Norway's National Communications Authority (Nkom) confirmed on September 11, 2026 that Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) now requires manufacturers of products with digital elements to report actively exploited vulnerabilities and serious security incidents. Norwegian producers placing connected devices on the EU market must build 24-hour notification workflows around ENISA's Single Reporting Platform, and, because the CRA is not yet incorporated into the EEA Agreement, channel those reports to an EU member state rather than to Nkom.

Article 14 took effect on September 11, 2026, the same day ENISA launched the Single Reporting Platform (SRP) that will receive the notifications. The obligation binds any producer established in Norway whose products with digital elements are made available on the EU market, even though the act is not yet Norwegian law.

What must producers report, and on what timeline?

Manufacturers must report two categories of event through the SRP: actively exploited vulnerabilities in products with digital elements, and serious incidents affecting a product's security. Reporting runs in stages. An early notification must be sent without undue delay and no later than 24 hours after the producer becomes aware of the vulnerability or incident, followed by a more detailed message within 72 hours. For serious incidents, a final report is due within one month of the first notification; for actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective measure such as a security update becomes available. Nkom department director Espen Slette stressed that the CRA requires cybersecurity across the whole product lifecycle, including continuous security updates.

Report stageDeadlineApplies to
Early notificationWithin 24 hours of awarenessVulnerabilities and incidents
Detailed messageWithin 72 hoursVulnerabilities and incidents
Final report (incidents)Within 1 month of first notificationSerious security incidents
Final report (vulnerabilities)Within 14 days of a corrective measureActively exploited vulnerabilities

Why must Norwegian producers report to an EU member state?

The CRA is marked EEA-relevant but, as of September 11, 2026, has not been incorporated into the EEA Agreement or transposed into Norwegian law. Without that national legal basis, Norwegian authorities have no CRA competence to receive notifications, conduct market surveillance, or impose CRA sanctions. A producer established in Norway is nonetheless covered by Article 14 for products placed on the EU market, and under Article 14(7) the report must be channelled to a relevant EU member state based on the producer's authorised representative, importer, distributor, or user location.

Nkom is preparing to take on the supervisory role once the CRA is EEA-incorporated, and the government has signalled that Nkom will hold CRA oversight in Norway. Until then, Norwegian manufacturers and importers need a documented route to an EU counterpart today, not after a vulnerability surfaces.

Which products and actors does the CRA cover?

Products with digital elements are the scope: hardware and software products, including the remote processing solutions necessary for the product to function. Typical examples are PCs, routers, modems, smart TVs, smart watches, and IoT devices such as robot vacuum cleaners. Products already governed by sectoral EU law, including certain medical devices, aviation products, and vehicles, may be exempt; it falls to the producer, importer, and distributor to identify which regime applies to their product.

The reporting duty sits formally on the manufacturer, but importers carry the operational risk. An importer, defined as an entity established in the EU or EEA that brings a product with digital elements onto the market, must verify conformity assessment, CE marking, technical documentation, and the producer's vulnerability-management processes before placing the product on the market. Where a product may pose a significant cybersecurity risk, the importer must inform the producer and the relevant market-surveillance authority.

What should importers do before December 2027?

Most CRA obligations apply from December 11, 2027, when the horizontal cybersecurity requirements in Annex I, the user-information duties in Annex II, and the conformity-assessment procedures take full effect. Importers of radio-based IoT equipment must also navigate a transition period: the Radio Equipment Directive's cybersecurity requirements (Article 3.3 d, e, f) have applied since August 1, 2025, and the CRA will supersede those clauses for covered products once it applies from December 2027.

The practical priority now is the supplier agreement. Importers should fix, in writing, who notifies the SRP, how vulnerability and incident information is shared, which contact points apply, and how the importer accesses information on updates and incidents. Concrete steps include mapping which products fall under the CRA, classifying them as ordinary, important, or critical under Annexes III and IV, confirming the EU declaration of conformity and technical documentation exist, and establishing internal escalation routines tuned to the 24-hour deadline.

For compliance teams tracking rapid-fire product-security developments across jurisdictions, Obsidian's continuous per-jurisdiction monitoring surfaces a change like the Article 14 entry into force the moment the regulator publishes it, rather than after a manual sweep.

Subscribe to the free newsletter

Norway: Digital Services Act and Data Act EEA incorporationLive
Monitor Norway's EEA incorporation and national implementation of EU digital single-market rules for the digital governance industry, jurisdiction Norway.
Email report 10+ news
You will receive an email report each time something new happens on this topic. Free, no account required.
Subscribe to the newsletter

Act now: confirm whether your connected products place you within the CRA's Article 14 scope, map your reporting route to an EU member state if you are a Norwegian producer, lock the notification chain into supplier agreements, and brief your product-security team on the 24-hour, 72-hour, and final-report deadlines before a vulnerability forces the question. Obsidian watches this jurisdiction and dozens more, so your team acts on the next change the day it breaks.