Clear answers for the moments when the CRA clock matters.
Operational reporting guidance, regulatory updates and source-backed explanations for product security teams preparing for the EU Cyber Resilience Act.
CRA reporting starts 11 September 2026: what manufacturers need ready
A practical launch-readiness briefing for manufacturers before Cyber Resilience Act Article 14 reporting becomes mandatory.
Read the briefingBuilt to be useful before it is quotable.
Each article starts with a concise answer, then shows the operational detail and official sources behind it.
The first hour of a potentially reportable CRA incident
What a product security team should preserve, classify and assign before the 24-hour CRA reporting window becomes an operational problem.
What timestamps and evidence should you preserve for CRA reporting?
A practical evidence checklist for awareness time, mitigations, 72-hour submission and final-report trigger dates under the CRA.
What to prepare before opening ENISA’s Single Reporting Platform
An operational preflight for manufacturers preparing a CRA vulnerability or severe-incident notification before entering the official SRP.
No content mill. No regulatory guessing.
Have a live incident instead of a research question?
Run the assessment and turn the facts you have into a likely reporting path before you open the official portal.