EU Cyber Resilience Act (CRA)
Mandatory Vulnerability & Incident Reporting starts 11 September 2026
From the 11th September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act (CRA).
The EU Cyber Resilience Act (CRA) – Regulation (EU) 2024/2847 introduces mandatory cybersecurity requirements for products with digital elements placed on the European Union market.
While the CRA’s main product cybersecurity obligations become fully applicable from 11 December 2027, an important requirement takes effect much earlier.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting their products with digital elements.
This means manufacturers should not wait until 2027 to prepare for CRA compliance. Appropriate vulnerability monitoring, incident response, escalation and regulatory reporting processes need to be established before September 2026.
What Must Manufacturers Report?
Actively Exploited Vulnerabilities
An actively exploited vulnerability is a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner.
Manufacturers therefore need processes capable of identifying vulnerabilities affecting their products and determining whether reliable evidence of active exploitation exists.
Severe Security Incidents
A cybersecurity incident may be considered severe where it negatively affects, or is capable of negatively affecting, the product’s ability to protect the availability, authenticity, integrity or confidentiality of important data or functions. It may also qualify where malicious code has been, or could be, introduced or executed in the product or the user’s network and information systems.
CRA Reporting Timeline
Once a manufacturer becomes aware of a reportable actively exploited vulnerability or severe incident, the CRA establishes strict notification deadlines.
Reporting Stage | Deadline | Main Requirement |
|---|---|---|
Early Warning | Within 24 hours | Initial notification after becoming aware of the vulnerability or incident. |
Vulnerability / Incident Notification | Within 72 hours | Provide available information regarding the vulnerability or incident, its impact and mitigation measures. |
Final Report - Actively Exploited Vulnerability | Within 14 days after a corrective or mitigating measure becomes available | Provide details of the vulnerability, impact and security update or corrective measures. |
Final Report - Severe Incident | Within one month after the 72-hour incident notification | Provide detailed incident information, root cause or threat information and mitigation measures. |
The short 24-hour and 72-hour reporting windows mean manufacturers need clearly defined internal escalation procedures. Cybersecurity, engineering, product management, compliance and management teams should understand who is responsible for assessing an event and initiating regulatory reporting.
CRA Single Reporting Platform
Notifications will be submitted through the CRA Single Reporting Platform (SRP) established, managed and maintained by the European Union Agency for Cybersecurity (ENISA).
The SRP provides manufacturers with a central electronic reporting mechanism rather than requiring separate notifications to multiple national authorities. The notification is directed to the relevant Computer Security Incident Response Team (CSIRT) and is simultaneously accessible to ENISA, subject to the specific provisions of the CRA.
For manufacturers with a main establishment in the EU, the relevant CSIRT is generally determined based on the Member State where cybersecurity decisions concerning the manufacturer’s products are predominantly taken. The CRA also establishes specific rules for manufacturers without a main establishment in the EU.
For more information, please refer to the official source below.
Manufacturers Must Also Inform Affected Users
Regulatory reporting is not the only obligation.
After becoming aware of an actively exploited vulnerability or severe security incident, manufacturers are also required to inform impacted users and, where appropriate, all users. Where necessary, this communication should explain risk-mitigation or corrective measures that users can take to reduce the impact of the vulnerability or incident.
Manufacturers therefore need to consider both regulatory notification procedures and customer security communication procedures as part of their CRA readiness activities.
Does the September 2026 Requirement Apply to Existing Products? | What Should Manufacturers Do Before 11 September 2026? |
|---|---|
This is an important consideration for manufacturers. The European Commission indicates that CRA reporting obligations apply to products with digital elements made available on the EU market, including products already placed on the market before the CRA becomes fully applicable on 11 December 2027. Manufacturers should therefore review their existing product portfolio rather than focusing only on products planned for launch after 2027. | With the reporting deadline approaching, manufacturers should establish and review their CRA cybersecurity processes, including:
These processes should form part of the manufacturer's wider product cybersecurity and vulnerability-handling framework. |
Does the September 2026 Requirement Apply to Existing Products?
This is an important consideration for manufacturers.
The European Commission indicates that CRA reporting obligations apply to products with digital elements made available on the EU market, including products already placed on the market before the CRA becomes fully applicable on 11 December 2027.
Manufacturers should therefore review their existing product portfolio rather than focusing only on products planned for launch after 2027.
What Should Manufacturers Do Before 11 September 2026?
With the reporting deadline approaching, manufacturers should establish and review their CRA cybersecurity processes, including:
- Identifying products with digital elements within CRA scope
- Establishing vulnerability monitoring and vulnerability disclosure processes
- Maintaining visibility of software and third-party components
- Defining criteria for identifying actively exploited vulnerabilities and severe incidents
- Establishing 24-hour and 72-hour internal escalation and reporting procedures
- Assigning responsible personnel for CRA notifications
- Preparing access and responsible users for the ENISA Single Reporting Platform
- Establishing incident investigation and evidence-retention procedures
- Implementing security update and vulnerability remediation processes
- Preparing procedures to communicate vulnerabilities, incidents and mitigation measures to affected users
These processes should form part of the manufacturer’s wider product cybersecurity and vulnerability-handling framework.
How C-PRAV Can Support Your CRA Readiness
Preparing for the Cyber Resilience Act requires more than product cybersecurity testing. Manufacturers need appropriate technical security controls together with documented processes for vulnerability management, incident response and post-market cybersecurity activities.
C-PRAV can support manufacturers and product developers in preparing for EU cybersecurity requirements through cybersecurity compliance assessment, vulnerability and penetration testing, cybersecurity gap assessments, vulnerability-management guidance and CRA readiness support.
C-PRAV’s cybersecurity services also cover standards including EN 18031 and EN 303 645.
With mandatory CRA reporting beginning on 11 September 2026, manufacturers placing products with digital elements on the EU market should review their cybersecurity and incident-reporting processes now.
Related Resources
European Cyber Resilience Act (CRA)
The European Cyber Resilience Act (CRA) establishes a robust legal framework to enhance the cybersecurity of hardware and software products with digital elements in the European Union (EU). Designed to address the increasing prevalence of cyberattacks and vulnerabilities in connected devices, the CRA sets clear and enforceable requirements for manufacturers, importers, and distributors, ensuring security across the entire lifecycle of these products. What is the Cyber Resilience Act? Adopted
FCC Selects Lead Administrator for Cybersecurity Label Program
The Public Safety and Homeland Security Bureau (Bureau) announces the selection of UL LLC (UL Solutions) to serve as both the Lead Administrator as well as a Cybersecurity Label Administrator (CLA) for the Federal Communications Commission’s (FCC or Commission) Internet of Things Cybersecurity Labeling Program (IoT Labeling Program) which includes the U.S. government certification mark (U.S. Cyber Trust Mark). Official Notification
Cyber Resilience Act: Council Approves New Legislation for Digital Products
The Council approved new legislation on cybersecurity requirements for products with digital components, aimed at ensuring the safety of items like connected home cameras, refrigerators, TVs, and toys before they are introduced to the market (Cyber Resilience Act), on 10th Oct 2024. The new legislation, targeting manufacturers, distributors, and importers of hardware and software, seeks to enhance the security of digital products across Europe. The Cyber Resilience Act will ensure: