EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026)
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform: early warning within 24 hours, notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents).
| Jurisdiction | European Union |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
The EU Cyber Resilience Act (CRA) vulnerability and incident reporting regime requires manufacturers of products with digital elements to use the ENISA Single Reporting Platform (SRP) from 11 September 2026 to submit a 24h early warning, 72h notification, and final report within 14 days (vulnerabilities) or 1 month (incidents), as set out in Regulation (EU) 2024/2847 and ENISA’s official SRP guidance.Regulation (EU) 2024/2847 – EUR‑LexConsolidated CRA TextENISA Single Reporting PlatformENISA SRP FAQ
Key Requirements
- Obligation to report actively exploited vulnerabilities and severe incidents
- The CRA imposes mandatory reporting for “actively exploited vulnerabilities” and “severe incidents having an impact on the security of products with digital elements” on manufacturers and certain open‑source software stewards.Regulation (EU) 2024/2847 – Publications OfficeConsolidated CRA TextENISA SRP FAQ
- ENISA confirms that manufacturers of products with digital elements and open‑source software stewards must report these events via the SRP.ENISA Single Reporting PlatformENISA SRP FAQENISA CRA SRP Factsheet (PDF)
- Use of the ENISA Single Reporting Platform (SRP) as the single reporting channel
- Under CRA, notifications must be submitted through the ENISA Single Reporting Platform, which serves as a single EU reporting tool used by CSIRTs and manufacturers.Regulation (EU) 2024/2847 – EUR‑LexENISA Single Reporting PlatformCRA Vulnerability and Incident Reporting Guide
- ENISA describes the SRP as the platform through which manufacturers meet their reporting obligations under Article 14 CRA.ENISA SRP FAQENISA CRA SRP Factsheet (PDF)ENISA SRP Factsheet (alternate)
- Three‑stage reporting: early warning, notification, final report
- ENISA states that manufacturers must follow three main deadlines:
- Early warning: within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.ENISA SRP FAQENISA CRA SRP Factsheet (PDF)CRA Vulnerability and Incident Reporting Guide
- Actively exploited vulnerability / severe incident notification: within 72 hours of becoming aware, including general information and an initial assessment.ENISA SRP FAQENISA CRA SRP Factsheet (PDF)CRA Vulnerability and Incident Reporting Guide
- Final report:
- For vulnerabilities: no later than 14 days after a corrective measure (e.g. patch) becomes available.ENISA SRP FAQENISA CRA SRP Factsheet (PDF)CRA Vulnerability and Incident Reporting Guide
- For severe incidents: within 1 month after the 72‑hour notification.ENISA SRP FAQENISA CRA SRP Factsheet (PDF)CRA Vulnerability and Incident Reporting Guide
- Applicability dates for reporting obligations
- The CRA provides that reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, while the rest of the regulation generally applies from 11 December 2027.Regulation (EU) 2024/2847 – EUR‑LexConsolidated CRA TextRegulation (EU) 2024/2847 – Publications Office
- ENISA explicitly notes that the SRP is scheduled to be operational from 11 September 2026, aligned with the reporting obligations under Article 14 CRA.ENISA SRP FAQENISA Single Reporting PlatformENISA CRA SRP Factsheet (PDF)
- Scope: products with digital elements in the EU digital single market
- The CRA sets horizontal cybersecurity requirements for products with digital elements placed on the EU market.Regulation (EU) 2024/2847 – EUR‑LexConsolidated CRA TextRegulation (EU) 2024/2847 – Publications Office
- ENISA clarifies that reporting covers products with digital elements sold or made available in the EU Digital Single Market.ENISA Single Reporting PlatformENISA CRA SRP Factsheet (PDF)CRA Guide – CyberResilienceAct.eu
- Routing to national CSIRTs and ENISA
- ENISA’s factsheet explains that each SRP notification can automatically send information to the national CSIRT designated as the coordinator, other concerned CSIRTs, and ENISA.ENISA CRA SRP Factsheet (PDF)ENISA Single Reporting PlatformENISA SRP FAQ
Compliance Challenges
- Short reporting timelines and operational readiness
- The combination of 24h early warning and 72h notification is identified by practitioners as one of the most demanding operational aspects of CRA compliance.ENISA SRP FAQCRA Vulnerability and Incident Reporting GuideEU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm Analysis
- Legal commentary highlights that organizations must detect, triage, and classify events very quickly to meet these deadlines.EU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm AnalysisCRA Guide – CyberResilienceAct.euCRA Vulnerability and Incident Reporting Guide
- Determining “actively exploited” and “severe incident” thresholds
- CRA’s definitions require judgment to determine when a vulnerability is “actively exploited” or an incident is “severe”, creating classification challenges for manufacturers.Consolidated CRA TextRegulation (EU) 2024/2847 – Publications OfficeEU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm Analysis
- Industry guidance notes that misclassification can lead either to under‑reporting (regulatory risk) or over‑reporting (operational burden).CRA Vulnerability and Incident Reporting GuideCRA Guide – CyberResilienceAct.euEU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm Analysis
- Integration with existing incident and vulnerability processes
- Many organizations already have incident response processes for NIS2, GDPR, and sector‑specific rules; aligning these with CRA’s SRP‑based reporting can be complex.NIS2 Directive – EUR‑LexGDPR – EUR‑LexCRA Guide – CyberResilienceAct.eu
- Commentary stresses that multiple overlapping reporting channels (data protection authorities, CSIRTs, regulators) can cause confusion and duplicative work unless coordinated.EU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm AnalysisCRA Vulnerability and Incident Reporting GuideCRA Guide – CyberResilienceAct.eu
- Technical onboarding and testing of the SRP
- ENISA indicates that the SRP will be operational from 11 September 2026, and practical guidance notes that onboarding and testing will be necessary before use.ENISA Single Reporting PlatformENISA SRP FAQENISA CRA SRP Factsheet (PDF)
- Industry analysis reports that as of mid‑2026 the SRP was not yet live, raising concerns about compressed testing windows for manufacturers.With Reporting Due on 11 September 2026, ENISA’s SRP Not Yet LiveENISA Single Reporting PlatformCRA Evidence – SRP Onboarding
- Cross‑border coordination with multiple CSIRTs
- ENISA notes that SRP notifications can be routed to multiple national CSIRTs where products are available, requiring organizations to maintain accurate market data and contact structures.ENISA CRA SRP Factsheet (PDF)ENISA Single Reporting PlatformENISA SRP FAQ
- Guidance suggests that tracking the geographical distribution of products and relevant CSIRTs is challenging for large portfolios.CRA Vulnerability and Incident Reporting GuideCRA Guide – CyberResilienceAct.euEU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm Analysis
Implementation Best Practices
- Establish a CRA‑specific incident and vulnerability reporting playbook
- Organizations should build a dedicated CRA playbook that maps detection, triage, decision‑making, and reporting steps to the 24h/72h/14‑day/1‑month deadlines.CRA Vulnerability and Incident Reporting GuideEU CRA: Preparing for Vulnerability and Incident Reporting – Law Firm AnalysisCRA Guide – CyberResilienceAct.eu
- Best‑practice guidance recommends integrating this playbook with existing incident response frameworks such as ISO/IEC 27035 or internal security policies.ISO/IEC 27035 Incident Management – ISO OverviewCRA Guide – CyberResilienceAct.euCRA Vulnerability and Incident Reporting Guide
- Automate detection and classification workflows
- To meet 24‑hour deadlines, guidance suggests automating ingestion from vulnerability scanners, SIEM/SOAR systems, and threat intelligence, combined with CRA‑specific classification logic.CRA Vulnerability and Incident Reporting GuideENISA SRP FAQENISA CRA SRP Factsheet (PDF)
- Tools such as SIEM platforms and vulnerability management suites are frequently referenced as enablers for timely reporting.ENISA Good Practices for CSIRTs – Incident ManagementISO/IEC 27001 & 27002 – Information Security ManagementCRA Guide – CyberResilienceAct.eu
- Prepare for SRP onboarding and connectivity
- ENISA provides helpdesk contact and technical information to support SRP onboarding, and specialized guidance maps registration and integration steps for manufacturers.ENISA CRA SRP Factsheet (PDF)ENISA Single Reporting PlatformCRA Evidence – SRP Onboarding
- Implementers recommend testing SRP workflows during
Recent developments
- — The European Commission’s CRA reporting page confirms that, as of 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA’s reporting process. It states the 24-hour early warning, 72-hour notification, and final report deadlines, and says the Single Reporting Platform will be operational by the reporting start date. (source)
- — Intertek published a practical update explaining that Article 14 reporting begins on 11 September 2026 and detailing the phased deadlines for early warning, fuller notification, and final report. The article frames this as a major compliance milestone for manufacturers subject to the CRA. (source)
- — Skadden’s client update highlights the same reporting timetable and notes that the CRA introduces new vulnerability and incident reporting duties for manufacturers of connected products. It presents the change as an immediate readiness issue for legal and compliance teams. (source)
- — This industry update says reporting becomes mandatory on 11 September 2026, but warns that the ENISA Single Reporting Platform was still being prepared and testing was expected beforehand. It reflects industry concern that firms may face a short implementation window before the reporting deadline. (source)
- — This policy commentary says the Commission’s implementation guidance arrived ahead of the 11 September 2026 reporting deadline and responds to concerns raised by cybersecurity stakeholders. It suggests the guidance is intended to reduce uncertainty before the CRA reporting obligations take effect. (source)
- — Cloudsmith’s update focuses on engineering readiness and explains the operational impact of the reporting obligations on product teams. It emphasizes that teams need logging, triage, and patch workflows in place before the 24-hour and 72-hour deadlines begin. (source)
- — The Commission’s main CRA policy page notes that the Act’s reporting obligations apply from 11 September 2026, while the broader obligations apply from 11 December 2027. This reinforces that the immediate regulatory change is the start of vulnerability and incident reporting. (source)
- — The implementation fact page lists 11 September 2026 as the entry into application date for reporting obligations. It is a concise official confirmation of the deadline manufacturers are preparing for. (source)
- — This item also captures a policy update: the Commission published implementation guidance that observers describe as the most substantial interpretive material so far. The update appears aimed at helping businesses operationalize the reporting framework before it goes live. (source)
- — The Commission published new guidance to support CRA implementation, including context for the reporting obligations that start on 11 September 2026. Industry reaction around this guidance has centered on the need for clearer compliance interpretation before the first mandatory reporting date. (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cybersecurity Act Revision (CSA2) — European Union, Proposed
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: Cyber Resilience Act CRA Policy (cyberpolicy.shop)
- Build it yourself: EU Cyber Resilience Act Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates