CRA vulnerability reporting — the 24-hour obligation that's already live

Since 11 September 2026, manufacturers of connected products must report actively exploited vulnerabilities within 24 hours. The three deadlines, how to report, penalties, and how to set up the process.

REVIEWED BY THE REGONANCE EDITORIAL TEAM

Most of the Cyber Resilience Act applies from December 2027. One part does not. Since 11 September 2026, manufacturers of products with digital elements have had to report actively exploited vulnerabilities and severe incidents to EU authorities — with an early warning within 24 hours of becoming aware of them.

This applies to connected products already on the market, not just new ones. If you sell own-brand smart devices, Bluetooth accessories, trackers or anything else with firmware in the EU, you are already subject to it. This guide explains the three reporting deadlines, what triggers them, how to report, and how to set up a process that can actually hit a 24-hour window.

Who has to report

The reporting obligation in Article 14 sits with the manufacturer. For private-label sellers that means you: under the CRA, placing a product on the market under your own name or trademark makes you the manufacturer, whoever built it — the same principle as GPSR Article 8(1) for product safety. We explain why in Article 21 — why the CRA treats private-label sellers as manufacturers.

It also covers products placed on the market before 11 December 2027. The CRA's other obligations don't apply retrospectively to those products, but the reporting duty does.

The two things you must report

Actively exploited vulnerabilities. A vulnerability is actively exploited when there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. A theoretical weakness found in a lab, or a researcher's proof of concept, is not enough on its own. Evidence that attackers are using it in the field is.

Severe incidents affecting the security of the product. An incident is severe if it harms, or could harm, the product's ability to protect the availability, authenticity, integrity or confidentiality of data or functions — or if it has led, or could lead, to malicious code being introduced into the product or your update systems. A compromised firmware update server is the textbook example.

The three deadlines

For an actively exploited vulnerability:

DeadlineWhat you send
Within 24 hours of becoming awareEarly warning — the product concerned and, where applicable, the Member States where you know it has been made available
Within 72 hoursVulnerability notification — general information about the product, the nature of the exploit and the vulnerability, any corrective or mitigating measures taken, measures users can take, and how sensitive you consider the information
Within 14 days after a corrective or mitigating measure is availableFinal report — a description of the vulnerability including its severity and impact, information about any malicious actor where available, and details of the security update or other corrective measures

For a severe incident, the early warning (24 hours) and the incident notification (72 hours) follow the same pattern, and the final report is due within one month of the 72-hour notification.

The clock starts when you become aware — not when you have confirmed the root cause. The early warning is deliberately short: you are telling authorities that something is happening, not explaining it.

How and where to report

Reports go through the single reporting platform established by ENISA, the EU cybersecurity agency. A notification is submitted to the CSIRT (computer security incident response team) designated as coordinator in the Member State where you have your main establishment, and it is made available to ENISA at the same time. If you have no main establishment in the EU, the CRA sets rules for which Member State's CSIRT applies — broadly, where your authorised representative is established, then your importer, then your distributor, then where most of your users are.

You must also inform affected users — and, where appropriate, all users — about the vulnerability or incident and any mitigation they can apply, in a structured, easy-to-use format.

In practice, check the current ENISA and national CSIRT guidance for the exact portal and account set-up before you need it. Registering after you discover an exploited vulnerability eats into the 24 hours.

What happens if you don't report

Failing to meet the manufacturer obligations in Articles 13 and 14 is one of the most heavily penalised breaches under the CRA: Member States can impose administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher.

Fines are only part of the risk. Market surveillance authorities can require corrective action, restrict the product, or order it withdrawn or recalled. And because reports reach authorities across the EU, an unreported exploited vulnerability that later becomes public creates a record that you knew and didn't act.

Setting up a process that can hit 24 hours

For most small brands, the hard part is not the report itself. It is knowing about the vulnerability in time, and having someone who can act on it at a weekend.

1. Know what you sell

Keep a list of every product with digital elements, with model numbers, firmware versions, the supplier behind each one, and the Member States you sell into. The early warning asks where the product has been made available. If you cannot answer quickly, you'll miss the window.

2. Get SBOMs from your suppliers

A Software Bill of Materials tells you which components are in each product. When a vulnerability is announced in a common library, the SBOM lets you check in minutes whether you are affected, instead of emailing a factory and waiting. From December 2027 the SBOM is mandatory anyway; getting it now also makes reporting workable.

3. Watch the right sources

Subscribe to vulnerability advisories for the chipsets, operating systems and major libraries in your SBOMs, and to your suppliers' security bulletins. Monitor your own support inbox and reviews — customers sometimes report compromised devices before anyone else does.

4. Publish a vulnerability contact point

The CRA requires a single point of contact where users and researchers can report vulnerabilities, and a coordinated vulnerability disclosure policy. A monitored security@ address and a short policy page on your site are the minimum.

5. Name an owner and a deputy

Someone must be able to decide, within hours, whether a report is an actively exploited vulnerability, and submit the early warning. Name the person, name a backup, and write the decision down in a one-page runbook.

6. Put your supplier on the clock

Your contract should require the factory to tell you within hours when it learns of an exploited vulnerability in your product, and to support the 72-hour and final reports with technical detail and a fix.

7. Rehearse once

Run a tabletop exercise: a researcher emails to say your camera's firmware is being exploited. Time how long it takes to identify the affected models, reach the supplier, and draft the early warning. Fix whatever slowed you down.

How this fits the rest of the CRA

Reporting is the first CRA obligation to apply, but it depends on the others: without an SBOM you can't tell whether you're affected, and without a support period and an update pipeline you can't fix what you report. The Cyber Resilience Act overview covers the full set that applies from 11 December 2027.

The EU Cyber Resilience Act Playbook (€49) includes the reporting timeline, the checklist for the vulnerability handling process and the SBOM template.

This guide is general information based on the published text of Regulation (EU) 2024/2847. ENISA and national authorities are still publishing practical guidance on the reporting platform — check it before relying on any detail here. It is not legal advice.

More on the Cyber Resilience Act

Need hands-on help? Our team can handle your compliance — from a €499 single-product scan to full catalogue management. Book a consultation →

CRA platform support coming soon — start with the 9 regulations we cover today

A free workspace checks your first three products against GPSR, CE marking, the Battery Regulation and six more EU regulations. CRA assessments join the platform next.

Start free workspace
Free · no account

Every EU deadline, on one page.

Nine mandates, each with dates attached between now and 2030. Get the calendar, plus a note when the guidance behind an article like this one changes.

  • → Every applicable EU compliance date
  • → Which mandate hits your category first
  • → An alert when a rule or guidance changes

No account needed. One-click unsubscribe. Or browse every deadline now →

Compliance guidance based on published EU regulatory texts. Not legal advice. Consult qualified counsel for your specific situation.