CRA 24-hour Early Warning
What the first Article 14 reporting milestone is, when the clock starts, and what manufacturers should prepare.
The Cyber Resilience Act requires an early warning without undue delay and in any event within 24 hours after a manufacturer becomes aware of a reportable actively exploited vulnerability or severe incident affecting product security.
When does the 24-hour clock start?
The statutory text ties the deadline to the manufacturer becoming aware of the occurrence. That makes the recorded awareness time operationally important: incident teams should preserve the timestamp and basis for when organisational awareness was established.
What belongs in the early warning?
For both reporting paths, the early warning includes the occurrence type and, where applicable, the Member States where the manufacturer knows the product has been made available. For severe incidents, the CRA additionally requires at least an indication of whether unlawful or malicious acts are suspected.
Prepare before opening the SRP
A useful internal preparation packet includes the awareness time, manufacturer identity, affected product, known EU market availability, occurrence classification, a concise initial summary and the internal owner responsible for the notification.
Official sources
Read Regulation (EU) 2024/2847 on EUR-Lex and ENISA’s current SRP guidance.