ambolt

CRA File / guide, updated 2026-10-05

CRA reporting obligations: 24 hours, 72 hours, final report

Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers to report two kinds of events. The duty applies from 11 September 2026, including for products that were already on the market before the main obligations start on 11 December 2027 (Articles 69 and 71).

What you must report

  1. An actively exploited vulnerability in your product: a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission.
  2. A severe incident that has an impact on the security of your product.

Deadlines

| Step | Actively exploited vulnerability | Severe incident | |---|---|---| | Early warning | Without undue delay and in any event within 24 hours of becoming aware | In any event within 24 hours | | Notification | In any event within 72 hours | In any event within 72 hours | | Final report | 14 days after a corrective or mitigating measure is available | One month after the incident notification |

To whom

Reports go to the CSIRT designated as coordinator in the Member State of your main establishment and, at the same time, to ENISA, through the single reporting platform that ENISA runs. The platform is for submitting reports; it does not draft them for you. If you have no establishment in the EU, other rules in Article 14 decide where to report.

What each report should contain (in short)

The 72-hour notification and the final report only need the information that you have not already provided. Reports about severe incidents have different content (Article 14(4)): a description of the incident, its severity and impact, the type of threat or root cause and the mitigation applied. Check Article 14 for the exact content; the lists above are a summary to prepare the facts you will need.

Prepare before it happens

You cannot invent these facts in a day. Keep ready: an owner for the process, a current SBOM (so you know which products and components are affected), a security contact and a disclosure policy, and a template for each of the three reports. The SBOM checker, the licence tool and the security.txt and policy generator cover the first parts.

Notes

Under Article 64, micro and small enterprises are not fined for missing the 24-hour deadline of the early warning; they must still submit it and meet all other deadlines and duties. Open-source stewards have lighter duties. Penalties differ by Member State and breach. This page is general information, not legal advice.

Free tools

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.