EU Cyber Resilience Act reporting is live: the 24-hour clock
On 11 September 2026 the vulnerability and incident reporting obligations in Article 14 of the EU Cyber Resilience Act (CRA) became applicable, and ENISA launched the Single Reporting Platform that manufacturers must use to file notifications. Most of the CRA’s product security requirements do not apply until December 2027, but the reporting duty is here now. If your organisation makes hardware or software sold in the EU, including from the UK or India, it deserves a place on this quarter’s risk agenda.
What now applies
Manufacturers of products with digital elements made available on the EU market must now report two kinds of event:
- Actively exploited vulnerabilities in their products.
- Severe incidents having, or potentially having, a significant impact on the security of the product or its users.
According to Crowell & Moring and TechNode Global, the reporting sequence is:
- An early warning within 24 hours of becoming aware.
- A fuller notification within 72 hours.
- A final report within 14 days of a corrective or mitigating measure being available for an exploited vulnerability, or within 30 days of the 72-hour notification for a severe incident.
Notifications go through ENISA’s Single Reporting Platform. ENISA explains that a manufacturer submits once, and the designated CSIRT coordinator shares the information with CSIRTs in the Member States where the product is available, while ENISA is notified at the same time. Crowell & Moring notes that the obligation also covers products already on the market. ENISA confirms that the main CRA cyber security requirements apply from 11 December 2027.
- In force since
- 11 September 2026 (reporting obligations).
- Who
- Manufacturers of hardware and software products with digital elements on the EU market, wherever they are based.
- How
- ENISA’s Single Reporting Platform.
- Full application
- 11 December 2027.
Why the 24-hour clock is harder than it looks
When a vendor learns that a flaw in its product is being exploited, it is already under intense pressure to investigate, fix and communicate with customers. Under the CRA, a manufacturer in that position also has a 24-hour window to warn the EU authorities. That is only achievable if the process exists before the incident does.
The practical challenges tend to fall into four areas:
- Knowing when the clock starts. “Becoming aware” needs a defined internal meaning, with timestamps.
- Knowing who presses send. Crowell & Moring recommends identifying your main establishment and competent CSIRT coordinator, and appointing primary and backup people with round-the-clock cover and platform access set up in advance.
- Knowing what is in your product. Exploited flaws often sit in third-party or open-source components. Without a software bill of materials, you may not realise you are affected.
- Joining it up with other regimes. The same event may also trigger GDPR breach notification, NIS2 incident reporting or customer contractual notices, each with different thresholds and clocks.
“You cannot build a 24-hour reporting process during the first 24 hours of an incident.”
— Praeferre analysisWhat to do now
- Confirm scope. List products with digital elements you place on the EU market, including software and connected devices, and who the “manufacturer” is for each.
- Register and rehearse. Set up access to the Single Reporting Platform for named people, with multi-factor authentication, and run a tabletop exercise.
- Define triggers and timestamps. Write down what counts as awareness, an actively exploited vulnerability and a severe incident, and log decisions as they are made.
- Prepare templates. Pre-draft early warning, 72-hour and final report content so responders fill in facts rather than write from scratch.
- Tighten supplier obligations. Require component and software suppliers to notify you promptly of vulnerabilities, and track them through your third-party risk programme.
- Map overlapping regimes. Build one incident playbook that routes to CRA, GDPR, NIS2 and, in the UK, the forthcoming Cyber Security and Resilience Bill requirements.
Praeferre’s GRC automation platform helps teams run unified incident and vulnerability workflows with evidence captured as they go, and our penetration testing services help find weaknesses before attackers do. Browse our supported frameworks.
Build one incident and vulnerability reporting workflow for CRA, GDPR and NIS2.
Explore GRC automationCommon questions
Yes, if they are manufacturers of products with digital elements made available on the EU market. The CRA applies based on where products are sold, not where the manufacturer is based.
Actively exploited vulnerabilities in a manufacturer’s products and severe incidents affecting product security, with an early warning within 24 hours, a notification within 72 hours and a final report later.
The main cyber security requirements for products apply from 11 December 2027.
Sources
- The CRA Single Reporting Platform is launched — ENISA, 11 September 2026
- EU Cyber Resilience Act Reporting Now Live — Crowell & Moring, 11 September 2026
- EU Cyber Resilience Act 24-hour vulnerability reporting rules take effect — TechNode Global, 12 September 2026


