To: Heads of technology, information security and compliance at licensed operators and at the suppliers who sell to them
From: The Gaming Boardroom
Date: 23 September 2026
Subject: Article 14 of the EU Cyber Resilience Act, applying since 11 September 2026
Article 14 of the EU Cyber Resilience Act started to apply on 11 September 2026, putting a 24-hour reporting clock on the manufacturer of any product with digital elements sold into the European Union, which includes cabinets, terminals, kiosks and the apps operators publish under their own brand. This is not the part of the Act that arrives in 2027. It applies now to products that have been in the field for years, and the party who files is whoever markets the product under its own name, which for a white-label app is the operator rather than the supplier.
Key Takeaways
- Article 14 of Regulation (EU) 2024/2847 has applied since 11 September 2026, so a manufacturer now has 24 hours from learning that a vulnerability in its product is being actively exploited to warn the coordinating national CSIRT and ENISA, 72 hours for the full notification, and 14 days after a fix for the final report.
- The duty reaches backwards. Article 69(3) applies Article 14 to every product already placed on the market before 11 December 2027, so cabinets, terminals and apps that have been in the field for years are in scope now, while the CE marking and design duties are still two years away.
- Whoever markets the product under its own name or trademark is the manufacturer under Article 3(13), so an operator publishing a white-label app under its own brand files the report itself. Article 64(2) puts the maximum fine for getting Article 14 wrong at EUR 15,000,000 or 2.5 per cent of worldwide annual turnover, whichever is the higher figure.
What actually changed on 11 September 2026?
The reporting half of the Act came into force, and ENISA opened the Single Reporting Platform the same day, so a manufacturer files once and that filing reaches the coordinating national CSIRT and ENISA together. Nothing else in Regulation (EU) 2024/2847 moved, since the essential requirements in Annex I, the conformity assessment and the CE marking all wait until 11 December 2027, which is a large part of why suppliers have been filing the regulation under next year’s budget.
The part that is live is also the only part written to catch what is already installed. Article 69(2) exempts a product placed on the market before 11 December 2027 unless it is substantially modified afterwards, and Article 69(3) then writes Article 14 back out of that exemption, so a cabinet shipped in 2019 and an app published in 2023 both sit under the 24-hour clock today.
Who files the report, you or your platform supplier?
The party who files is whoever put their name on it. Article 3(13) defines a manufacturer as the person who develops a product, or has it developed, and markets it under its own name or trademark, so the question is not who wrote the code but whose brand is on the app store listing and on the cabinet. An operator running a white-label casino app under its own brand is the manufacturer of that app, and the supplier behind it is not. Article 22 gives the same status to anyone who substantially modifies a product and makes it available.
The one real exemption is narrow, because an operator whose games run only in a browser is not placing a product on the market by running a website, and very few operators of any size stop there.
How does the EU clock sit against the clocks already in your incident plan?
They sit badly together, because the four clocks start at different moments, run at different speeds and go to different people.
| Rule | Who it binds | Deadlines | What starts the clock |
| EU Cyber Resilience Act, Article 14 | The manufacturer of the product, meaning whoever markets it under its own name | 24 hours early warning, 72 hours notification, final report 14 days after a fix (one month for a severe incident) | Knowing that a vulnerability in the product is being actively exploited, or that a severe incident is affecting the product’s security |
| EU NIS2 Directive, Article 23 | Essential and important entities, where a member state’s implementation catches the business | 24 hours early warning, 72 hours notification, final report within one month | Becoming aware of a significant incident at the entity itself |
| Nevada Regulation 5.260 | Nonrestricted, race book, sports pool and interactive gaming licensees | 24 hours to notify the Board, written report within 5 calendar days, written updates every 30 days until resolved | Activating the response procedures in the licensee’s own cybersecurity incident response plan |
| Great Britain, LCCP 15.2.1 | All Gambling Commission licensees | 5 working days | Awareness of a breach that could harm the confidentiality of customer data, or that blocks account access for more than 12 hours |
One incident can start all four at once, and the shortest clock belongs to whoever sits furthest from your incident room. When a supplier files an Article 14 early warning, a national CSIRT and ENISA have been told that a product you run is being exploited, and if nobody rang you first, your own regulator can hear it by a route you do not control. That is a contract problem rather than a technical one, and it is fixable this month.
Recommended Actions
- Build the product register first: one line per app, cabinet, terminal, kiosk and downloadable client you sell or publish into an EU market, with the brand it carries, the market and the year it was placed on the market.
- Mark manufacturer status against every line using the name on the product, not the name on the development contract. Anything under your own brand is yours to report.
- Put a notice-before-filing clause into supplier contracts at the next renewal, naming the role that makes the call and the number it rings out of hours, so you hear before ENISA does.
- Draw one notification clock map for every licence you hold, with the trigger, the deadline, the recipient and the format for each. TGB’s Cybersecurity Incident Response Playbook (GBP 499, Cybersecurity & Tech Innovation) runs the 24 to 72 hour response itself, and the clock map is the page it does not yet carry.
- Rehearse against an incident that starts at a supplier rather than inside your own estate, because that is the version where the first warning arrives from someone else’s lawyer and the 24 hours are already running.
Questions for Managers
- Which products do we place on the EU market under our own brand, and who is named to file an Article 14 early warning at two in the morning?
- If our platform supplier learned today that a flaw in the product we run was being exploited, does our contract make them tell us before they tell ENISA?
- Can we produce on one page every notification deadline a single cyber incident would start across our licences, with an owner against each?
- What is our evidence that 24 hours is achievable rather than assumed, and when did we last put a clock on a rehearsal?
Sources
1. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Article 14 (reporting obligations of manufacturers). EUR-Lex.
2. Regulation (EU) 2024/2847, Article 3(13) (definition of manufacturer) and Article 3(1) and 3(2) (product with digital elements, remote data processing). EUR-Lex.
3. Regulation (EU) 2024/2847, Article 22 (cases in which the obligations of manufacturers apply to other persons, substantial modification). EUR-Lex.
4. Regulation (EU) 2024/2847, Article 64(2) (penalties: EUR 15,000,000 or 2.5 per cent of total worldwide annual turnover). EUR-Lex.
5. Regulation (EU) 2024/2847, Article 69(2) and 69(3) (transitional provisions, and the application of Article 14 to products placed on the market before 11 December 2027). EUR-Lex.
6. Regulation (EU) 2024/2847, Article 71(2) (Article 14 applies from 11 September 2026). EUR-Lex.
7. ENISA, The CRA Single Reporting Platform is launched, 11 September 2026. https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched
8. European Commission, Cyber Resilience Act: reporting obligations, Shaping Europe’s digital future. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
9. Directive (EU) 2022/2555 (NIS2), Article 23(4)(a) to (d) (early warning, incident notification, intermediate and final reports). EUR-Lex.
10. Nevada Gaming Commission Regulation 5.260, Cybersecurity, adopted and effective 29 January 2026. Nevada Gaming Control Board. https://www.gaming.nv.gov/
11. Gambling Commission (Great Britain), Notification of information security breaches, and Licence Condition 15.2.1 (reporting key events). https://www.gamblingcommission.gov.uk/licensees-and-businesses/guide/notification-of-information-security-breaches