Get in touch
CRA

Cyber Resilience Act: new vulnerability reporting rules

Published:

Short answer: since 11 September 2026, all manufacturers of products with digital elements placed on the EU market, regardless of size, must report actively exploited vulnerabilities and severe incidents affecting the security of their products. Reports are made on ENISA’s Single Reporting Platform (SRP). The remaining requirements of Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), apply from 11 December 2027.

Who is affected

  • Manufacturers of connected devices and IoT products
  • Businesses that develop and sell commercial software
  • Producers of operating systems, applications and security software
  • Suppliers of standalone software or hardware components
  • Businesses that outsource development but sell the product under their own name

The list comes from the National Cybersecurity Authority’s announcement. If you merely use such products in your business, the reporting obligation usually lies with the manufacturer, not with you. It is still worth asking your suppliers how they cover it.

What is reported and when

The three reporting stages
StageDeadlineWhat it contains
Early warningWithout undue delay and within 24 hoursNotice of an actively exploited vulnerability or a severe incident
Detailed notificationWithout undue delay and within 72 hoursAdditional information and an initial assessment of the situation
Final reportVulnerability: within 14 days of a corrective or mitigating measure becoming available. Severe incident: within one month of the 72-hour notificationCompletes the report

Source: the Authority’s announcement of 11 September 2026, as relayed by the press. The deadlines run from the moment the manufacturer becomes aware.

Where to report

Reports are submitted electronically on ENISA’s Single Reporting Platform, selecting the Authority’s EL-CSIRT as the receiving body. According to the announcement, manufacturers must also inform affected users and, where required, all users about the incident and the available protection or remediation measures. The platform and its instructions are maintained by ENISA, so always check the current version.

What does not apply yet

11 September 2026 is not the full application of the CRA. The essential cybersecurity requirements for products, the technical documentation obligations, the conformity assessment procedures and CE marking apply from 11 December 2027.

What to do now (our own practical advice)

  1. List which products with digital elements you make or sell under your own name: software, apps, devices, add-ons you sell.
  2. Appoint someone responsible for reports, and a deputy. The 24-hour deadline does not wait for holidays.
  3. Set up a process to receive vulnerability reports from customers and researchers, and ready templates for the three reports.
  4. Check your access to the SRP early, from ENISA’s up-to-date page, so you do not lose time within the 24 hours.
  5. Keep a way ready to inform your users about fixes and protective measures.

And if I do not make products?

Most small and medium businesses use products rather than make them. For them, the CRA means that the manufacturers of the products they buy now have vulnerability-handling and user-notification obligations. The National Cybersecurity Strategy 2026–2030 summarises this as security by design and vulnerability management across the product life cycle. The CRA does not replace your own obligations, such as those under NIS2 where you are in scope.

Frequently asked questions

Does the CRA apply to small businesses?

The reporting obligations that apply from 11 September 2026 concern all manufacturers of products with digital elements regardless of size, according to the Authority’s announcement.

When does the 24-hour deadline start?

From the moment the manufacturer becomes aware of the actively exploited vulnerability or the severe incident.

Where do I submit the report?

On ENISA’s Single Reporting Platform, selecting the Authority’s EL-CSIRT as the receiving body.

When do the other CRA requirements apply?

From 11 December 2027: essential cybersecurity requirements, technical documentation, conformity assessment and CE marking.