CRA 72-hour Notification
The second reporting stage expands the initial warning with product, occurrence, assessment and mitigation information.
For reportable actively exploited vulnerabilities and severe incidents, the CRA requires a fuller notification without undue delay and within 72 hours of awareness, unless the relevant information has already been provided.
For an actively exploited vulnerability
The notification provides available general information about the affected product, the general nature of the exploit and vulnerability, corrective or mitigating measures already taken, measures users can take and, where applicable, how sensitive the manufacturer considers the notified information.
For a severe security incident
The notification provides available general information about the nature of the incident, an initial assessment, corrective or mitigating measures taken, measures users can take and any applicable sensitivity indication.
Why preparation matters
Security, engineering, product and legal teams may hold different pieces of the required information. A structured preflight makes missing data visible early instead of discovering gaps during regulatory submission.
Official sources
Regulation (EU) 2024/2847 and European Commission CRA reporting guidance.