CRA Vulnerability Reporting Requirements
The Cyber Resilience Act introduces some of the strictest software vulnerability reporting timelines in the world. From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours. Here's exactly what you have to report, to whom, and how fast.
What You Have to Report
The CRA's reporting duties (set out in Article 14 of Regulation (EU) 2024/2847) cover two things: actively exploited vulnerabilities in your product with digital elements, and severe incidents that affect the security of that product. “Actively exploited” is the key trigger: a known vulnerability being used in an attack starts the clock, not the mere existence of a flaw.
Reporting is not a single event. The CRA sets a staged cadence, so you report early with what you know and follow up as the picture becomes clearer.
Notify the coordinating CSIRT and ENISA of an actively exploited vulnerability or a severe incident as soon as you become aware of it, even before you have full details.
Provide general information on the nature of the exploit or incident, an initial assessment, and any corrective or mitigating measures taken or advised.
For an actively exploited vulnerability, submit a final report within 14 days of a corrective measure becoming available. For a severe incident, submit it within one month of the notification.
Who You Report To: The Single Reporting Platform
To avoid manufacturers having to notify dozens of national bodies, the CRA establishes a single reporting platform operated by ENISA (the European Union Agency for Cybersecurity). You submit one notification, and it is routed to the CSIRT designated as coordinator in your member state and to ENISA. In tightly defined situations (for example, where there is an imminent, serious cybersecurity risk) information can be shared more broadly to protect users.
The CVD Policy You Need in Place First
Reporting fast is only possible if you can receive and triage reports fast. That is why Annex I separately requires a coordinated vulnerability disclosure (CVD) policy: a published process and contact point for third parties to report potential vulnerabilities, plus a commitment to remediate them without undue delay and to distribute security updates for the support period. A security.txt file and a monitored disclosure inbox are practical starting points.
Can You Meet the 24-Hour Clock Today?
The CRA Readiness Assessment grades your vulnerability handling, reporting workflow, and CVD policy against Annex I, then builds a 30/60/90-day plan to close the gaps before September 2026.
Launch the CRA Readiness AssessmentHow to Prepare Before September 2026
The 24-hour requirement is an operational commitment, not a documentation exercise. To be ready, most manufacturers need to:
- Publish a CVD policy with a monitored security contact and clear triage ownership.
- Stand up an incident-response runbook that can produce an early warning within 24 hours of awareness.
- Continuously monitor third-party and open source components so “active exploitation” is detected quickly; this is where an automated SBOM and vulnerability feed pays for itself.
- Define severity-based remediation SLAs and a channel to ship security updates separately from feature releases.
CRA Vulnerability Reporting FAQ
The reporting-timeline questions manufacturers ask most.
Continue Your CRA Readiness
About This Assessment
This assessment maps your answers to the essential cybersecurity requirements in Annex I of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), covering product classification, vulnerability handling and 24-hour reporting, secure-by-design defaults, SBOM and supply chain governance, and lifecycle security updates.
The readiness score is severity-weighted: each question counts in proportion to how central the requirement is to CRA compliance, so the 24-hour reporting mandate (Article 14) and the SBOM requirement move the score more than lifecycle details. A few requirements are legal must-haves; if one is missing (for example, no vulnerability reporting workflow or no machine-readable SBOM), it acts as a knockout that caps the grade regardless of your score elsewhere. Scoring runs entirely in your browser, and no answers leave your device. This is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination.