New European Rules for Reporting Cyber Incidents Take Effect
On September 11, the reporting requirement under the European Cyber Resilience Act (CRA) will take effect. From that point on, manufacturers must report actively exploited vulnerabilities and serious security incidents involving products with digital components. This obligation also applies to companies in the energy storage sector that develop, market under their own name or brand, import, or distribute such products.
Cyber Resilience Act
The CRA is a European regulation designed to improve the cybersecurity of products with digital elements. The rules apply to hardware and software that can be connected, directly or indirectly, to a device or network. This includes, for example, inverters, energy management systems, industrial control systems, apps, and software components. The regulation primarily targets manufacturers, but also imposes requirements on importers and distributors.
The CRA has been in effect since December 2024, but is being phased in gradually. The reporting requirement takes effect on September 11, 2026, and also applies to products that were placed on the European market before the CRA became fully applicable. The remaining obligations—including requirements for secure design, risk assessment, vulnerability management, security updates, and conformity assessment—will apply starting December 11, 2027, to products placed on the European market on or after that date.
What does the reporting requirement entail?
Manufacturers must report actively exploited vulnerabilities and serious security incidents. Dutch manufacturers report these through the digital reporting portal of the National Cyber Security Center (NCSC). This reporting center is connected to the European reporting platform operated by ENISA, the EU Agency for Cybersecurity.
In the case of an actively exploited vulnerability, an initial warning must be issued within 24 hours after the manufacturer becomes aware of it. A more detailed report must follow within 72 hours, and a final report must be submitted no later than fourteen days after a solution or mitigating measure becomes available. For a serious security incident, an initial warning must also be issued within 24 hours and a more detailed report within 72 hours; the final report must be submitted no later than one month after the more detailed report.
The responsibility lies primarily with the manufacturer. However, importers and distributors must notify a manufacturer when they become aware of a vulnerability. Manufacturers must also inform affected users as soon as possible about an incident or an actively exploited vulnerability and, where necessary, indicate what measures users can take.
What does this mean for energy storage?
Energy storage systems consist of an increasing number of digitally controlled and connected components. These include inverters, battery management systems, energy management systems, and other digitally connected hardware and software components. When a company places such a product on the European market under its own name or brand, it may be considered a manufacturer for the purposes of the CRA. Organizations that make significant modifications to an existing product—for example, in a way that affects its cybersecurity characteristics, compliance, or intended use—may also be subject to the responsibilities of a manufacturer.
Energy Storage NL advises companies to determine what role they play within the supply chain and which products fall within the scope of the CRA. It is also important to clearly define who within the company is responsible for assessing, escalating, and reporting vulnerabilities and incidents. In addition, agreements with suppliers and customers must be properly documented, technical information must remain available, and the reporting process must be practiced in advance. Companies can use this initial requirement to prepare in a timely manner for the broader cybersecurity and product requirements that will take effect in December 2027.
The CRA focuses on product safety, while the Cybersecurity Act (Cbw), which has been in effect since August 15, sets requirements for organizations’ digital resilience. As a result, companies may have to comply with both regulatory frameworks and must ensure that responsibilities or reporting procedures are not established in isolation from one another. Energy Storage NL urges companies to approach both legal frameworks in a coordinated manner and continues to highlight feedback from the sector regarding the feasibility of these obligations.
Want to know more? For further explanation, please refer to the Guide to the Cyber Resilience Act from the National Inspectorate for Digital Infrastructure (RDI).


