Appoint us
Security operations receiving an alert that starts the CRA reporting clock

REP27 · CRA · Reporting

Article 14 · single reporting platform · 11 September 2026

The CRA 24-hour clock, and what actually starts it.

From 11 September 2026 a manufacturer of a product with digital elements has 24 hours to send an early warning when it becomes aware of an actively exploited vulnerability in that product, or of a severe incident affecting its security. Then 72 hours for the notification, and a final report after that. The deadlines are short, the platform is ENISA's, and the recipient depends on where you are established. This page sets out what triggers the clock, what does not, and how to be ready before the date rather than after it.

24 hours72 hoursFinal reportENISA platformCSIRT

Request this service   Ask a question

The clock, stage by stage

The CRA reporting deadlines from early warning to final report
The CRA reporting deadlines from early warning to final report

The first stage is the one that catches teams out, because 24 hours includes weekends and the trigger is becoming aware, not finishing the investigation. The early warning is deliberately short: it says something is happening, not what.

What starts it, and what does not

Which vulnerabilities and incidents trigger the CRA reporting obligation
Which vulnerabilities and incidents trigger the CRA reporting obligation
The distinction that matters: actively exploited, not merely discovered. A serious vulnerability found in your own testing and patched before anyone used it does not start this clock. The same vulnerability seen being used against a customer does.

Who receives the report

Your situationCoordinating CSIRTWhat to prepare
Main establishment in the UnionThat Member State's CSIRTAccount on the platform, named submitters
No establishment, authorised representative appointedThe representative's Member StateThe mandate, and the representative's details in your runbook
No representative, importer of recordThe importer's Member StateConfirmation from the importer that it accepts the role
No importer, distributorThe distributor's Member StateThe same, one link further down the chain
None of theseUndeterminedTwenty-four hours spent finding out is twenty-four hours not spent fixing

This table is the entire commercial argument for the optional mandate in Article 18, and it is why we describe that appointment as optional and worth signing rather than pretending it is required.

A runbook that fits on one page

  1. Define "becoming aware"

    Write down who can declare it and on what evidence: exploitation observed in telemetry, a credible customer report, a public proof of concept in use. Without this, the clock starts in an argument.

  2. Name the submitters

    At least two people with platform access, in different time zones if you have them. One person on holiday should not be a compliance failure.

  3. Pre-write the early warning

    Product, version, what is happening, whether it looks malicious, whether other Member States are affected. Five fields, drafted in advance.

  4. Set the 72-hour owner

    The notification needs severity, impact and any corrective measures. Different author, different depth.

  5. Plan the user communication

    Where appropriate, users must be informed and told what they can do. Draft the template before you need it at 3am.

  6. Record everything

    Timestamps of awareness, submission and updates. If the deadline is ever questioned, this is the answer.

How it differs from the other reporting duties you may have

RegimeTriggerFirst deadlineTo whom
CRA Article 14Actively exploited vulnerability or severe incident affecting product security24 hoursCoordinating CSIRT via the single platform
NIS2 Article 23Significant incident affecting the service you operate24 hoursCSIRT or competent authority of your Member State
GDPR Article 33Personal data breach72 hoursThe supervisory authority
GPSR Article 20Dangerous product placed on the marketWithout delayMarket surveillance, through Safety Business Gateway

A single event can trigger three of these at once. A ransomware intrusion that exploits a flaw in your own product, affects the cloud service you operate and exposes customer data is not a hypothetical, and the three reports go to three different places with two different clocks. Deciding who writes which one is a table-top exercise, not a policy document.

What we can and cannot do here

We fix the route

With the Article 18 mandate, the coordinating CSIRT is determined by our Member State, known in advance and written in your runbook.

We receive what comes back

Questions from market surveillance and the CSIRT reach us and are forwarded to you the same working day, in the language they arrived in.

We hold the documentation

Declaration of conformity and technical documentation, produced on a reasoned request without waiting for your office to open.

We do not report

The early warning is yours. It needs facts only your security team has, and the platform expects the manufacturer.

We do not assess severity

Whether a vulnerability is actively exploited is a technical judgement inside your organisation.

We do not patch

Corrective measures and the support period are manufacturer duties under Article 13, expressly outside the mandate.

The short version

From 11 September 2026: 24 hours for the early warning, 72 for the notification, then the final report, through ENISA's single platform, to the CSIRT determined by where you are established or represented. Write the runbook now, name two submitters, define what counts as becoming aware, and if you have no establishment in the Union, sign the Article 18 mandate so the recipient is decided before the day you need it.

Preparing for September 2026 without a project

There is a version of this work that takes a fortnight and a version that takes six months. The difference is whether you treat it as a documentation exercise or as an operational one.

ArtefactEffortWhy it pays
Definition of "becoming aware"One meetingRemoves the argument that eats the first six hours
Two named submitters with platform accessAn afternoonHoliday and time zone cover for a calendar deadline
Early warning templateAn hourFive fields written calmly instead of at 3am
SBOM per shipped versionBuild pipeline workAnswers "which products contain this component" in minutes
Customer notice templateAn hourInforming users is part of the duty where appropriate
A known coordinating CSIRTThe Article 18 mandateRemoves the routing question entirely
A rehearsalHalf a dayEvery gap on this list surfaces in the first table-top exercise

Companies that run one rehearsal before September 2026 will discover something uncomfortable and cheap. Companies that do not will discover the same thing during an actual exploitation, when it is neither.

What the early warning actually contains

Deliberately short

The 24-hour message is an alert, not an analysis. It says what product, what is happening and whether it appears malicious.

Cross-border flag

Whether the issue affects users in other Member States, which is what triggers wider dissemination between CSIRTs.

Provisional by design

You are expected to update it. Waiting for certainty is the mistake, not sending an incomplete first message.

Followed at 72 hours

Severity, impact and corrective measures where available. This is where the technical detail belongs.

Then the final report

For vulnerabilities, within 14 days of a corrective measure being available; for severe incidents, within a month.

Recorded throughout

Timestamps of awareness and submission. If a deadline is ever questioned, that record is the answer.

Two hard cases

The vulnerability is in a component we did not write

If it is in the product you placed on the market and it is being actively exploited, it is reportable. The licence of the dependency does not move the duty. This is precisely why the SBOM requirement exists: without it, working out which of your products contain the affected component takes longer than the deadline allows.

We learned about it from a customer, not from telemetry

Becoming aware does not require your own detection. A credible customer report of exploitation starts the clock, which is why the definition of awareness needs to be written down before it is tested. Teams that leave it undefined lose hours arguing about whether a report was credible enough, and the clock does not pause for the discussion.

The short version

From 11 September 2026 the clock is 24 hours for the early warning, 72 for the notification, then a final report, submitted through ENISA's single platform to the CSIRT determined by where you are established or represented. Actively exploited is the trigger, not merely discovered. Write down what counts as becoming aware, name two submitters, draft the templates now, keep an SBOM so you can answer which products are affected, and if you have no establishment in the Union, sign the Article 18 mandate so the recipient is settled before the day you need it. One rehearsal before September will find every gap in this paragraph.

Who does what, on the day

HourWhoWhat
0Security leadDeclares awareness against the written definition and starts the clock in the log
0 to 2EngineeringIdentifies affected products and versions from the SBOM
2 to 6Named submitterDrafts the early warning from the template and confirms the coordinating CSIRT
Before 24Named submitterSubmits through the single reporting platform and records the timestamp
24 to 72Security leadSeverity, impact, corrective measures, then the notification
In parallelSupport and marketingUser communication where appropriate, from the pre-drafted template
AfterComplianceFinal report, and the record of every timestamp

Seven rows, one page, printed. That is the entire preparation, and the companies that have it treat 11 September 2026 as a date rather than an event.

Connected product affected by an actively exploited vulnerability
Connected product affected by an actively exploited vulnerability
Coordinating CSIRT receiving a report under the Cyber Resilience Act

Questions we are actually asked

When does the reporting obligation start?

11 September 2026. The rest of the regulation applies fully from 11 December 2027.

What has to be reported within 24 hours?

An early warning about an actively exploited vulnerability in your product, or a severe incident affecting the product's security.

Does a vulnerability we found ourselves count?

Not unless it is actively exploited. Discovery alone does not start this clock, though it triggers your handling duties.

What goes in the 72-hour notification?

General information on the vulnerability or incident, its severity and impact, and corrective measures where available.

When is the final report due?

For vulnerabilities, within 14 days of a corrective measure being available. For severe incidents, within one month of the notification.

Where are reports submitted?

Through the single reporting platform established and maintained by ENISA, which routes to the coordinating CSIRT.

Which CSIRT is ours?

The one in your Member State of main establishment; failing that, of your authorised representative, then importer, then distributor.

Can our representative file the report?

No. The report requires facts only your team has, and the platform is designed for the manufacturer.

Do we have to tell users?

Where appropriate, yes: about the vulnerability or incident and any measures they can take.

Does this apply to products sold before 2027?

The reporting obligations reach products made available on the market, including those placed before the full application date.

What if the same event triggers NIS2 too?

Both reports are due, to potentially different recipients. Decide in advance who writes which.

Are 24 hours calendar or working hours?

Calendar. Weekends and holidays included, which is why two named submitters matter.

What are the penalties for failing to report?

Reporting failures fall within the regulation's penalty framework, with ceilings up to €15 million or 2.5% for the most serious breaches.

Can we report voluntarily?

Yes. Any natural or legal person may notify vulnerabilities, threats, incidents and near misses on a voluntary basis.

Does an SBOM help here?

Enormously. Knowing which products contain an affected component is what turns a 24-hour deadline into a manageable one.

What if we are unsure whether it is exploited?

Report on the basis of what you know and update. The early warning is deliberately short and is meant to be provisional.

Do we need the Article 18 mandate for this?

It is optional, but without it the recipient of your report is determined further down a chain you may not control.

How fast can the mandate be in place?

Within 24 hours of a short intake call, well before the September 2026 date.

Related: the Article 18 mandate · how it differs from NIS2

Decide the recipient before the deadline exists

Europe Services, SE in Prague as your Article 18 representative, so the coordinating CSIRT is known in advance and written into your runbook.

Request this service