---
title: "CRA Vulnerability Reporting Requirements | 24-Hour ENISA Rule | FOSSA"
description: "A plain-English guide to the EU Cyber Resilience Act's vulnerability reporting requirements: the 24-hour early warning to ENISA, the 72-hour and 14-day deadlines, the single reporting platform, and CVD policy obligations that begin 11 September 2026."
canonical_url: "https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/cra-vulnerability-reporting/"
markdown_url: "https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/cra-vulnerability-reporting.md"
language: "en"
author: "FOSSA"
organization: "FOSSA"
---

# CRA Vulnerability Reporting Requirements | 24-Hour ENISA Rule | FOSSA

> A plain-English guide to the EU Cyber Resilience Act's vulnerability reporting requirements: the 24-hour early warning to ENISA, the 72-hour and 14-day deadlines, the single reporting platform, and CVD policy obligations that begin 11 September 2026.

## What You Have to Report

The CRA's reporting duties (set out in Article 14 of Regulation (EU) 2024/2847) cover two things: **actively exploited vulnerabilities** in your product with digital elements, and **severe incidents** that affect the security of that product. “Actively exploited” is the key trigger: a known vulnerability being used in an attack starts the clock, not the mere existence of a flaw.

Reporting is not a single event. The CRA sets a staged cadence, so you report early with what you know and follow up as the picture becomes clearer.

Within 24 hours

Early warning

Notify the coordinating CSIRT and ENISA of an actively exploited vulnerability or a severe incident as soon as you become aware of it, even before you have full details.

Within 72 hours

Vulnerability / incident notification

Provide general information on the nature of the exploit or incident, an initial assessment, and any corrective or mitigating measures taken or advised.

Within 14 days / 1 month

Final report

For an actively exploited vulnerability, submit a final report within 14 days of a corrective measure becoming available. For a severe incident, submit it within one month of the notification.

## Who You Report To: The Single Reporting Platform

To avoid manufacturers having to notify dozens of national bodies, the CRA establishes a **single reporting platform** operated by ENISA (the European Union Agency for Cybersecurity). You submit one notification, and it is routed to the CSIRT designated as coordinator in your member state and to ENISA. In tightly defined situations (for example, where there is an imminent, serious cybersecurity risk) information can be shared more broadly to protect users.

## The CVD Policy You Need in Place First

Reporting fast is only possible if you can receive and triage reports fast. That is why Annex I separately requires a **coordinated vulnerability disclosure (CVD) policy**: a published process and contact point for third parties to report potential vulnerabilities, plus a commitment to remediate them without undue delay and to distribute security updates for the support period. A [security.txt](https://securitytxt.org/) file and a monitored disclosure inbox are practical starting points.

## Can You Meet the 24-Hour Clock Today?

The CRA Readiness Assessment grades your vulnerability handling, reporting workflow, and CVD policy against Annex I, then builds a 30/60/90-day plan to close the gaps before September 2026.

[Launch the CRA Readiness Assessment](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md)

## How to Prepare Before September 2026

The 24-hour requirement is an operational commitment, not a documentation exercise. To be ready, most manufacturers need to:

- Publish a CVD policy with a monitored security contact and clear triage ownership.
- Stand up an incident-response runbook that can produce an early warning within 24 hours of awareness.
- Continuously monitor third-party and open source components so “active exploitation” is detected quickly; this is where an automated SBOM and vulnerability feed pays for itself.
- Define severity-based remediation SLAs and a channel to ship security updates separately from feature releases.

## CRA Vulnerability Reporting FAQ

The reporting-timeline questions manufacturers ask most.

## Continue Your CRA Readiness

[CRA Readiness Assessment (free tool)](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md)[CRA product classification explained](https://fossa.com/blog/cra-product-classification/)[Cyber Resilience Act timeline & deadlines](https://fossa.com/blog/cra-compliance-timeline/)

## About This Assessment

This assessment maps your answers to the essential cybersecurity requirements in Annex I of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), covering product classification, vulnerability handling and 24-hour reporting, secure-by-design defaults, SBOM and supply chain governance, and lifecycle security updates.

The readiness score is **severity-weighted**: each question counts in proportion to how central the requirement is to CRA compliance, so the 24-hour reporting mandate (Article 14) and the SBOM requirement move the score more than lifecycle details. A few requirements are legal must-haves; if one is missing (for example, no vulnerability reporting workflow or no machine-readable SBOM), it acts as a **knockout** that caps the grade regardless of your score elsewhere. Scoring runs entirely in your browser, and no answers leave your device. This is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination.

### Official sources

- [Regulation (EU) 2024/2847: full Cyber Resilience Act text (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj)
- [European Commission: The Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)
- [ENISA (European Union Agency for Cybersecurity)](https://www.enisa.europa.eu/)

Last reviewed July 9, 2026Maintained by the FOSSA software supply chain compliance team

## Get Started with FOSSA

Start managing your dependencies, licenses, and vulnerabilities today.

## Frequently asked questions

### When do the CRA vulnerability reporting obligations start?

The Cyber Resilience Act's reporting obligations apply from 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT through the single reporting platform.

### What is the CRA 24-hour reporting rule?

Manufacturers must submit an early-warning notification within 24 hours of becoming aware of an actively exploited vulnerability in their product or a severe incident affecting its security. This is followed by a fuller notification within 72 hours and a final report within 14 days (for vulnerabilities) or one month (for incidents).

### Who do you report CRA vulnerabilities to?

Reports are submitted through a single reporting platform established and operated by ENISA. Notifications are routed to the CSIRT designated as coordinator in the manufacturer's member state and to ENISA. This replaces having to notify multiple national authorities separately.

### Does the CRA require a vulnerability disclosure policy?

Yes. Annex I of the CRA requires manufacturers to put in place and enforce a policy on coordinated vulnerability disclosure (CVD), including a contact address for reporting, and to facilitate the sharing of information about potential vulnerabilities with third parties.

## Source

Canonical page: https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/cra-vulnerability-reporting/
