CRApreparedContact us

Cyber Resilience Act

CRA reporting obligations: 24 hours, 72 hours and final report

Since 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents that affect the security of their products. An early warning is due within 24 hours of becoming aware, a notification within 72 hours and a final report later, through the ENISA single reporting platform.

Written by: CRAprepared teamExpert: Dejan TropLast reviewed: 2 min read
In short

Two kinds of event trigger reporting: an actively exploited vulnerability in a product with digital elements, and a severe incident having an impact on the security of the product. The manufacturer reports to the CSIRT designated as coordinator and to ENISA, through the single reporting platform, on a fixed clock.

CRA reporting has applied since 11 September 2026 and, under Article 69(3), covers all in-scope products including those placed on the market before 11 December 2027.

The clock

StepActively exploited vulnerabilitySevere incident
Early warningWithout undue delay, within 24 hours of becoming awareWithin 24 hours; says whether unlawful or malicious acts are suspected
NotificationWithin 72 hours, unless already providedWithin 72 hours, unless already provided
Final reportNo later than 14 days after a corrective or mitigating measure is availableWithin one month after the 72-hour notification

The CSIRT designated as coordinator may ask for an intermediate report (Article 14(6)). The manufacturer must also inform impacted users (Article 14(8)).

What counts

An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner (Article 3(42)). An incident is severe when it negatively affects, or can negatively affect, the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or when it has led or can lead to the introduction or execution of malicious code in the product or in a user’s network and information systems (Article 14(5)).

Where and to whom

Notifications go through the single reporting platform that ENISA operates under Article 16. They are submitted to the CSIRT designated as coordinator in the Member State of the manufacturer’s main establishment, and are made available to ENISA at the same time (Article 14(7)).

Common mistake

Waiting for the platform or for certainty. The deadlines run from the moment the manufacturer becomes aware. Prepare the process before the first case.

Relevant service

We help manufacturers turn this requirement into a process and evidence.

See the service (Slovenian)

Related guidance

Written by: CRAprepared teamExpert: Dejan Trop, Cybersecurity strategistLast reviewed: Editorial policy

This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.

Will your product be CRA prepared?

CRA reporting obligations have applied since 11 September 2026. Most CRA requirements apply from 11 December 2027. We work with manufacturers in Slovenia and across the EU. Write to us in English or Slovenian.