CRA Article 14 guide

Cyber Resilience Act reporting obligations

The practical reporting timeline manufacturers need to understand before mandatory CRA incident reporting begins on 11 September 2026.

From 11 September 2026, the Cyber Resilience Act requires manufacturers to report two categories through the Single Reporting Platform established by ENISA: actively exploited vulnerabilities and severe incidents having an impact on the security of a product with digital elements.

Core timeline: early warning without undue delay and within 24 hours of awareness; fuller vulnerability or incident notification within 72 hours; then a path-specific final report.

The 24-hour early warning

For an actively exploited vulnerability, the early warning is due within 24 hours after the manufacturer becomes aware and should indicate, where applicable, the Member States where the affected product has been made available. For a severe incident, the early warning must additionally include at least whether unlawful or malicious acts are suspected.

The 72-hour notification

Unless the information has already been provided, the next notification is due within 72 hours of awareness. Vulnerability notifications include available general information about the product, the exploit and vulnerability, and corrective or mitigating measures. Incident notifications include available information about the nature of the incident, an initial assessment, and corrective or mitigating measures.

The final report is path-specific

For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after submission of the 72-hour incident notification.

Where notifications are submitted

Notifications are submitted through ENISA’s CRA Single Reporting Platform. The platform is intended as a single entry point that routes the notification to the relevant CSIRT coordinator and, subject to exceptional confidentiality provisions, ENISA.

Primary sources