Compliance · 6 min read
User information under Annex II, safety instructions, the declaration of conformity and the reporting deadlines at a glance.
Four rows: user information under Annex II in the language of users in the market, the EU declaration of conformity in the language required by the member state, technical documentation on request from the authority, and incident communications in the language of the affected users. Four document types, four language rules Regulation (EU) 2024/2847, as at 31 August 2026 User information Annex II, Art. 13(18) Language of users in that market Declaration of conformity Art. 28, template in Annex V As the member state requires Technical documentation Art. 13(22) On request from the authority Incident communications Art. 14(8) Language of affected users Which language rule applies to which document, with the article reference for each.The Cyber Resilience Act, Regulation (EU) 2024/2847, comes into application in stages. The first milestone that affects manufacturers was 11 September 2026, when the reporting duties under Art. 14 took effect. Anyone making a product with digital elements available on the Union market has to report an actively exploited vulnerability or a severe security incident to the relevant CSIRT and to ENISA. Full application, including CE marking and conformity assessment, follows on 11 December 2027.
For documentation this matters because the report itself is a process, but everything attached to it is text. Affected users have to be informed under Art. 14(8), and informed in a way they understand. For a product sold in eight markets that means eight language versions of a notice that has to be written within hours. This is a description of the legal position, not legal advice.
| Stage | Deadline | Clock starts | Content |
|---|---|---|---|
| Early warning | 24 hours | becoming aware | brief first notice, including whether a vulnerability is being actively exploited |
| Notification | 72 hours | becoming aware | nature of the vulnerability or incident, corrective or mitigating measures taken |
| Final report, vulnerability | 14 days | a corrective or mitigating measure becomes available | description, severity, impact, remediation |
| Final report, incident | One month | the 72-hour notification | incident description, type of threat or likely root cause, countermeasures |
The asymmetry in the last two rows is easy to miss: for a vulnerability the clock starts when a fix exists, for an incident it starts from the earlier notification. Reports go through the single reporting platform that ENISA operates under Art. 16. The text of the regulation is on EUR-Lex, and the German federal cyber security agency BSI publishes a practical summary in German.
Annex II lists the information and instructions that have to come with the product: the name and identification of the product, the manufacturer's contact details, the contact point for reporting vulnerabilities, the intended purpose, the known risks under foreseeable misuse, details of security updates, guidance on secure commissioning and decommissioning, and the end date of the support period.
Under Art. 13(18) this material has to be in a language that users and market surveillance authorities can easily understand. In practice that means the local language of each target market: an English manual does not cover the French market. Retention matters too. The information stays available for at least ten years after the product is placed on the market, or for the support period if that is longer. A language version that goes offline after three years does not meet that.
What this usually calls for is technical translation with a maintained termbase, so that safety instructions stay worded the same way across product generations. Which parts of the technical documentation have to be translated is covered under specialist translation.
The EU declaration of conformity under Art. 28 follows the template in Annex V. It is drawn up in the languages required by the member state where the product is placed or made available on the market. For Germany that is German, for France French. With software the CE marking can sit on the declaration or on the accompanying website, which turns that website into a document with a language obligation.
Technical documentation stays in English at many companies. Under Art. 13(22) the market surveillance authority can require, on a reasoned request, that the material is supplied in a language it can easily understand. If you sell in several member states, keep the most frequently requested sections ready for translation rather than producing them in two weeks when the request arrives.
Connected machinery also falls under Regulation (EU) 2023/1230 from 20 January 2027. Its language rules stand on their own and are set out in our overview of the Machinery Regulation, so documentation in mechanical engineering is affected twice over. Each regulation calls for its own declaration, but a shared termbase still saves work.
The hardest part is the message to users. It has to be written at the moment everyone else is dealing with the incident, it is legally sensitive, and it has to exist in several languages quickly. Improvising here produces versions that drift apart.
What helps is a set of approved building blocks: a short first notice, a version with the mitigation, and an all-clear. Those three can be translated into every target language in advance and filled in with a handful of variables when the time comes. For fast updates, post-editing to ISO 18587 works well, because the source text has already been reviewed. For the first version of the building blocks, specialist translation is the right choice.
The channels are affected as well: support pages, release notes and the product interface. If you publish the notice on your site, you need the website in the same languages, and with software the interface too if a message appears there.
The duty attaches to products with digital elements made available on the Union market. For how that applies to your particular portfolio, the text of the regulation governs, together with the Commission's guidance. This is a description of the legal position, not legal advice.
The report to the CSIRT and ENISA is an official filing with its own language requirements. The language versions that matter in practice are the notice to users and the accompanying product documents.
For user information, usually not. The test is whether users in that market can easily understand it, and the member state sets that. For technical documentation English is often sufficient, unless the authority asks for something else.
With a maintained termbase and a translation memory from the previous version, a typical manual takes a few working days per language. Without that groundwork the first version takes longer, because the terms have to be agreed first. For an assessment of your volume, get in touch through contact; the rates are under prices.
To find out which of your documents are missing in which languages, send us a list of your target markets and one sample document. We will map what exists and what has to be in place for 11 December 2027.
To put your documentation in context: services overview and certifications.