EU regulation

EU Cyber Resilience Act reporting has started: what software vendors must do now

Since 11 September 2026, anyone placing software or connected products on the EU market must report exploited vulnerabilities and severe incidents within 24 hours. Here is the runbook.

Short answer

Since 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for incidents.

Key takeaways

  • Reporting applies to products already on the EU market, not only new ones.
  • Three clocks: 24-hour early warning, 72-hour notification, then a final report.
  • One submission through ENISA's Single Reporting Platform reaches the relevant CSIRTs.
  • The rest of the CRA, including essential security requirements, applies from 11 December 2027.

What started on 11 September 2026

The Cyber Resilience Act (CRA) sets security requirements for hardware and software products with digital elements sold in the EU. Most of the regulation applies from 11 December 2027, but the reporting obligations in Article 14 applied first, on 11 September 2026. They cover every product already on the EU market, so a vendor with an existing customer base is in scope today.

Timeline

The CRA timeline

  1. CRA enters into force
  2. Article 14 reporting appliesENISA's Single Reporting Platform goes live.
  3. Full applicationEssential cybersecurity requirements and conformity assessment apply.

The three reporting clocks

StepActively exploited vulnerabilitySevere incident affecting product security
Early warningWithin 24 hours of becoming awareWithin 24 hours of becoming aware
NotificationWithin 72 hours, with corrective or mitigating measuresWithin 72 hours, with initial assessment
Final reportWithin 14 days after a corrective measure is availableWithin one month of the notification

Reports go through ENISA's Single Reporting Platform. You submit once; the notification is addressed to the CSIRT in the member state of your main establishment and shared with ENISA and the CSIRTs where the product is available.

What counts as reportable

  • An actively exploited vulnerability: there is reliable evidence that someone has exploited it in a product you make.
  • A severe incident: one that affects, or could affect, the product's ability to protect data or functions, or that led to malicious code in the product or its update mechanism.
  • A vulnerability you have found but that nobody has exploited is not reportable under Article 14, although you still have to fix it.

Build the runbook now

Checklist

CRA reporting runbook

0 of 7 done

Where your existing controls help

An ISO 27001 information security management system already expects incident management planning (), a defined response () and technical vulnerability management (). The CRA adds product-specific triggers and fixed deadlines, so the fastest route is to extend those procedures instead of writing new ones.

Frequently asked questions

Does the Cyber Resilience Act reporting duty apply to products already on sale?

Yes. Article 14 reporting applies from 11 September 2026 to products with digital elements already on the EU market, not only to products placed on the market after that date.

Where are CRA reports submitted?

Through ENISA's Single Reporting Platform. One submission reaches the CSIRT of the member state of main establishment and is made available to ENISA.

Sources

  1. Cyber Resilience Act: reporting obligations, European Commission
  2. The CRA Single Reporting Platform is launched, ENISA
  3. It's live: Cyber Resilience Act reporting is mandatory as of 11 September 2026, Crowell & Moring