CRA File / guide, updated 2026-10-05
CRA reporting obligations: 24 hours, 72 hours, final report
Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers to report two kinds of events. The duty applies from 11 September 2026, including for products that were already on the market before the main obligations start on 11 December 2027 (Articles 69 and 71).
What you must report
- An actively exploited vulnerability in your product: a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission.
- A severe incident that has an impact on the security of your product.
Deadlines
| Step | Actively exploited vulnerability | Severe incident | |---|---|---| | Early warning | Without undue delay and in any event within 24 hours of becoming aware | In any event within 24 hours | | Notification | In any event within 72 hours | In any event within 72 hours | | Final report | 14 days after a corrective or mitigating measure is available | One month after the incident notification |
To whom
Reports go to the CSIRT designated as coordinator in the Member State of your main establishment and, at the same time, to ENISA, through the single reporting platform that ENISA runs. The platform is for submitting reports; it does not draft them for you. If you have no establishment in the EU, other rules in Article 14 decide where to report.
What each report should contain (in short)
- Early warning: that the event is under way and, where applicable, the Member States where you know the product has been made available. Keep it short and fast.
- Notification: general information about the product, the general nature of the exploit and the vulnerability, any corrective or mitigating measures taken and measures users can take, and your assessment of severity and impact.
- Final report: a description of the vulnerability including its severity and impact, information about the actor if known, and details about the security update or other corrective measure.
The 72-hour notification and the final report only need the information that you have not already provided. Reports about severe incidents have different content (Article 14(4)): a description of the incident, its severity and impact, the type of threat or root cause and the mitigation applied. Check Article 14 for the exact content; the lists above are a summary to prepare the facts you will need.
Prepare before it happens
You cannot invent these facts in a day. Keep ready: an owner for the process, a current SBOM (so you know which products and components are affected), a security contact and a disclosure policy, and a template for each of the three reports. The SBOM checker, the licence tool and the security.txt and policy generator cover the first parts.
Notes
Under Article 64, micro and small enterprises are not fined for missing the 24-hour deadline of the early warning; they must still submit it and meet all other deadlines and duties. Open-source stewards have lighter duties. Penalties differ by Member State and breach. This page is general information, not legal advice.
Free tools
- Product classifier: Is your product in scope, and in which category?
- SBOM checker: Check a CycloneDX or SPDX file in your browser.
- security.txt and disclosure policy: The contact file and policy the Regulation expects.
- Repository check: what a GitHub repository already shows.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.