The CRA’s 24-hour reporting deadline is here
The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities from September 2026
The first major EU Cyber Resilience Act (CRA) deadline hits on 11 September 2026.
That's when manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours of awareness.
The clock starts the moment you know. For an actively exploited vulnerability, you file an early warning within a day, a fuller notification within 72 hours, and a final report later.
You report once through ENISA's Single Reporting Platform. It goes to your main establishment's CSIRT and, in most cases, simultaneously to ENISA, which shares it across the EU.
The platform is under development now, with testing underway for its September 2026 launch. ENISA maintains an FAQ.
What is the EU Single Reporting Platform and how do manufacturers use it under the 24‑hour CRA rule?
The EU Single Reporting Platform (SRP) is the official, ENISA‑run portal that manufacturers must use to file their 24‑hour early warning, 72‑hour notification, and final report for actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act.
From 11 September 2026, if you place a "product with digital elements" on the EU market, you report once through the SRP and your submission is automatically routed to:
- your designated national CSIRT (based on your main establishment in the EU), and
- ENISA, which shares the notification across the EU.
How manufacturers access the SRP under the 24‑hour rule
Access is manual (no public API at launch) and follows this flow:
-
Create an EU Login account now
- Use the European Commission's EU Login (ECAS) system: https://ecas.ec.europa.eu/cas/login.
- Set this up for both your Primary and Secondary (backup) Assigned Representatives.
-
Register your organisation in the SRP
- On first access, select your role (manufacturer or open‑source steward).
- Choose your designated CSIRT from the drop‑down (based on your main establishment).
- Accept the legal agreement and confirm your personal details.
- Enter your manufacturer entity details (name, address, legal contacts). This creates your organisation profile in the platform.
-
Submit the 24‑hour early warning
- From the SRP dashboard, select "Submit New Notification" to create a single case record.
- Complete the mandatory early‑warning fields (notification type/level, manufacturer/steward name, product, title, and whether unlawful or malicious acts are suspected for incidents).
- Click Submit. The platform routes your early warning simultaneously to your CSIRT and ENISA.
-
Update the same case for 72‑hour and final reports
- Re‑open the same case record from your dashboard to add the 72‑hour notification and later the final report. Do not create separate cases for each stage.
- Final reports are due within 14 days of a corrective measure for vulnerabilities, or within 1 month for severe incidents.
The SRP is scheduled to go live on 11 September 2026. Its public URL will be published on ENISA's SRP page before launch, and you can create your EU Login accounts in advance. ENISA also provides a dedicated help‑desk at cra-srp-helpdesk [at] enisa.europa.eu for platform questions (see the ENISA CRA Single Reporting Platform FAQ linked above).
What is actually new here?
It's not the concept of reporting. It's the formal, regulated deadline applied to every 'product with digital elements' on the EU market.
This turns internal incident response playbooks into a legal compliance sprint.
The genuine novelty is the 'actively exploited vulnerability' category. This isn't about a high CVSS score in your backlog. It's about evidence of in-the-wild abuse.
Your triage must now definitively answer 'is this being used in attacks?' faster than ever.
Why does this matter to a mid-sized European company?
It matters in two direct ways.
If you manufacture or significantly modify a product with digital elements for the EU market, this is your new compliance baseline. Your security and legal teams need a joint process before September 2026.
If you are a buyer and integrator of such products, your vendor management just gained leverage. You can contractually expect—and demand—this 24-hour notification for severe incidents affecting your systems. It creates a clear standard.
For everyone else, the urgency is manufactured. If you're a purely domestic service provider using off-the-shelf software, the CRA's direct obligations likely don't apply to you yet. The broader product security requirements phase in December 2027.
What about AI attack loops?
Because automation compresses time. An AI-driven attack loop can find and weaponise a flaw faster than a manual compliance workflow can spin up.
Your 24-hour reporting timer is competing with an adversary's potentially minute-scale exploitation cycle.
What should you do about it this week?
Start with your existing team.
First, map which of your products or major software components fall under the 'manufacturer' definition. This is a legal and product management exercise.
Second, run a tabletop exercise. Take a recent severe security incident. Pressure-test your ability to confirm active exploitation and draft a regulatory notification within 24 hours. You will find the bottlenecks between technical and legal teams.
Third, review your vulnerability intake process. Does it have a clear, evidence-based gate for 'actively exploited'? If not, build one. This is operational work, not just policy.
The CRA's reporting rule is a line in the sand for product security accountability. For those it touches, the countdown to September 2026 is already on.
Sources
- European Commission Cyber Resilience Act - Reporting obligations
- ENISA CRA Single Reporting Platform FAQ