Know What You Know: The EU’s CRA Heightens Need For Risk “Awareness”
December 11, 2027 may be the date EU Cyber Resilience Act (CRA) comes into force in its entirety, but the regulation has already introduced several binding obligations for manufacturers. Since September 11, 2026, Article 14 has required manufacturers of products with digital elements to notify the European Union Agency for Cybersecurity (ENISA) and a relevant national computer security incident response team (CSIRT) if they become “aware” of an actively exploited vulnerability.
In practice, this requires organizations to submit an early warning within 24 hours, followed by a more detailed vulnerability notification within 72 hours. Failure to do so risks a severe penalty: either €15 million or 2.5% of turnover, whichever figure is higher. This short provision – easily overlooked within the wider framework – poses a nuanced problem for risk managers working with fragmented and conflicting streams of risk intelligence, demanding a defensible judgment on when they became truly “aware” of downstream exploits.
This issue is complex because Article 14 does not define awareness. While the Commission’s July 2026 guidance suggests awareness follows an initial assessment that provides “a reasonable degree of certainty”, this is non-binding and leaves firms to decide what counts as reasonable. If manufacturers initially receive evidence that may be unreliable, they are faced with weighing the potential reputational risk of reporting on uncorroborated evidence against the cost of waiting for confirmation after the 24/72-hour window has closed. Deciding when evidence is strong enough has always been an intelligence task, but Article 14 of the CRA has significantly compressed the judgement timeframe. Regulators will review either choice with the benefit of hindsight, and how organizations handle incoming intelligence will mark the difference between resilience and regulatory exposure.
What awareness looks like in a fragmented world
Under Article 14, the question of awareness largely rests on two separate judgements: whether a digital vulnerability is being actively exploited, and whether it affects the manufacturer’s product. As cybersecurity risks evolve, both points are becoming less clear-cut. Internal telemetry may show anomalies in the manufacturer’s own system, but most products run in customer environments the manufacturer cannot see. Meanwhile, supplier notices flag compromised components, but their value depends on how quickly and candidly the supplier shares information.
As a result, manufacturers can now easily fall into an evidence gap where the signals behind each judgement arrive through different systems and at different times. Without the right internal governance and tooling, proving to an auditor precisely when both intelligence signals combined into “awareness” may be an arduous task.
To ensure strict compliance with the CRA’s notification window, risk managers in manufacturing should:
- Understand awareness thresholds before an incident.
Define what evidence – from which source tiers – moves a signal from monitored to reportable, via a clear internal escalation route. A good understanding of who has the internal authority to make this decision allows for better continuity across reporting judgements.
- Grade evidence by reliability rather than volume.
Adopt a simple scale that grades the reliability of each source and the credibility of its information to keep judgements consistent. Under this approach, flimsy single-source claims may be treated as leads until they can be traced to a primary source.
- Maintain insight into product offering details.
Holding an up-to-date software bill of materials (SBOM) for every product and version, alongside a view of which versions are deployed with which customers, allows for an exploited component to be mapped faster. Without this, the second awareness judgement (whether the vulnerability affects the manufacturer’s product) will remain a slow, manual process.
- Properly record the moment of awareness.
Log when each signal arrives, along with when the initial assessment begins and concludes, to facilitate defence of judgement calls when regulators look to test the timing of a notification after the fact.
Ultimately, Article 14 of the CRA means that many manufacturers will find themselves reconstructing their own reporting judgement under regulatory scrutiny in a time-sensitive scenario. The far more sustainable approach will be to build an operating model around agreed thresholds and graded intelligence so that awareness can be evidenced properly. Firms that make this shift now will likely be the most resilient moving forwards.
For more risk management content, check out Verdantix insights.
About The Author

Tom Murphy
Analyst



