CRA reporting starts 11 September 2026: what manufacturers need ready
A practical launch-readiness briefing for manufacturers before Cyber Resilience Act Article 14 reporting becomes mandatory.
What you need to know
From 11 September 2026, Cyber Resilience Act Article 14 reporting becomes mandatory for manufacturers that become aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements. The reporting sequence can begin with a 24-hour early warning, followed by a 72-hour notification and a path-specific final report through ENISA’s Single Reporting Platform.
Key takeaways
- Mandatory Article 14 reporting starts on 11 September 2026, before the CRA becomes fully applicable in December 2027.
- The two mandatory occurrence types are actively exploited vulnerabilities and severe incidents affecting product security.
- The first two statutory milestones are tied to awareness: an early warning within 24 hours and a fuller notification within 72 hours.
- Manufacturers submit through ENISA’s Single Reporting Platform, which is intended to be operational by the reporting start date.
What actually changes on 11 September 2026?
The CRA has been in force since December 2024, but its obligations start applying in stages. Article 14 reporting obligations are one of the early application dates. From 11 September 2026, manufacturers need an operational process for determining whether an occurrence fits one of the two mandatory reporting paths and for moving quickly enough to meet the first reporting milestones.
This matters because the reporting clock is not designed around the date your investigation finishes. Article 14 ties the 24-hour and 72-hour stages to the manufacturer becoming aware of the reportable occurrence.
Which occurrences trigger mandatory reporting?
The Regulation identifies two categories. The first is an actively exploited vulnerability contained in a product with digital elements. The second is a severe incident having an impact on the security of the product. Both routes use the Single Reporting Platform, but the content and final-report trigger differ.
A vulnerability merely existing is not the same as the CRA actively exploited vulnerability reporting trigger. Likewise, not every security event is automatically a severe incident under Article 14. Teams need a classification step that preserves uncertainty instead of turning an incomplete investigation into an overconfident legal conclusion.
What are the deadlines?
The first stage is an early warning without undue delay and, in any event, within 24 hours after awareness. Unless the relevant information has already been provided, a fuller vulnerability or incident notification follows within 72 hours after awareness.
The final stage is path-specific. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after the 72-hour incident notification is submitted.
What should manufacturers have ready before the date arrives?
The minimum useful preparation is not a giant policy document. It is a repeatable handoff between product security, engineering, legal and whoever owns regulatory submission.
- A named reporting owner. Someone must be responsible for getting a potentially reportable occurrence from internal escalation to the official submission workflow.
- A preserved awareness timestamp. Record when the organisation became aware, what was known at that point and where the timestamp came from.
- A classification checkpoint. Separate vulnerability exploitation questions from severe-incident questions and record unresolved facts explicitly.
- A staged information checklist. The 24-hour stage should not be treated as if the investigation must already contain every fact needed for the final report.
- An SRP handoff process. Know who will access the official platform and how prepared text will be reviewed before submission.
What does ENISA say about the Single Reporting Platform?
ENISA describes the SRP as the single entry point for CRA notifications. Its current FAQ says the platform is scheduled to be operational by 11 September 2026, with testing expected before that date. The manufacturer selects the relevant CSIRT coordinator and the platform handles the statutory routing.
The practical consequence is that your internal system does not need to become a replacement filing portal. It needs to get the facts, timestamps and staged reporting content into a reviewable state before the official submission.
What should you do this week?
Run one tabletop exercise using a realistic product-security scenario. Start the clock at a specific awareness timestamp, force the team to classify the occurrence with incomplete information, produce a 24-hour early warning, then identify what additional information would be required by the 72-hour stage. That exercise will expose ownership and data gaps faster than another generic compliance memo.
Official references
Verify against the live official sources
CRA Report is a preparation tool. Regulatory guidance and the ENISA reporting workflow can change, so final decisions and submissions should be checked against the current Regulation, Commission guidance and ENISA SRP documentation.