Cyber Resilience Act
Reporting obligations
Practical term
The reporting obligations sit in Article 14 and are the most time-critical requirement in the whole Cyber Resilience Act (CRA). They apply from 11 September 2026, more than a year before the regulation applies in full.
Two triggers
Two things must be reported, in each case as soon as the manufacturer becomes aware of them:
- any actively exploited vulnerability contained in the product
- any severe incident having an impact on the security of the product
Both go simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform established under Article 16.
The deadlines
Both triggers follow the same three-stage structure. Only the closing step differs:
- Within 24 hours the early warning is due. For vulnerabilities it names, where applicable, the Member States on whose territory the manufacturer is aware the product has been made available; for incidents it states at least whether unlawful or malicious action is suspected.
- Within 72 hours a notification follows with general information, as available, about the product, the nature of the exploitation or incident, and the measures taken.
- The final report is due, for vulnerabilities, no later than 14 days after a corrective or mitigating measure becomes available; for incidents, within one month of the 72-hour notification.
For the early warning and the 72-hour notification the clock starts on becoming aware, not when the event occurred.
Why 24 hours is the real problem
The deadline runs in calendar time. A report on Friday evening means a notification by Saturday evening, regardless of weekends, public holidays or holiday plans.
Meeting it requires three things settled in advance: who decides whether a finding crosses the threshold, who is reachable outside office hours and authorised to file, and whether the product details needed for the early warning are available without research.
The bottleneck is almost never technical. It is the decision, and it costs hours when it is first taken under pressure.
Informing users is a separate duty
Alongside notifying the authorities, the CRA requires informing users: the impacted users, and where appropriate all users, have to be told about the vulnerability or incident. Where necessary, that information covers the measures they can take themselves. Where appropriate it is given in a structured, machine-readable format that is easily automatically processable.
A report to authorities therefore does not replace that information. The two run in parallel and should be tracked separately in the process.
Practical questions
-
From 11 September 2026, well before the regulation applies in full on 11 December 2027. They are therefore the first CRA requirement to bite in practice, and the reason the processes behind them should be the first to be in place.
-
No. Only actively exploited vulnerabilities and severe incidents affecting product security are reportable. A vulnerability you find and close yourself, without anyone exploiting it, must be documented and fixed, but not reported.
-
You do, for your product. The duty attaches to the product you placed on the market, not to whoever wrote the code. The component maker reporting for its own product does not discharge your obligation for yours.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.