Two kinds of event trigger reporting: an actively exploited vulnerability in a product with digital elements, and a severe incident having an impact on the security of the product. The manufacturer reports to the CSIRT designated as coordinator and to ENISA, through the single reporting platform, on a fixed clock.
CRA reporting has applied since 11 September 2026 and, under Article 69(3), covers all in-scope products including those placed on the market before 11 December 2027.
The clock
| Step | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Without undue delay, within 24 hours of becoming aware | Within 24 hours; says whether unlawful or malicious acts are suspected |
| Notification | Within 72 hours, unless already provided | Within 72 hours, unless already provided |
| Final report | No later than 14 days after a corrective or mitigating measure is available | Within one month after the 72-hour notification |
The CSIRT designated as coordinator may ask for an intermediate report (Article 14(6)). The manufacturer must also inform impacted users (Article 14(8)).
What counts
An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner (Article 3(42)). An incident is severe when it negatively affects, or can negatively affect, the ability of the product to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or when it has led or can lead to the introduction or execution of malicious code in the product or in a user’s network and information systems (Article 14(5)).
Where and to whom
Notifications go through the single reporting platform that ENISA operates under Article 16. They are submitted to the CSIRT designated as coordinator in the Member State of the manufacturer’s main establishment, and are made available to ENISA at the same time (Article 14(7)).
Waiting for the platform or for certainty. The deadlines run from the moment the manufacturer becomes aware. Prepare the process before the first case.
We help manufacturers turn this requirement into a process and evidence.
Related guidance
- Cyber Resilience Act (CRA): what it is and what it requires
- CRA timeline: what applies in 2026 and 2027
This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.