Final reporting stage

CRA Final Report

The final deadline is not the same for an actively exploited vulnerability and a severe security incident.

Actively exploited vulnerability

The final report is due no later than 14 days after a corrective or mitigating measure becomes available. It includes at least a description of the vulnerability including severity and impact, available information about malicious actors exploiting it, and details of the security update or other corrective measures.

Severe incident

The final report is due within one month after submission of the 72-hour incident notification. It includes at least a detailed description of the incident and its severity and impact, the threat type or likely root cause, and applied and ongoing mitigation measures.

This is why a final-report calculator needs path-specific trigger dates. Adding a fixed number of days to the initial awareness timestamp is not sufficient.

Keep the actual trigger date

For vulnerabilities, record when the corrective or mitigating measure became available. For severe incidents, record when the 72-hour notification was actually submitted. CRA Report uses those explicit dates to calculate the corresponding final milestone.

Official source

Read Article 14 in Regulation (EU) 2024/2847.