REP27REP27
Reporting desk open every hour of the year for CRA vulnerability reports

Article 14 · Regulation (EU) 2024/2847 · Reporting from 11 September 2026

Article 14 applies in

A vulnerability is being exploited.You have 24 hours.

From 11 September 2026 every manufacturer of a product with digital elements sold in the European Union must send an early warning within 24 hours of becoming aware, a full notification within 72, and a final report within 14 days. The clock does not pause at night, at the weekend or in August. We hold it for you, in Europe, all year.

See how the clock runs

Europe Services, SE — Prague, Czech Republic. Active since 2018. Article 27, Article 16 and CRA mandates already signed for companies in 24 countries.

00:00
since you became aware
  • Early warning to the CSIRT and ENISA24h
  • Full notification with the first corrective measures72h
  • Users informed, mitigation published14d
  • Final report on the vulnerability and the fix1m

A simulation. The real deadlines run in calendar hours, not working hours.

Who has to report, and who does not

The duty falls on the manufacturer of the product, wherever it is established. Not on the importer, not on the distributor, not on the customer who found the flaw. If you sell anything that connects — an app, a router, a camera, a machine with firmware, a piece of software — and it reaches a buyer in the European Union, you are the one holding the clock.

SituationWho reportsWhat we do
Manufacturer outside the EU, sells directly to EU buyersYou. The CSIRT is determined through your authorised representative, then the importer, then the distributor.We are the representative and we file for you.
Manufacturer in the EUYou, to the CSIRT of the member state of your main establishment.We run the intake channel and prepare the filing.
Open source steward, non-commercialLighter regime, but the duty to report an exploited vulnerability still applies.Reduced plan, same channel.
Product already on the market before the CRA appliedYou. Legacy products are inside the reporting duty from day one.We map the legacy catalogue with you.
Importer or distributorNot you, unless you put the product on the market under your own name.We tell you honestly that you do not need us.
Monitoring desk receiving a CRA early warning within the first 24 hours

What actually starts the clock

Not every bug is reportable. Two events are, and mixing them up is the most expensive mistake a manufacturer can make in September.

An actively exploited vulnerability

Someone is using the flaw against your product, right now, and you have evidence of it. Proof of concept published, exploitation seen in the field, a customer reporting a compromise. A vulnerability nobody is exploiting is not reportable under Article 14, however severe its score.

A severe incident

An event that affects the security of the product itself: your build system compromised, a malicious update signed and shipped, a repository poisoned. The damage does not have to be realised — the impact on the product's security is enough.

The clock starts when you become aware. Unverified noise does not start it; a credible report does. Deciding where that line sits, in writing, before the event, is half of what we sell.

What the law does not require on 11 September

Most of what is being sold this month as "CRA compliance" is not due yet. We would rather tell you now than take money for it.

Binding from 11 September 2026

Article 14 only: the early warning, the notification, the final report, and informing affected users. Filed through the single reporting platform run by ENISA, reaching your coordinating CSIRT at the same time.

Binding from 11 December 2027

The coordinated disclosure policy, the software bill of materials, secure-by-design requirements, the declared support period, CE marking and conformity assessment. Useful to start now, not yet enforceable — and anyone telling you otherwise is selling urgency.

The catch is practical rather than legal: you cannot report what you never detect. A manufacturer with no intake channel does not become aware of an exploited vulnerability until a journalist calls. That is why the channel, and not the paperwork, is the thing worth buying in 2026.

The desk. Open every hour of the year.

A published address that nobody reads is worse than no address, because it proves you were told. Ours is staffed continuously — nights, weekends, the whole of August, 25 December — and every message that arrives is answered, logged and triaged inside the first hours.

Your public intake address

A reporting address in your own name, published on your site and in your security.txt, pointing at our desk. Researchers, customers and supply-chain partners write there instead of nowhere.

Triage inside the first hours

Every report is acknowledged, deduplicated and rated against one question: is there evidence of active exploitation? If yes, your named contacts are woken up. If no, it goes on the log and you read it on Monday.

The filing, written for you

We prepare the early warning, the 72-hour notification and the final report in the format the platform expects, in English, and send them once you confirm the facts. You approve; we file.

A timestamped record

Every message in, every decision, every filing, kept with its exact time. If an authority asks in 2029 what you knew and when, the answer is a document, not a memory.

The CSIRT question, answered in advance

For a manufacturer outside the Union, the competent CSIRT is determined first by the authorised representative. Because we hold that mandate, your coordinating authority is known before anything happens, not decided in a panic.

Users informed properly

The regulation asks you to tell affected users, without a fixed deadline and without a prescribed format. We draft that notice with you, so it does not become the second incident.

Circuit board of a product with digital elements covered by the Cyber Resilience Act
If it has firmware and it reaches an EU buyer, it is a product with digital elements.

What counts as a product with digital elements

Wider than people expect. Any software or hardware product whose intended use includes a data connection, direct or indirect, to a device or network. A mobile app. A desktop program. A router, a camera, a smart plug, a fitness band. An industrial machine with a controller. A component sold separately.

Outside: medical devices, cars, aviation and marine equipment, products regulated for national security, and software as a service unless it forms part of the remote data processing of a covered product. If you are not sure which side you sit on, that is the first question we answer, free, before you pay anything.

The four deadlines, in calendar hours

DeadlineFromWhat has to be in itWho receives it
24hBecoming awareEarly warning: that it exists, whether it is being exploited, which member states may be affected. Facts you have, not an analysis.Coordinating CSIRT and ENISA
72hBecoming awareNotification: general information on the product, the nature of the flaw, the severity and impact, and any corrective measures already taken or available.Coordinating CSIRT and ENISA
14dA fix being availableFinal report on an exploited vulnerability: description, severity, impact, and the corrective or mitigating measures now available to users.Coordinating CSIRT and ENISA
1mThe 72-hour notificationFinal report on a severe incident: what happened, how, the cross-border effect, the measures applied.Coordinating CSIRT and ENISA

Plus, without a fixed deadline: informing the users of the affected product, and where relevant telling them what they can do themselves. Late is not the only failure mode — a filing that contradicts what you publish is worse.

Three cyber duties, three different animals

Companies routinely believe one filing covers all of them. It does not, and the deadlines are not the same.

CRANIS2GDPR
Who is boundManufacturer of the productOperator of the serviceController of the data
What triggers itExploited vulnerability or severe incident affecting product securityIncident with significant impact on the serviceBreach of personal data
First deadline24h24h72h
Filed withCSIRT and ENISA, single platformNational CSIRT or authorityData protection authority
Applies from11 September 2026In forceIn force

One event can trigger two of them at once. A signed malicious update that also exposes customer records is a CRA severe incident and a personal data breach, on two clocks, to two authorities, with two different sets of words. We hold the CRA clock, and we tell you when the other one has started.

What it costs to miss it

Failing to report sits in the highest penalty band of the regulation, alongside the essential cybersecurity requirements themselves. Fines scale with worldwide turnover, and market surveillance authorities can order a product withdrawn or recalled from the Union market.

The commercial damage arrives sooner than the fine. A withdrawal order reaches your distributors and marketplaces in days, and an unanswered researcher publishes on the fifteenth day because nobody wrote back.

Compliance manager responsible for CRA vulnerability reporting at a manufacturer
One named person has to own the clock. Usually they already have another job.

Inside the desk

Three moments of the same duty: the report arriving, the filing being written, and the product it is about.

The 72-hour notification, written while the facts are still moving.
The 72-hour notification, written while the facts are still moving.
A named person reads every report. Nights and weekends included.
A named person reads every report. Nights and weekends included.
A component sold on its own is a product in its own right.
A component sold on its own is a product in its own right.

Plans

One price, one renewal, no hourly billing and no charge per product. A single provider quotes five figures a year for the same duty; the desk costs less than one hour of the incident it prevents.

CHANNEL

€390 / year

Renewal €320

One product line

  • Public intake address in your name
  • Staffed 24 hours a day, every day
  • Triage and escalation to your contacts
  • Timestamped log of everything received

CHANNEL + FILING

€690 / year

Renewal €590

Whole catalogue, legacy included

  • Everything in Channel
  • Early warning, notification and final report drafted and filed
  • Coordinating CSIRT identified in advance
  • User notice drafted with you
  • Verifiable certificate of the mandate

REPRESENTATIVE

€1190 / year

Renewal €990

Manufacturers outside the Union

  • Everything in Channel + Filing
  • Authorised representative under the CRA
  • Address published on the product or its documentation
  • Technical documentation held for ten years
  • Bundled with Article 27 and Article 16 mandates

We do not sell penetration tests, CE certification, SBOM tooling or conformity assessment. When you need those, we say so and stay out of the way.

How this obligation arrived

We have been tracking these dates since the text was adopted, and revising this page each time they moved. Two of them already have.

DateMilestoneWhat changed
2024-10-23AdoptionRegulation (EU) 2024/2847 adopted. The text is final; the dates are not all the same.
2024-12-10Entry into forceThe regulation enters into force. Nothing is enforceable yet, and this is where most compliance calendars quietly stop.
2026-06-11Notified bodiesArticles 35 to 51 apply: conformity assessment bodies can be notified. Relevant to certification providers, not yet to manufacturers.
2026-09-11 Article 14 · reportingActively exploited vulnerabilities and severe incidents become reportable. 24 hours, 72 hours, 14 days. Legacy products included.
2027-12-11Everything elseEssential requirements, vulnerability handling, disclosure policy, SBOM, support period, CE marking, market surveillance.

The words, defined the way an authority uses them

Most of the arguments about this regulation are arguments about four or five definitions. These are the ones that decide whether you file or not.

Product with digital elements
Any software or hardware whose intended use includes a direct or indirect data connection to a device or a network. Wider than 'IoT': a desktop application qualifies.
Actively exploited vulnerability
A vulnerability for which there is reliable evidence that someone is using it against the product, without the manufacturer's knowledge or consent. Severity score alone does not make a vulnerability reportable.
Severe incident
An event that negatively affects the security of the product itself — a compromised build pipeline, a signed malicious update — whether or not damage has already occurred.
Becoming aware
The moment the manufacturer has a credible basis to believe the event happened. It starts every deadline in the regulation, and it should be recorded in writing when it happens, not reconstructed afterwards.
Early warning
The first filing, due within 24 hours. Short by design: that it exists, whether it is exploited, which member states may be affected.
Coordinating CSIRT
The national computer security incident response team that receives your filing. For a manufacturer outside the Union it is determined first through the authorised representative, then the importer, then the distributor.
ENISA
The European Union Agency for Cybersecurity. It operates the single reporting platform and receives your notification at the same time as the CSIRT.
Single reporting platform
The electronic system through which one submission reaches both the coordinating CSIRT and ENISA. One filing, two recipients, no duplicate paperwork.
Authorised representative
A person established in the Union appointed by written mandate to carry out defined tasks for a manufacturer. Under the CRA the appointment is optional; under other regimes it is not.
Coordinated vulnerability disclosure policy
The published rules that tell researchers how to report to you and what you will do next. Binding from December 2027, useful from today.
Support period
The time during which the manufacturer commits to providing security updates. Declared by the manufacturer, from December 2027.
SBOM
A machine-readable inventory of the components inside your product. Not required in September 2026, and the fastest way to answer 'are we affected' when a component breaks.
security.txt
A small file at a fixed path on your website that tells researchers where to send security reports. Not named in the regulation and the simplest way to publish the contact address it asks for.
Open source steward
A person or organisation providing sustained support for open source software used commercially, subject to a lighter set of duties than a manufacturer.
Remote data processing
Processing carried out at a distance that the product cannot function without. It is what pulls parts of a cloud backend into the scope of the CRA.
Market surveillance authority
The national body that can demand documentation, restrict a product, or order it withdrawn or recalled from the Union market.

Read the primary sources yourself

Everything on this page comes from the regulation itself. Where we interpret, we say so. Where we are unsure, we say that too.

Regulation (EU) 2024/2847

The consolidated text on EUR-Lex, in all official languages.

CRA reporting obligations

The European Commission page on what must be reported from 11 September 2026.

Our page on the 24-hour rule

How the early warning is written and what goes in it.

CRA authorised representative

What the mandate covers and who determines your CSIRT.

CRA compared with NIS2

Two 24-hour duties, two different triggers.

Products with digital elements

Where the scope starts and stops.

Page maintained continuously since the regulation entered into force. Last revision: 02 September 2026. When a date moves, this page moves with it, and the old date stays visible in the table above.

Questions manufacturers actually ask

Does the whole Cyber Resilience Act apply from 11 September 2026?
No. Only the reporting duties in Article 14 become binding on that date. The essential cybersecurity requirements, the vulnerability handling obligations in Annex I, CE marking and conformity assessment apply from 11 December 2027. Notification of conformity assessment bodies started earlier, in June 2026.
Do we have to report every vulnerability we find?
No. Only vulnerabilities that are being actively exploited, and severe incidents affecting the security of the product. A critical scoring flaw that nobody is exploiting is not reportable under Article 14, although you will still want to fix it.
When exactly does the 24 hours start?
When the manufacturer becomes aware. Awareness needs a credible basis: a reproducible report, exploitation seen in the field, a customer confirming a compromise. Unverified noise does not start the clock, which is precisely why the moment of awareness should be recorded in writing at the time.
What if the deadline falls on a Sunday or in August?
It still runs. The regulation counts hours, not working hours. This is the reason our desk is staffed on Sundays and in August, and the reason a shared inbox monitored on weekdays is not a compliant arrangement.
Who do we report to if we are established outside the EU?
The coordinating CSIRT is determined first through your authorised representative in the Union, then the importer, then the distributor. If we hold your representative mandate, your coordinating authority is fixed in advance and does not have to be worked out during an incident.
Does this apply to products we sold years ago?
Yes. The reporting obligations reach products with digital elements that were already placed on the EU market before the CRA fully applies. Legacy catalogues are inside the duty from the first day, which surprises most manufacturers.
Is a coordinated vulnerability disclosure policy required in September?
Not yet. The policy, together with the rest of the Annex I vulnerability handling requirements, becomes binding on 11 December 2027. In practice you need the intake channel before then, because you cannot report what you never hear about.
We are a software company, not a hardware maker. Are we in scope?
Almost certainly yes. A product with digital elements includes software placed on the market, from a desktop application to a mobile app to a library sold or distributed commercially. The connection can be direct or indirect.
Is software as a service covered?
Generally not by itself. Cloud services fall under NIS2 rather than the CRA, unless the remote data processing forms part of a covered product — the backend a connected camera cannot work without, for instance.
What happens if we report something and it turns out to be nothing?
Nothing bad. Reporting in good faith on the information you had is the behaviour the regulation asks for. Silence while evidence accumulates is the risk, not an early warning that is later downgraded.
Can our reports be kept confidential?
The notification goes to your coordinating CSIRT and, in parallel, to ENISA. There is a mechanism for delaying wider dissemination in exceptional cases, on cybersecurity risk grounds. It is narrow and it is not a general right to secrecy.
Do we have to tell our customers as well?
Yes, where the vulnerability affects them, and where relevant you must tell them what they can do about it. No fixed deadline is prescribed, and no format. Getting the wording right matters, because it is the part your customers actually read.
Are open source projects caught by this?
Non-commercial open source development is largely outside the regime, and a lighter set of duties applies to open source stewards. The reporting duty for an exploited vulnerability is one of the parts that still applies.
Where are the reports actually submitted?
Through the single reporting platform operated by ENISA, which routes a single submission to your coordinating CSIRT and to ENISA at the same time. One filing, two recipients.
What are the penalties?
The reporting duties sit in the highest fine band of the regulation, next to the essential requirements themselves, and the fines scale with worldwide turnover. Market surveillance authorities can also order a product to be withdrawn or recalled from the Union market.
Does the UK have the same rule?
The United Kingdom has its own regime for connected products, requiring a published contact point for security reports and a stated period of security updates. It is a separate duty from the CRA, and a manufacturer selling in both markets needs both.
We already have a security@ address. Is that enough?
On paper, sometimes. In practice an address that nobody watches at 3am is evidence that you were told and did nothing. What we sell is not the address, it is the person behind it and the record of what happened next.
Can you sign the report on our behalf?
We prepare it and submit it once you confirm the facts. The duty stays with you as manufacturer and we never invent technical facts about your product — the description of what happened has to come from your engineers.
How fast can the channel be live?
Within one working day of a completed form. The address, the triage rules and the escalation contacts are set up first; mapping the catalogue and the legacy products takes a little longer and can run in parallel.
What do you need from us to start?
The product lines in scope, two named contacts who can be woken up, and the address you want published. If you sell outside the Union we also need the mandate details, because that determines your coordinating authority.
Do you also handle NIS2, GDPR or product safety duties?
Yes, as separate mandates on the same account: Article 27 for personal data, Article 16 for product safety, NIS2 and Data Act representation. One renewal date, separate designations, no bundling of duties that are legally distinct.
What if we decide to stop the service?
The mandate ends with notice, we hand over the full timestamped log, and we tell you clearly that from that date nobody is watching the address until you point it somewhere else.

Nine days, then the clock is real

Tell us what you sell and where. We answer with the one thing you need to know first: whether the CRA reaches you at all, and which authority would receive your filing. That answer is free and it does not commit you to anything.

See our other mandates