Read this if your company makes anything with a chip, a circuit board, or firmware in it and any of it ends up in Europe. On September 11, 2026, a European law starts requiring the makers of connected products to report an actively exploited flaw in one of their products within 24 hours, and it reaches across the Atlantic to a machine-shop owner in Thomasville who has never sold direct to a European customer, as long as a product they build reaches the EU market. The rule is Article 14 of the EU Cyber Resilience Act, and it applies to any manufacturer that places a product with digital elements on the EU market regardless of where that manufacturer sits, including products already placed on that market, per the European Commission. For the Piedmont Triad, this is not a rounding error: North Carolina's goods trade with the EU runs into the billions each year.
Key takeaway: The reporting clock starts September 11, 2026: an early warning within 24 hours and a fuller notification within 72 hours, both timed from when you become aware, then a final report (14 days after a corrective or mitigating measure for an exploited vulnerability, one month for a severe incident). The financial penalties do not begin until December 11, 2027, per Pearl Cohen. That 15-month gap is the window to build a process, not permission to ignore it, because a reportable flaw does not wait for a compliance calendar.
Not sure whether anything you build falls under this, or who inside your shop would even file the report? Preferred Data Corporation has kept North Carolina manufacturers running and defended since 1987, from its home base in the Piedmont Triad. Call (336) 886-3282 or book a compliance and security review.
Does the EU Cyber Resilience Act apply to a North Carolina manufacturer?
It applies if you place a product with digital elements on the EU market, and the rule reaches you regardless of where your company sits, per the European Commission. "Place on the market" covers products that reach Europe through a distributor or an importer, and you need no European office or customer of your own for the obligation to attach. A product that reaches the EU only as a component is a subtler case: the duty may be yours or the integrator's depending on who places the finished product on the market, so pin that down in writing (see the FAQ below). A non-EU manufacturer can appoint an EU-established authorised representative for certain market-surveillance and documentation tasks, but the Article 14 reporting obligations cannot be delegated to a representative and stay with you as the manufacturer.
A "product with digital elements" is broad on purpose: it covers hardware and software whose intended use includes a data connection to a device or network, from a smart thermostat to an industrial PLC to the firmware in a connected sensor. For a North Carolina reader, the honest scoping question is not "am I a tech company" but "does anything I make contain software or connect to anything, and does it end up in the EU." A furniture maker in High Point whose adjustable-desk motor controller ships inside products sold in Europe is closer to the line than the owner assumes. A textile plant near Gastonia running purely mechanical looms and selling only domestically is not in scope at all.
Here is the part that trips people: the obligation follows the product even after you stop selling it. Reporting duties "continue to apply after a product is no longer supported," per Pearl Cohen. The discontinued controller you shipped in 2023 is still your reporting responsibility if it is still running in a plant in Rotterdam and a flaw in it gets exploited.
North Carolina is not a bystander here. The state's goods exports hit $43.8 billion in 2025, with the European Union taking $10.0 billion of that, per the U.S. Trade Representative. Manufacturing is the third-largest contributor to the state economy, generating $83.5 billion in GDP in 2025, per the North Carolina Department of Commerce. A meaningful slice of that output is connected hardware, and every unit of it that reaches the EU market carries this obligation home to Greensboro, Hickory, and Winston-Salem.
What exactly do you have to report, and how fast?
Two things trigger a report: an actively exploited vulnerability in one of your products, and a severe incident affecting the security of one of your products. When either happens, you notify a designated national Computer Security Incident Response Team (CSIRT) and the European Union Agency for Cybersecurity (ENISA), per Pearl Cohen. The timeline is measured in hours and stacked.
| Deadline | What you owe | Why it is hard for a small shop |
|---|---|---|
| 24 hours | Early warning that the flaw is being exploited or the incident happened | You have to notice it first, which means someone is watching |
| 72 hours | Fuller notification with technical detail and any corrective steps | Your engineers are still diagnosing while the clock runs |
| Final report | Within 14 days of a corrective or mitigating measure for an actively exploited vulnerability, or within one month for a severe incident | Requires a fix path, not an apology |
The 24/72/14 structure is Article 14 of the regulation, and the early warning is due within 24 hours of the manufacturer becoming aware of active exploitation, per the Cyber Resilience Act text. The word "aware" is doing quiet work in that sentence. You cannot report what you never detected, so the practical foundation of compliance is monitoring, a reporting inbox, and a named person who owns the clock. In our experience across the Piedmont Triad, a lot of 40-person to 200-person NC manufacturers do not yet have all three in place.
How heavy is this really for a small manufacturer? Less than the headlines suggest, for now. The full sweep of CRA design obligations, including secure-by-design engineering and a software bill of materials, do not become the general rule until December 11, 2027, per Pearl Cohen. What starts September 11, 2026 is narrower: the duty to report actively exploited flaws and severe incidents. The alarm system is due first; the rest of the house gets built over the next year.
When does the Cyber Resilience Act actually start costing money?
The penalties are large, and they arrive later than the reporting duty. Non-compliance with the manufacturer obligations in Articles 13 and 14 can draw fines of up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, per the Cyber Resilience Act text. Those penalty provisions apply from December 11, 2027, when the regulation reaches general application.
Here is where a lot of NC owners will make the wrong call. The reporting duty lands September 11, 2026; the fines that give it teeth start about 15 months later. A shop that reads "no fines until 2027" and files this under next year's problem is misreading the risk. The reason to build the process this quarter is not the fine: the first time you have a reportable exploited vulnerability, you get 24 hours, and you cannot stand up detection, a CSIRT contact, and an escalation path in a panic. The penalty is the least of it, since a European customer or importer refusing your product for want of CRA readiness will bite long before a regulator does.
What should a 60-person NC manufacturer do before it has a reportable flaw?
Start with scope, because some shops that assume they are safe are squarely in scope and some that panic are not. Work the list in order:
- Inventory what you make that has software or connectivity in it. Firmware in a controller counts, so does a companion mobile app or a cloud dashboard that pairs with your device.
- Trace where those products go. Ask your distributors and OEM customers, in writing, whether your product reaches the EU market. If it goes there directly, the manufacturer obligations are yours. If it arrives only as a component inside someone else's finished product, the duties may fall to you or the integrator, so pin the allocation down in writing.
- Stand up a way to learn about vulnerabilities in your own products. A monitored security contact, a coordinated disclosure channel, and someone who reads vendor and CISA advisories for the components inside your product.
- Write down the 24-hour path now. Who declares a reportable event, who drafts the early warning, who files with the coordinating national CSIRT and ENISA (which is standing up a single reporting platform for these notifications), and who notifies your impacted users. Article 14 requires informing affected users of the vulnerability or incident and any mitigation or corrective steps they can apply, a separate duty from the regulator filing, so build both into the runbook. A one-page runbook beats a heroic scramble.
- Build toward a software bill of materials. You will need to know what open-source and third-party code sits in your firmware before December 2027 anyway, and it is the most useful artifact you can have when a flaw in a shared component gets exploited.
Key takeaway: The manufacturers who will handle their first reportable flaw calmly are the ones who did the boring work first: an inventory, a monitored inbox, a named owner, and a one-page runbook. That requires no European lawyer, only deciding this quarter that a 24-hour clock is not something you improvise.
Ready to figure out your exposure and build a reporting process that actually works on a factory floor? Preferred Data Corporation is at 1208 Eastchester Drive, Suite 131, High Point, NC 27265. Call (336) 886-3282 or start with a security and compliance assessment.
The part your compliance binder will not tell you
The CRA is going to expose how little most shops know about the software inside their own products: controller firmware from a vendor acquired twice, a connectivity module running an old Linux build nobody has patched since it shipped. None of that mattered when the product was a black box you shipped and forgot. The CRA turns it into a standing obligation, and shops that treated embedded software as someone else's problem get caught flat-footed.
Handing this to a lawyer is the expensive way to get it half-right. For most small NC manufacturers the CRA is not primarily a legal project; it is an engineering and IT visibility project with a legal deadline attached. You cannot report a flaw you cannot see, in code you did not know you were running. Fix the visibility and the compliance mostly follows. That visibility half, the monitoring, the component inventory, and the reporting runbook the duty runs on, is the part a managed IT and security partner can own, alongside whatever legal help the scope call needs.
Questions NC exporters are asking about the CRA
Does the EU Cyber Resilience Act apply to a US company with no EU office? Yes, if you place a product with digital elements on the EU market, directly or through a distributor or importer, regardless of where the manufacturer is located, per the European Commission. If it reaches the EU only as a component in someone else's finished product, the duty may fall to the integrator instead (see the US-OEM question below). No EU office is required.
What is the deadline I need to know? September 11, 2026 for the vulnerability and incident reporting duties, and December 11, 2027 for the full set of secure-design obligations and the penalty regime, per Pearl Cohen. The reporting clock is the one that starts first.
How fast do I have to report a flaw? An early warning within 24 hours of becoming aware of active exploitation, a fuller technical notification within 72 hours, and a complete report within 14 days once a corrective or mitigating measure is available, per the Cyber Resilience Act text.
What are the penalties if we get it wrong? Up to 15 million euros or 2.5% of total worldwide annual turnover for breaches of the core manufacturer and reporting obligations, whichever is higher, per the Cyber Resilience Act text. Those penalties apply from December 11, 2027.
We only sell to a US OEM. Are we off the hook? Not necessarily, and this is the case most NC sub-suppliers get wrong. The test is what the OEM does with your part: if it integrates your component into a new finished product sold in the EU, the OEM generally carries the manufacturer obligations for that product, while your obligations track the component you placed on the market. Ask your OEM, in writing, whether your part reaches the EU and who they treat as the manufacturer of the finished product. A close call is worth a lawyer's read.
Related resources
- Managed cybersecurity for North Carolina businesses
- Custom and embedded software development
- Manufacturing IT and OT solutions
- Operational efficiency solutions
- Vendor Risk Management in the AI Age: NC Business Guide
- OT Security in the AI Age: Protecting NC Factory Networks
The honest Monday-morning move is not to call a lawyer. It is to pull every product you make that has software or a connection in it, ask your distributors in writing whether any of it reaches Europe, and name one person who owns the 24-hour clock if the answer is yes. Preferred Data Corporation helps North Carolina manufacturers across the Piedmont Triad turn that from a fire drill into a process. Call (336) 886-3282 or request a compliance and security review.