72-hour reporting

CRA 72-hour Notification

The second reporting stage expands the initial warning with product, occurrence, assessment and mitigation information.

For reportable actively exploited vulnerabilities and severe incidents, the CRA requires a fuller notification without undue delay and within 72 hours of awareness, unless the relevant information has already been provided.

For an actively exploited vulnerability

The notification provides available general information about the affected product, the general nature of the exploit and vulnerability, corrective or mitigating measures already taken, measures users can take and, where applicable, how sensitive the manufacturer considers the notified information.

For a severe security incident

The notification provides available general information about the nature of the incident, an initial assessment, corrective or mitigating measures taken, measures users can take and any applicable sensitivity indication.

Why preparation matters

Security, engineering, product and legal teams may hold different pieces of the required information. A structured preflight makes missing data visible early instead of discovering gaps during regulatory submission.

CRA Report intentionally separates the 24-hour, 72-hour and final stages so teams can see which information is needed now and which information can follow as the investigation develops.

Official sources

Regulation (EU) 2024/2847 and European Commission CRA reporting guidance.