Free Tools

    Free Compliance Tools

    Interactive tools to help you assess readiness, estimate costs, and compare frameworks — no signup required.

    Compliance calendar

    Cyber Resilience Act: vulnerability and incident reporting starts 11 September 2026

    Under Regulation (EU) 2024/2847 (the Cyber Resilience Act), manufacturers of products with digital elements made available on the EU market must report actively exploited vulnerabilities and severe incidents having an impact on the security of their product. Article 71(2) applies these reporting obligations from 11 September 2026, ahead of the Act's main application date of 11 December 2027.

    Reporting is phased, and the deadlines are outer limits rather than waiting periods: an early warning without undue delay and in any event within 24 hours of the manufacturer becoming aware of it; a fuller notification without undue delay and in any event within 72 hours (each stage may skip what has already been provided); and a final report to close the loop. Every early warning should also indicate, where applicable, the Member States in which the manufacturer is aware its product has been made available.

    • Actively exploited vulnerabilities (Art. 14(1) and (2)): the final report is due no later than 14 days after a corrective or mitigating measure becomes available. It describes the vulnerability's severity and impact and, where available, which malicious actors have exploited or are exploiting it, together with the fixes or other corrective measures made available.
    • Severe incidents (Art. 14(3) and (4)): the early warning also flags whether the incident is suspected of being caused by unlawful or malicious acts, and the final report is due within one month of the incident notification. It covers the incident's severity and impact, the likely threat type or root cause, and mitigation measures applied or under way.

    Both tracks are reported through the single reporting platform ENISA establishes under Article 16. The end-point is determined under Article 14(7): first by the manufacturer's main establishment in the Union, meaning the Member State where decisions related to the cybersecurity of its products are predominantly taken or, if that cannot be determined, its Union establishment with the highest number of employees. A manufacturer with no Union main establishment follows a strict fallback sequence: first the Member State of the authorised representative acting for the highest number of its products; failing that, of the importer placing the highest number of its products on the market; failing that, of the distributor making available the highest number of its products; and finally the Member State where the highest number of its users are located. The first CSIRT shares the notification with the other relevant CSIRTs, and as a normal rule it is simultaneously accessible to ENISA; in particularly exceptional circumstances, the receiving CSIRT may delay both the onward dissemination to other CSIRTs and ENISA's access to the full notification, on the grounds the Regulation specifies for those cases. Separately, Article 14(8) requires manufacturers to inform impacted users (and, where appropriate, all users) of the vulnerability or incident and, where necessary, of the risk-mitigation and corrective measures users can deploy; where appropriate, that information should be in a structured, machine-readable format.

    The reporting duty is not tied to any certification date: Article 69(3) applies Article 14 to every in-scope product placed on the market before 11 December 2027. On the platform itself, ENISA is establishing the CRA Single Reporting Platform, and the European Commission states it will be operational by 11 September 2026, with functional and security testing under way as of the Commission's reporting page dated 31 July 2026.

    If you develop or supply software or hardware products with digital elements to EU customers, check whether the CRA applies to you: scope depends on the product and on the commercial role you play. Where it does, this reporting regime sits alongside the ISMS and vulnerability-handling work the directory's listed providers support.

    Checked against the official texts on 10 September 2026. This is an orientation aid, not legal advice; the Regulation itself and your competent authority decide each case, and the Commission and ENISA pages below are official guidance for interpretation.