EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026)

Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform: early warning within 24 hours, notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents).

JurisdictionEuropean Union
CategoryCybersecurity
StatusActive
Effective date
Latest development

Analysis

The EU Cyber Resilience Act (CRA) vulnerability and incident reporting regime requires manufacturers of products with digital elements to use the ENISA Single Reporting Platform (SRP) from 11 September 2026 to submit a 24h early warning, 72h notification, and final report within 14 days (vulnerabilities) or 1 month (incidents), as set out in Regulation (EU) 2024/2847 and ENISA’s official SRP guidance.Regulation (EU) 2024/2847 – EUR‑LexConsolidated CRA TextENISA Single Reporting PlatformENISA SRP FAQ


Key Requirements

  • Obligation to report actively exploited vulnerabilities and severe incidents
  • Use of the ENISA Single Reporting Platform (SRP) as the single reporting channel
  • Three‑stage reporting: early warning, notification, final report
  • Applicability dates for reporting obligations
  • Scope: products with digital elements in the EU digital single market
  • Routing to national CSIRTs and ENISA

Compliance Challenges

  • Short reporting timelines and operational readiness
  • Determining “actively exploited” and “severe incident” thresholds
  • Integration with existing incident and vulnerability processes
  • Technical onboarding and testing of the SRP
  • Cross‑border coordination with multiple CSIRTs

Implementation Best Practices

  • Establish a CRA‑specific incident and vulnerability reporting playbook
  • Automate detection and classification workflows
  • Prepare for SRP onboarding and connectivity

Recent developments

  • — The European Commission’s CRA reporting page confirms that, as of 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA’s reporting process. It states the 24-hour early warning, 72-hour notification, and final report deadlines, and says the Single Reporting Platform will be operational by the reporting start date. (source)
  • — Intertek published a practical update explaining that Article 14 reporting begins on 11 September 2026 and detailing the phased deadlines for early warning, fuller notification, and final report. The article frames this as a major compliance milestone for manufacturers subject to the CRA. (source)
  • — Skadden’s client update highlights the same reporting timetable and notes that the CRA introduces new vulnerability and incident reporting duties for manufacturers of connected products. It presents the change as an immediate readiness issue for legal and compliance teams. (source)
  • — This industry update says reporting becomes mandatory on 11 September 2026, but warns that the ENISA Single Reporting Platform was still being prepared and testing was expected beforehand. It reflects industry concern that firms may face a short implementation window before the reporting deadline. (source)
  • — This policy commentary says the Commission’s implementation guidance arrived ahead of the 11 September 2026 reporting deadline and responds to concerns raised by cybersecurity stakeholders. It suggests the guidance is intended to reduce uncertainty before the CRA reporting obligations take effect. (source)
  • — Cloudsmith’s update focuses on engineering readiness and explains the operational impact of the reporting obligations on product teams. It emphasizes that teams need logging, triage, and patch workflows in place before the 24-hour and 72-hour deadlines begin. (source)
  • — The Commission’s main CRA policy page notes that the Act’s reporting obligations apply from 11 September 2026, while the broader obligations apply from 11 December 2027. This reinforces that the immediate regulatory change is the start of vulnerability and incident reporting. (source)
  • — The implementation fact page lists 11 September 2026 as the entry into application date for reporting obligations. It is a concise official confirmation of the deadline manufacturers are preparing for. (source)
  • — This item also captures a policy update: the Commission published implementation guidance that observers describe as the most substantial interpretive material so far. The update appears aimed at helping businesses operationalize the reporting framework before it goes live. (source)
  • — The Commission published new guidance to support CRA implementation, including context for the reporting obligations that start on 11 September 2026. Industry reaction around this guidance has centered on the need for clearer compliance interpretation before the first mandatory reporting date. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates