Skip to Content
ANALYSISMEMBER

Four clocks, one incident: What the CRA adds to EU incident notifications

The Cyber Resilience Act adds a fourth reporting layer, making initial incident narratives critical across EU compliance regimes.

Published
Subscribe to IAPP newsletters

Contributors:

Georgia Chatzitheodorou

CIPP/E, CIPP/US

Privacy Counsel

Athens Bar Associations

Beginning 11 Sept. 2026, one incident may start four EU notification clocks at once, but the practical risk is not timing. The first filing may become the official factual record against which every later notification, customer communication and regulatory explanation is assessed. For those responsible for incident response in the healthcare and medtech sectors, especially for software sold around medical devices rather than the devices themselves, the Cyber Resilience Act will add a fourth reporting layer to the NIS2 Directive, the EU General Data Protection Regulation and EU Medical Device Regulation vigilance. The European Commission's CRA application guidance of 27 July 2026, nonbinding and structured around numerous examples, indicates the complexity and practical significance of the reporting duties.

The clocks start at different moments, for different organizations. The shortest of them, the 24-hour notification deadline, usually starts running first for an organization other than the one against which every later account is read.

That organization is often the data center. Its legal position is split across those legal regimes. Under NIS2, it is directly regulated as digital infrastructure. Under the GDPR, it is almost always a processor, because storage is a personal data processing activity even where the provider never truly accesses the content (EDPB Guidelines 07/2020, para. 40). But the data center sits outside the product and patient-safety regimes that bind its customers. It has no CRA obligations for the devices whose backends it hosts and no MDR vigilance duties for incidents it may have caused. In many incidents, the data center is first to know and first to describe what happened, yet it is the least exposed under the product and patient-safety regimes triggered downstream. 

Contributors:

Georgia Chatzitheodorou

CIPP/E, CIPP/US

Privacy Counsel

Athens Bar Associations

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership