What must be reported, and to whom Art. 14(1), Art. 14(3), Art. 14(5), Art. 14(7)
Two triggers create a mandatory report. The first is an actively exploited vulnerability contained in the product. The second is a severe incident having an impact on the security of the product. In both cases the manufacturer notifies the CSIRT designated as coordinator and ENISA at the same time, using the single reporting platform established under Article 16.
The CRA defines when an incident is "severe": where it negatively affects, or can affect, the product's ability to protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions, or where it has led, or can lead, to malicious code being introduced or executed in the product or in a user's network and information systems.
The three-stage clock Art. 14(2), Art. 14(4)
For both triggers the timeline is the same at the front: an early warning notification without undue delay and in any event within 24 hours of becoming aware, then a fuller notification within 72 hours. The 24-hour early warning is a short alert; the 72-hour notification adds general information about the product, the nature of the exploit or incident, and any corrective or mitigating measures.
The final report is where the two triggers diverge. For a vulnerability, it is due no later than 14 days after a corrective or mitigating measure is available. For a severe incident, it is due within one month after the 72-hour incident notification. Read those two clocks carefully: they are measured from different events, so do not assume a single deadline covers both.
Telling your users Art. 14(8)
Reporting to authorities is not the end of it. After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer must inform the impacted users, and where appropriate all users, of the issue and of any risk mitigation or corrective measures they can deploy, where appropriate in a structured, machine-readable format. If you fail to do so in time, the notified CSIRTs may inform users themselves where proportionate and necessary.
One platform, and the option to report voluntarily Art. 16(1), Art. 14(7), Art. 15, Art. 17(4), Art. 17(6)
You file through a single reporting platform that ENISA establishes and maintains, using the electronic notification end-point of the CSIRT coordinator of the Member State where you have your main establishment in the Union. That is meant to spare you filing separately in every affected country. CSIRTs also provide helpdesk support, in particular for smaller manufacturers.
Separately from the mandatory duty, manufacturers and anyone else may report vulnerabilities, cyber threats, incidents, and near misses on a voluntary basis. The mere act of notifying, whether mandatory or voluntary, does not by itself expose the notifying party to increased liability.