Product Hacked: Why Shipments, Revenue and Customer Trust Can Collapse Before the Root Cause Is Known [GeXPs26-0821EN]

EU Cyber Resilience Act 24-hour and 72-hour incident response guide for connected-product manufacturers
Your connected product has been hacked in Europe.
A distributor pauses new shipments. Customers demand answers. Your security team is still investigating, while legal, product, support and sales teams disagree about who owns the notification. The most expensive question may not be how the breach happened. It may be: when did your company become aware?

From September 11, 2026, the EU Cyber Resilience Act’s reporting obligations apply to manufacturers of in-scope products with digital elements. An actively exploited vulnerability or a severe security incident can trigger an early warning within 24 hours and a fuller notification within 72 hours.

This is not simply another cybersecurity checklist. It changes the operating model for global manufacturers, software vendors and connected-product companies selling into the EU.

The global-company gap
Security may sit in California, engineering in Korea, customer support in India and the EU importer in Germany. If each team waits for another team to decide, the reporting clock keeps running.

Why can one product breach disrupt shipments, revenue and customer trust?

A cyberattack does not automatically cause a legal sales ban or recall. But uncertainty about affected models, software versions and markets can cause distributors to pause shipments, customers to demand refunds, and authorities to request corrective action. A significant cybersecurity risk may ultimately require withdrawal or recall measures, depending on the facts.

  • Shipment risk: If the affected versions cannot be isolated, unaffected inventory may also be held.
  • Response cost: Emergency patches, remote updates, field service and support costs arrive together.
  • Channel risk: Importers and distributors may receive inconsistent answers from different teams.
  • Trust risk: Delayed customer guidance can damage renewals and future contracts.
  • Regulatory risk: Late or incomplete reporting can increase scrutiny and enforcement exposure.

The incident may begin in security, but the loss spreads across product, legal, sales, operations and customer success.

The hidden problem: waiting for a complete root-cause analysis

Many companies follow a familiar sequence: detect the incident, investigate the root cause, confirm the impact, obtain executive approval and then report externally. That workflow may be too slow for the CRA.

The CRA uses staged reporting. The manufacturer reports what is known, then updates the record as the investigation develops.

StageDeadlinePurpose
Early warningWithin 24 hours of awarenessInitial awareness, suspected malicious activity and known cross-border impact
Full notificationWithin 72 hours of awarenessNature of the event, initial impact assessment and mitigation measures
Final report: exploited vulnerabilityWithin 14 days after a corrective measure is availableRoot cause, corrective action and prevention
Final report: severe incidentWithin one month after the 72-hour notificationIncident analysis, impact and remediation

The operational risk is not incomplete information. It is a company that cannot make a decision until every detail is complete.

Not every bug or outage is reportable

The CRA reporting obligation does not turn every software bug, CVE entry or service interruption into a 24-hour report. The first decision is whether the event involves:

  1. An actively exploited vulnerability supported by reliable evidence of malicious use; or
  2. A severe incident affecting the security of the product with digital elements.

Companies therefore need an internal triage model that distinguishes a product defect, an ordinary outage, a vulnerability, confirmed exploitation and a severe security incident.

A five-step operating model for global manufacturers

1. Build a product-and-market map

Map connected hardware, embedded software, mobile applications and remote data-processing functions. Link each product to its model, software version, EU markets, importer, distributor, customer groups and support period.

Article 14 reporting obligations also apply to in-scope products placed on the EU market before December 11, 2027. A company that maps only future CRA-labelled products may miss its installed base.

2. Define the awareness trigger

The reporting clock depends on when the manufacturer becomes aware. Define which alerts, customer reports, supplier notices and security findings must be escalated, who validates exploitation, and who records the awareness timestamp.

3. Assign decision and reporting ownership

Name a primary and backup decision-maker for nights, weekends and holidays. Clarify the roles of headquarters, EU importers, authorised representatives, security operations, legal counsel and product teams before an incident occurs.

4. Prepare the 24-hour and 72-hour data packs

The first pack should capture the product, version, awareness time, evidence of exploitation, potentially affected countries and immediate mitigation. The 72-hour update should add the incident’s nature, initial impact, known attack path, affected versions, containment and patch plan.

Separate confirmed facts, reasonable indications and items still under investigation. Speed does not require speculation.

5. Connect reporting, remediation and customer communication

Maintain one evidence chain showing when the event was detected, who classified it, what was filed, which distributors and users were informed, and how the issue was corrected. Reporting, patch deployment, shipment decisions and user guidance should not live in separate spreadsheets.

Who should act now?
  • Manufacturers of connected equipment, IoT, smart appliances, robots and industrial systems sold in the EU
  • Software and app vendors whose products fall within the CRA scope
  • Non-EU brands using EU importers, distributors or authorised representatives
  • OEM and ODM suppliers whose contracts do not clearly allocate incident responsibilities
  • Companies using third-party or open-source components in supported products

The penalty is not the first pain you will feel

Non-compliance with Articles 13 and 14 may fall within the CRA’s highest administrative-fine tier: up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher. This is not an automatic fixed fine for missing the 24-hour deadline; authorities consider the circumstances of each case.

The faster commercial pain may be a distributor’s shipment hold, emergency remediation costs, customer churn and damaged renewal negotiations. That is why CRA readiness starts with operational ownership, not with a legal memo stored on a shared drive.

Frequently asked questions

Does this affect a manufacturer with no EU office?
Potentially yes. The CRA applies to in-scope products made available on the EU market, including products from non-EU manufacturers. The company should verify its reporting jurisdiction and authorised representative structure before an incident.
Why prepare now if the main CRA obligations apply in 2027?
The main requirements apply from December 11, 2027, but Article 14 reporting obligations apply from September 11, 2026.
Do older products matter?
Yes. Article 14 applies to in-scope products placed on the market before December 11, 2027, even though the broader transitional rule treats other requirements differently.

Conclusion

The most dangerous moment after a product breach is not necessarily the attack itself. It is the period when teams are searching for owners, versions and customers while the reporting clock continues.

The companies that preserve EU market trust will not be those claiming that breaches are impossible. They will be those capable of controlling the confusion after a breach.

If one of your products were exploited today, who would classify the event and file within 24 hours?
If the answer is unclear, start with the product map, awareness trigger and responsibility matrix.

Watch the EU CRA 24-hour and 72-hour response guide

Official sources

Comments