial Ethernet, plus a weekly email digest of industry news, technology features and new products. Subscribe today!

Subscribe for Free