NORMQ

CYBER RESILIENCE ACT · CRA

Prepare your company for CRA notifications within 24 hours.

From 11 September 2026, certain notification obligations under the Cyber Resilience Act apply to manufacturers of products with digital elements.

NORMQ prepares the procedures, responsibilities and documentation needed so that, when faced with a potentially reportable event, your company does not have to start improvising with a 24-hour legal deadline.

EUROPEAN REGULATION

11 September 2026

Cyber Resilience Act: the 24-hour
notification obligations are now applicable.

Regulation (EU) 2024/2847 establishes cybersecurity requirements for manufacturers of products

with digital elements. From 11 September 2026, the notification obligations set out in Article 14 apply.

Manufacturers must report certain actively exploited vulnerabilities and severe incidents.

The procedure includes an early warning within 24 hours of the manufacturer becoming aware

of the event, followed by subsequent notifications within the time limits established by the Regulation.

El Reglamento (UE) 2024/2847 establece obligaciones de ciberseguridad para fabricantes

de productos con elementos digitales. Desde el 11 de septiembre de 2026 son aplicables las

obligaciones de notificación previstas en su artículo 14.

Los fabricantes deben comunicar

determinadas vulnerabilidades explotadas activamente e incidentes graves.

El procedimiento contempla una alerta temprana dentro de las 24 horas desde que

el fabricante tiene conocimiento del hecho y posteriores comunicaciones conforme a

los plazos establecidos por el Reglamento.

Our work combines regulatory analysis and operational preparation so that your company has a clear procedure in place for potential CRA notifications, with responsibilities, steps and documentation defined in advance.

Official source
Regulation (EU) 2024/2847 — Cyber Resilience Act
Articles 14 and 71
Application of the notification obligations: 11 September 2026


Regulation (EU) 2024/2847 — EUR-Lex, official text

WHAT WE REVIEW

We prepare the process before the clock starts running.

We review how your company would respond to an actively exploited vulnerability or a severe incident potentially subject to notification under the CRA.

Products and scope

Identification of products with digital elements and the responsible teams involved.

Internal detection and escalation

How a potentially reportable event is communicated, assessed and escalated internally.

Responsibilities and notification

Roles, responsible persons, contacts and steps required to activate the procedure.

Documentation and deadlines

Required information and preparation of the 24-hour communication, subsequent notifications and closure.

SERVICES

A protocol in place before the urgency begins.

CRA 24H PROTOCOL

€390 + VAT

Preparation of the basic response procedure for a potential actively exploited vulnerability or severe incident subject to notification.

Includes scope review, internal responsibilities, escalation flow, information checklist and templates for the communications required under the CRA.

CRA 24H PROTOCOL · MULTI-PRODUCT

From €690 + VAT

Preparation of the procedure for companies with multiple products with digital elements, teams involved or internal notification workflows.

Includes definition of responsibilities by product, escalation flows, documentation and communication templates adapted to the company's structure.

Does your company have a more complex structure?

FOR MANUFACTURERS WITH MULTIPLE PRODUCTS, SUBSIDIARIES, INTERNATIONAL TEAMS OR COMPLEX INTERNAL WORKFLOWS,

WE CARRY OUT AN INITIAL ASSESSMENT AND PREPARE A TAILORED CRA PROCEDURE.

[ REQUEST A QUOTE ]

Does your company have a more complex structure?

FOR MANUFACTURERS WITH MULTIPLE PRODUCTS, SUBSIDIARIES, INTERNATIONAL TEAMS OR

COMPLEX INTERNAL WORKFLOWS,

WE CARRY OUT AN INITIAL ASSESSMENT AND PREPARE A TAILORED CRA PROCEDURE.

[ REQUEST A QUOTE ]

PENALTIES

The CRA provides for significant financial
penalties for non-compliance.

Regulation (EU) 2024/2847 establishes a system of penalties for certain infringements of its obligations.

Non-compliance with the obligations laid down, among others,

in Articles 13 and 14 may result in administrative fines of up to:

15.000.000 €
or, if higher,

2,5 % of the total worldwide annual turnover for the preceding financial year.

For other categories of non-compliance, the Regulation establishes different maximum penalties.

The applicable amount will depend on the obligation concerned and the specific circumstances of the infringement.

Regulation (EU) 2024/2847 establishes a system of penalties for certain

infringements of its obligations.

Non-compliance with the obligations laid down, among others,

in Articles 13 and 14 may result in administrative fines of up to:

15.000.000 €
or, if higher,

2,5 % of the total worldwide annual turnover for the preceding financial year.

For other categories of non-compliance, the Regulation establishes different

maximum penalties.

The applicable amount will depend on the obligation concerned and the specific

circumstances of the infringement.

Official source: Regulation (EU) 2024/2847 — Article 64(2).

PROCESS

A clear procedure before the clock starts running.

01

Scope review

We identify the products, teams involved and internal responsibilities.

02

Protocol design

We define the escalation flow, responsible persons, contacts and decision points.

03

Documentation preparation

We create checklists and templates for the 24-hour CRA communication and subsequent notifications.

04

Delivery and validation

We review the procedure with your company and leave the documentation ready for use.

FAQ

Frequently asked questions, answered clearly.

What does the CRA 24H Protocol include?

Does NORMQ determine whether a vulnerability or incident must be reported?

Does the service include penetration testing or a cybersecurity audit?

CONTACT

Let’s talk about your CRA preparation.

Tell us about your products with digital elements and your current notification process. We will get back to you to assess the most appropriate scope for your company.

NORMQ

Regulatory and operational preparation services for compliance with the Cyber Resilience Act (CRA).

Legal Notice

Privacy Policy

Cookies