The CRA’s 24-hour reporting deadline is closer than it looks
The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities from September 2026
The first major EU Cyber Resilience Act (CRA) deadline hits on 11 September 2026.
That’s when manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours of awareness.
The clock starts the moment you know. For an actively exploited vulnerability, you file an early warning within a day, a fuller notification within 72 hours, and a final report later.
You report once through ENISA’s Single Reporting Platform. It goes to your main establishment’s CSIRT and, in most cases, simultaneously to ENISA, which shares it across the EU.
The platform is under development now, with testing underway for its September 2026 launch. ENISA maintains an FAQ.
What is actually new here?
It’s not the concept of reporting. It’s the formal, regulated deadline applied to every ‘product with digital elements’ on the EU market.
This turns internal incident response playbooks into a legal compliance sprint.
The genuine novelty is the ‘actively exploited vulnerability’ category. This isn’t about a high CVSS score in your backlog. It’s about evidence of in-the-wild abuse.
Your triage must now definitively answer ‘is this being used in attacks?’ faster than ever.
Why does this matter to a mid-sized European company?
It matters in two direct ways.
If you manufacture or significantly modify a product with digital elements for the EU market, this is your new compliance baseline. Your security and legal teams need a joint process before September 2026.
If you are a buyer and integrator of such products, your vendor management just gained leverage. You can contractually expect—and demand—this 24-hour notification for severe incidents affecting your systems. It creates a clear standard.
For everyone else, the urgency is manufactured. If you’re a purely domestic service provider using off-the-shelf software, the CRA’s direct obligations likely don’t apply to you yet. The broader product security requirements phase in December 2027.
What about AI attack loops?
Because automation compresses time. An AI-driven attack loop can find and weaponise a flaw faster than a manual compliance workflow can spin up.
Your 24-hour reporting timer is competing with an adversary’s potentially minute-scale exploitation cycle.
What should you do about it this week?
Start with your existing team.
First, map which of your products or major software components fall under the ‘manufacturer’ definition. This is a legal and product management exercise.
Second, run a tabletop exercise. Take a recent severe security incident. Pressure-test your ability to confirm active exploitation and draft a regulatory notification within 24 hours. You will find the bottlenecks between technical and legal teams.
Third, review your vulnerability intake process. Does it have a clear, evidence-based gate for ‘actively exploited’? If not, build one. This is operational work, not just policy.
The CRA’s reporting rule is a line in the sand for product security accountability. For those it touches, the countdown to September 2026 is already on.
Sources:
- European Commission Cyber Resilience Act - Reporting obligations
- ENISA CRA Single Reporting Platform FAQ