CRA reporting starts 11 September 2026
From that date, any manufacturer of a product with digital elements sold into the EU has 24 hours to file an early warning once it becomes aware that a vulnerability in its product is being actively exploited. Not 24 business hours. This page sets out what the obligation actually says, who it binds, and what to have in place before the date.
The reporting cascade
Article 14 sets four clocks, all of them running from the moment the manufacturer becomes aware — not from the moment it finishes investigating.
- 24 hours Early warningThat an actively exploited vulnerability or a severe incident exists. A holding notice: it does not need root cause or a fix.
- 72 hours Full notificationGeneral information on the vulnerability or incident, its nature, and any corrective or mitigating measures taken or available.
- 14 days Final report — vulnerabilitiesDue within 14 days of a corrective or mitigating measure becoming available.
- 1 month Final report — severe incidentsDue within one month of the full notification.
The 24-hour clock is the part teams underestimate. It presumes someone is already watching, already empowered to declare, and already knows which CSIRT to file with. Most hardware organisations have none of those three on a weekend.
Who it binds
Manufacturers of products with digital elements made available on the EU market. That is a deliberately wide category: software, IoT devices, industrial and OT systems, networking gear, connected appliances, and embedded systems.
Two points that catch teams out:
- Legacy products count. The duty attaches to products already on the market and still supported, not only to what ships after the date.
- Being outside the EU does not exempt you. Placing the product on the EU market is what triggers it.
Where the report goes
Manufacturers file once, through the CRA Single Reporting Platform. The notification goes to the CSIRT designated as coordinator in the member state of the manufacturer's main establishment, and reaches ENISA at the same time. The receiving CSIRT then forwards it without delay to the CSIRTs of other member states where the product is available.
Practically, that means one thing worth settling before September: know which CSIRT is yours, and know who in the organisation is authorised to press send at 2am.
The wider CRA timeline
- 10 Dec 2024Regulation (EU) 2024/2847 enters into force.
- 11 Jun 2026Chapter IV applies — notification of conformity assessment bodies.
- 27 Jul 2026European Commission publishes implementation guidance for manufacturers.
- 11 Sep 2026Article 14 reporting obligations apply.
- 11 Dec 2027Main obligations apply — CE marking, essential requirements, conformity assessment.
What to have ready
September is a reporting deadline, not a compliance deadline — the CE-marking work is a year further out. But the reporting duty is the one that can be triggered by someone else's disclosure, on someone else's schedule. A minimum posture before the date:
- A named on-call owner with authority to declare, and a documented deputy.
- The identity of your coordinating CSIRT, written down where the on-call owner can find it.
- A vulnerability intake channel that a researcher can actually reach — and that someone reads.
- A current inventory of supported products and their software components, so "which products are affected" is answerable in hours rather than weeks.
- A pre-drafted early-warning template, because 24 hours is not the time to start writing one.
Free tools to check where you stand
Three companion tools from Tangibles, all free and requiring no sign-up to run:
Primary sources
- European Commission — Cyber Resilience Act reporting obligations
- European Commission — Cyber Resilience Act overview
- European Commission — summary of the legislative text
- ETSI — consumer IoT security (EN 303 645)
Where this comes from. Chapter 18 of Tangibles — "Connected AND Secured? Think Again" — works through the attack surface across silicon, firmware, radios, and cloud, and Chapter 19 covers the regulatory response.
This page summarises publicly available regulatory material for product teams planning their readiness work. It is not legal advice, and it is not a substitute for reading Regulation (EU) 2024/2847 or taking qualified counsel on how it applies to a specific product. Last reviewed 4 August 2026.