Cyber Resilience Act reporting obligations
The practical reporting timeline manufacturers need to understand before mandatory CRA incident reporting begins on 11 September 2026.
From 11 September 2026, the Cyber Resilience Act requires manufacturers to report two categories through the Single Reporting Platform established by ENISA: actively exploited vulnerabilities and severe incidents having an impact on the security of a product with digital elements.
The 24-hour early warning
For an actively exploited vulnerability, the early warning is due within 24 hours after the manufacturer becomes aware and should indicate, where applicable, the Member States where the affected product has been made available. For a severe incident, the early warning must additionally include at least whether unlawful or malicious acts are suspected.
The 72-hour notification
Unless the information has already been provided, the next notification is due within 72 hours of awareness. Vulnerability notifications include available general information about the product, the exploit and vulnerability, and corrective or mitigating measures. Incident notifications include available information about the nature of the incident, an initial assessment, and corrective or mitigating measures.
The final report is path-specific
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after submission of the 72-hour incident notification.
Where notifications are submitted
Notifications are submitted through ENISA’s CRA Single Reporting Platform. The platform is intended as a single entry point that routes the notification to the relevant CSIRT coordinator and, subject to exceptional confidentiality provisions, ENISA.