Blog – Inside Translation with tolingo

Cyber Resilience Act: which documents have to be multilingual

Written by Jessi | August 2026
Home Blog Cyber Resilience Act: which documents have to be multilingual

Compliance · 6 min read

Cyber Resilience Act: which documents have to be multilingual from 11 September

User information under Annex II, safety instructions, the declaration of conformity and the reporting deadlines at a glance.

Four rows: user information under Annex II in the language of users in the market, the EU declaration of conformity in the language required by the member state, technical documentation on request from the authority, and incident communications in the language of the affected users. Four document types, four language rules Regulation (EU) 2024/2847, as at 31 August 2026 User information Annex II, Art. 13(18) Language of users in that market Declaration of conformity Art. 28, template in Annex V As the member state requires Technical documentation Art. 13(22) On request from the authority Incident communications Art. 14(8) Language of affected users Which language rule applies to which document, with the article reference for each.

In brief

  • As of 11 September 2026 the reporting duties under Art. 14 of Regulation (EU) 2024/2847 apply to actively exploited vulnerabilities and severe security incidents.
  • The cascade runs 24 hours for the early warning, 72 hours for the notification, then a final report: within 14 days for a vulnerability, within one month for an incident.
  • User information under Annex II has to be in a language the users can easily understand, and the EU declaration of conformity in the language the member state requires.
  • The regulation applies in full from 11 December 2027. There is still time for the language versions, but not for incident communications.

What changes on 11 September

The Cyber Resilience Act, Regulation (EU) 2024/2847, comes into application in stages. The first milestone that affects manufacturers was 11 September 2026, when the reporting duties under Art. 14 took effect. Anyone making a product with digital elements available on the Union market has to report an actively exploited vulnerability or a severe security incident to the relevant CSIRT and to ENISA. Full application, including CE marking and conformity assessment, follows on 11 December 2027.

For documentation this matters because the report itself is a process, but everything attached to it is text. Affected users have to be informed under Art. 14(8), and informed in a way they understand. For a product sold in eight markets that means eight language versions of a notice that has to be written within hours. This is a description of the legal position, not legal advice.

The reporting deadlines

Stage Deadline Clock starts Content
Early warning 24 hours becoming aware brief first notice, including whether a vulnerability is being actively exploited
Notification 72 hours becoming aware nature of the vulnerability or incident, corrective or mitigating measures taken
Final report, vulnerability 14 days a corrective or mitigating measure becomes available description, severity, impact, remediation
Final report, incident One month the 72-hour notification incident description, type of threat or likely root cause, countermeasures

The asymmetry in the last two rows is easy to miss: for a vulnerability the clock starts when a fix exists, for an incident it starts from the earlier notification. Reports go through the single reporting platform that ENISA operates under Art. 16. The text of the regulation is on EUR-Lex, and the German federal cyber security agency BSI publishes a practical summary in German.

User information under Annex II

Annex II lists the information and instructions that have to come with the product: the name and identification of the product, the manufacturer's contact details, the contact point for reporting vulnerabilities, the intended purpose, the known risks under foreseeable misuse, details of security updates, guidance on secure commissioning and decommissioning, and the end date of the support period.

Under Art. 13(18) this material has to be in a language that users and market surveillance authorities can easily understand. In practice that means the local language of each target market: an English manual does not cover the French market. Retention matters too. The information stays available for at least ten years after the product is placed on the market, or for the support period if that is longer. A language version that goes offline after three years does not meet that.

What this usually calls for is technical translation with a maintained termbase, so that safety instructions stay worded the same way across product generations. Which parts of the technical documentation have to be translated is covered under specialist translation.

Declaration of conformity and technical documentation

The EU declaration of conformity under Art. 28 follows the template in Annex V. It is drawn up in the languages required by the member state where the product is placed or made available on the market. For Germany that is German, for France French. With software the CE marking can sit on the declaration or on the accompanying website, which turns that website into a document with a language obligation.

Technical documentation stays in English at many companies. Under Art. 13(22) the market surveillance authority can require, on a reasoned request, that the material is supplied in a language it can easily understand. If you sell in several member states, keep the most frequently requested sections ready for translation rather than producing them in two weeks when the request arrives.

How this sits alongside the Machinery Regulation

Connected machinery also falls under Regulation (EU) 2023/1230 from 20 January 2027. Its language rules stand on their own and are set out in our overview of the Machinery Regulation, so documentation in mechanical engineering is affected twice over. Each regulation calls for its own declaration, but a shared termbase still saves work.

Incident communications under time pressure

The hardest part is the message to users. It has to be written at the moment everyone else is dealing with the incident, it is legally sensitive, and it has to exist in several languages quickly. Improvising here produces versions that drift apart.

What helps is a set of approved building blocks: a short first notice, a version with the mitigation, and an all-clear. Those three can be translated into every target language in advance and filled in with a handful of variables when the time comes. For fast updates, post-editing to ISO 18587 works well, because the source text has already been reviewed. For the first version of the building blocks, specialist translation is the right choice.

The channels are affected as well: support pages, release notes and the product interface. If you publish the notice on your site, you need the website in the same languages, and with software the interface too if a message appears there.

Questions

Do the reporting duties cover products already on the market?

The duty attaches to products with digital elements made available on the Union market. For how that applies to your particular portfolio, the text of the regulation governs, together with the Commission's guidance. This is a description of the legal position, not legal advice.

Does the report to the authority have to be translated?

The report to the CSIRT and ENISA is an official filing with its own language requirements. The language versions that matter in practice are the notice to users and the accompanying product documents.

Is English enough for the whole single market?

For user information, usually not. The test is whether users in that market can easily understand it, and the member state sets that. For technical documentation English is often sufficient, unless the authority asks for something else.

How long does a language version of the user information take?

With a maintained termbase and a translation memory from the previous version, a typical manual takes a few working days per language. Without that groundwork the first version takes longer, because the terms have to be agreed first. For an assessment of your volume, get in touch through contact; the rates are under prices.

Terms

Cyber Resilience Act
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. Reporting duties since 11 September 2026, full application on 11 December 2027.
Actively exploited vulnerability
A vulnerability with reliable evidence that it is being exploited. A known vulnerability that is not being exploited does not start the 24-hour clock.
EU declaration of conformity
The manufacturer's declaration under Art. 28, following the template in Annex V. It is drawn up in the languages the relevant member state requires.
Technical documentation
The material that demonstrates conformity. It can be kept internally in one working language; on a reasoned request from the authority a comprehensible language version has to be supplied.
ISO 27001
The standard for information security management systems. Relevant to how documents and incident information are handled at a service provider.

The next step

To find out which of your documents are missing in which languages, send us a list of your target markets and one sample document. We will map what exists and what has to be in place for 11 December 2027.

To put your documentation in context: services overview and certifications.

Related

Last updated: 1 September 2026. Legal position as at 31 August 2026, checked against the text of the regulation on EUR-Lex. EU deadlines can move.

Contents

Your contact

Peer Bosse

We reply within ~10 minutes (within business hours).

service@tolingo.com
0800 55 133 00

Document check in five lines

  • target markets and official languages listed
  • user information under Annex II complete
  • EU declaration of conformity in place per market
  • building blocks for incident communications approved
  • ten-year availability of the language versions settled