Four clocks, one incident: What the CRA adds to EU incident notifications

The Cyber Resilience Act adds a fourth reporting layer, making initial incident narratives critical across EU compliance regimes.

Contributors:
Georgia Chatzitheodorou
CIPP/E, CIPP/US
Privacy Counsel
Athens Bar Associations
Beginning 11 Sept. 2026, one incident may start four EU notification clocks at once, but the practical risk is not timing. The first filing may become the official factual record against which every later notification, customer communication and regulatory explanation is assessed. For those responsible for incident response in the healthcare and medtech sectors, especially for software sold around medical devices rather than the devices themselves, the Cyber Resilience Act will add a fourth reporting layer to the NIS2 Directive, the EU General Data Protection Regulation and EU Medical Device Regulation vigilance. The European Commission's CRA application guidance of 27 July 2026, nonbinding and structured around numerous examples, indicates the complexity and practical significance of the reporting duties.
The clocks start at different moments, for different organizations. The shortest of them, the 24-hour notification deadline, usually starts running first for an organization other than the one against which every later account is read.
That organization is often the data center. Its legal position is split across those legal regimes. Under NIS2, it is directly regulated as digital infrastructure. Under the GDPR, it is almost always a processor, because storage is a personal data processing activity even where the provider never truly accesses the content (EDPB Guidelines 07/2020, para. 40). But the data center sits outside the product and patient-safety regimes that bind its customers. It has no CRA obligations for the devices whose backends it hosts and no MDR vigilance duties for incidents it may have caused. In many incidents, the data center is first to know and first to describe what happened, yet it is the least exposed under the product and patient-safety regimes triggered downstream.
Contributors:
Georgia Chatzitheodorou
CIPP/E, CIPP/US
Privacy Counsel
Athens Bar Associations