Article 14 ยท Regulation (EU) 2024/2847

What are the CRA reporting obligations?

Verified against the Official Journal text on

Manufacturers must report two things: any actively exploited vulnerability in their product, and any severe incident affecting its security, each notified simultaneously to the CSIRT designated as coordinator and to ENISA through the single reporting platform. The clock runs in three stages: an early warning within 24 hours, a notification within 72 hours, and a final report (within 14 days after a corrective measure is available for a vulnerability, within one month of the notification for an incident). You must also inform affected users. These duties apply from 11 September 2026.

Basis: Art. 14(1)-(4), Art. 14(8), Art. 16, Art. 71(2)

Judgment call: The single reporting platform is established by ENISA under Article 16 and goes live with the reporting duties. Exact submission format and procedures may be refined by implementing acts (Art. 14(10)).

What must be reported, and to whom Art. 14(1), Art. 14(3), Art. 14(5), Art. 14(7)

Two triggers create a mandatory report. The first is an actively exploited vulnerability contained in the product. The second is a severe incident having an impact on the security of the product. In both cases the manufacturer notifies the CSIRT designated as coordinator and ENISA at the same time, using the single reporting platform established under Article 16.

The CRA defines when an incident is "severe": where it negatively affects, or can affect, the product's ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or where it has led, or can lead, to malicious code being introduced or executed in the product or in a user's network and information systems.

The three-stage clock Art. 14(2), Art. 14(4)

For both triggers the timeline is the same at the front: an early warning notification without undue delay and in any event within 24 hours of becoming aware, then a fuller notification within 72 hours. The 24-hour early warning is a short alert; the 72-hour notification adds general information about the product, the nature of the exploit or incident, and any corrective or mitigating measures.

The final report is where the two triggers diverge. For a vulnerability, it is due no later than 14 days after a corrective or mitigating measure is available. For a severe incident, it is due within one month after the 72-hour incident notification. Read those two clocks carefully: they are measured from different events, so do not assume a single deadline covers both.

Telling your users Art. 14(8)

Reporting to authorities is not the end of it. After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer must inform the impacted users, and where appropriate all users, of the issue and of any risk mitigation or corrective measures they can deploy, where appropriate in a structured, machine-readable format. If you fail to do so in time, the notified CSIRTs may inform users themselves where proportionate and necessary.

One platform, and the option to report voluntarily Art. 16(1), Art. 14(7), Art. 15, Art. 17(4), Art. 17(6)

You file through a single reporting platform that ENISA establishes and maintains, using the electronic notification end-point of the CSIRT coordinator of the Member State where you have your main establishment in the Union. That is meant to spare you filing separately in every affected country. CSIRTs also provide helpdesk support, in particular for smaller manufacturers.

Separately from the mandatory duty, manufacturers and anyone else may report vulnerabilities, cyber threats, incidents, and near misses on a voluntary basis. The mere act of notifying, whether mandatory or voluntary, does not by itself expose the notifying party to increased liability.

What you must do

  • Notify actively exploited vulnerabilities and severe incidents to the CSIRT coordinator and ENISA via the single reporting platform: early warning within 24 hours, notification within 72 hours. (Art. 14(1)-(4), Art. 16)
  • File the final report: within 14 days after a corrective measure is available (vulnerabilities), or within one month of the notification (severe incidents). (Art. 14(2)(c), Art. 14(4)(c))
  • Inform impacted users of the vulnerability or incident and of mitigation and corrective measures. (Art. 14(8))

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))

Frequently asked

When do the CRA reporting obligations start?

From 11 September 2026. Article 71(2) accelerates Article 14 ahead of the rest of the regulation, which applies from 11 December 2027. The single reporting platform is expected to be operational for that date. (Art. 71(2), Art. 16)

What exactly has to happen within 24 hours?

An early warning notification, without undue delay and in any event within 24 hours of becoming aware of the actively exploited vulnerability or severe incident. It is a short alert, not the full report; the detailed information follows in the 72-hour notification. (Art. 14(2)(a), Art. 14(4)(a))

What counts as a severe incident?

One that negatively affects, or can affect, the product's ability to protect availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or that has led or can lead to malicious code being introduced or executed in the product or a user's systems. (Art. 14(5))

Do I have to report to every country where my product is sold?

No. You file once through the single reporting platform, using the end-point of the CSIRT coordinator in your Member State of main establishment; that CSIRT disseminates the notification to the others. CSIRTs also run a helpdesk, in particular for smaller manufacturers. (Art. 14(7), Art. 16(1), Art. 17(6))

Not sure the CRA applies to you at all?

The free Vexwatch Scope Checker walks the cited decision tree in about three minutes and tells you whether you are in scope, in which role, and which duties (including reporting) land on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.