verified_user
Standardful
Homechevron_rightStandardschevron_rightEU CRA
ActiveInternational Standardupdate Standard Updated: September 2026fact_check Fact checked: Sep 6, 2026

EU CRA

Cyber Resilience Act — Regulation (EU) 2024/2847

apartmentPublishing Organization:European Union

Standard Introduction

The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity rules for products with digital elements. Its first major operational deadline is 11 September 2026, when manufacturers must begin reporting actively exploited vulnerabilities and severe product-security incidents through ENISA's Single Reporting Platform.

The main product-security, technical-documentation, conformity-assessment, and CE-marking duties apply from 11 December 2027. Reporting starts earlier and reaches in-scope products already made available on the EU market, so product inventories, triage criteria, reporting authority, and evidence workflows need to be operational now.

notification_important

Reporting Starts 11 September 2026

Manufacturers must use ENISA's Single Reporting Platform for actively exploited vulnerabilities and severe product-security incidents from this date, before the CRA's main product requirements apply.

schedule

24-Hour and 72-Hour Stages

An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours and a final report on the applicable vulnerability or incident timetable.

devices

Earlier Products Are Included

The reporting duty reaches in-scope products already made available on the EU market before 11 December 2027, not only products launched after full CRA application.

list_alt CRA Reporting Readiness

  • Identify in-scope products with digital elements
  • Define actively exploited vulnerability and severe incident decision criteria
  • Assign 24-hour triage and reporting authority
  • Prepare 72-hour evidence and final-report workflows
  • Select the responsible CSIRT designated as coordinator
  • Create EU Login accounts with multi-factor authentication for assigned representatives
  • Coordinate one notification across subsidiaries and product teams
  • Link reporting to user notification, remediation, and evidence retention

Who Needs to Comply?

groups

Manufacturers placing products with digital elements on the EU market are the principal Article 14 reporters. From 11 September 2026, the duty also applies to in-scope products placed on the market before full CRA application. Open-source software stewards have related reporting duties under Article 24 when the statutory conditions are met. Importers and distributors should maintain escalation paths because they must respond when they identify or suspect non-conformity.

Key Requirements

1

Classify Reportable Events

Document how product-security teams distinguish an actively exploited vulnerability from a severe incident and from events that do not meet Article 14 thresholds.

2

Submit the 24-Hour Early Warning

Notify through the Single Reporting Platform without undue delay and no later than 24 hours after awareness, using the available facts and affected-market information.

3

Complete the 72-Hour Notification

Provide the fuller product, exploit or incident, severity, impact, mitigation, and sensitivity information required at the second reporting stage.

4

Close with the Final Report

For an actively exploited vulnerability, report no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, report within one month after the 72-hour notification.

5

Coordinate Users and Evidence

Connect regulatory reporting to affected-user communication, corrective measures, incident and vulnerability records, management escalation, and product-level ownership.

Implementation Roadmap

1
Phase 1schedule Duration: 1-2 weeks

Map products and reporting ownership

Identify every product with digital elements made available in the EU, including products launched before full CRA application. Assign the legal manufacturer, product-security owner, assigned representatives, approving executive, and CSIRT designated as coordinator.

2
Phase 2schedule Duration: 1-3 weeks

Define Article 14 decision rules

Translate the legal definitions of actively exploited vulnerability and severe incident into triage criteria. Specify when awareness starts the clock, how third-party component signals are assessed, and who can decide that an event is reportable.

3
Phase 3schedule Duration: 2-4 weeks

Build and exercise the reporting workflow

Prepare EU Login accounts with multi-factor authentication, reporting templates, evidence sources, approval paths, user-notification steps, and 24-hour, 72-hour, and final-report handoffs. Run a timed tabletop exercise with an incomplete-information scenario.

4
Phase 4schedule Duration: Ongoing

Operate reporting and full CRA readiness

Monitor vulnerability and incident signals, submit required notifications, preserve decision evidence, and review each case. In parallel, continue secure-design, support-period, technical-documentation, conformity-assessment, declaration, and CE-marking work for full application on 11 December 2027.

Compliance Checklist

0 / 12

checklist Products, roles, and access

checklist Triage and notification

checklist Exercise and evidence

CRA Reporting Versus Full CRA Application

The early reporting duty and the later product-compliance regime have different dates and operational owners.

AreaApplies fromPrimary ownerImmediate evidence
Article 14 reporting11 September 2026Manufacturer product-security and incident teamsAwareness time, triage decision, staged notifications, platform receipts, user communications
Open-source steward reporting11 September 2026Qualifying open-source software stewardDeployment involvement, reportability assessment, staged notifications, coordination records
Main product and conformity duties11 December 2027Manufacturer product, engineering, compliance, and conformity teamsRisk assessment, technical documentation, vulnerability handling, support period, declaration, CE marking

Common Misconceptions

cancel
Myth

Nothing under the CRA is mandatory until December 2027.

check_circle
Reality

Article 14 reporting starts on 11 September 2026, fifteen months before the main product requirements apply.

cancel
Myth

Only products launched after the full CRA deadline need incident reporting.

check_circle
Reality

The reporting duty applies to in-scope products already made available on the EU market before 11 December 2027.

cancel
Myth

Every software vulnerability must be reported within 24 hours.

check_circle
Reality

Mandatory Article 14 reporting concerns actively exploited vulnerabilities contained in the product and severe incidents affecting product security, using the statutory definitions and criteria.

cancel
Myth

A single group security team can file separate reports for every subsidiary without coordination.

check_circle
Reality

ENISA states that only one notification is required for a reportable event even where the manufacturer has multiple EU branches or a non-EU parent, so internal coordination and authority must be explicit.

Penalties & Enforcement

warning

CRA penalties depend on the breached provision and national enforcement. The regulation requires maximum administrative fines of at least EUR 15 million or 2.5% of worldwide annual turnover for breaches of essential cybersecurity obligations, EUR 10 million or 2% for other obligations, and EUR 5 million or 1% for incorrect, incomplete, or misleading information. Market-surveillance measures can also restrict or withdraw products.

Frequently Asked Questions

When do CRA reporting obligations start?

expand_more

Article 14 reporting obligations apply from 11 September 2026. The CRA's main product cybersecurity and conformity obligations apply from 11 December 2027, but reporting is an earlier operational deadline.

What must be reported under the CRA?

expand_more

Manufacturers must report actively exploited vulnerabilities contained in an in-scope product and severe incidents affecting the security of that product. Open-source software stewards have related duties under Article 24 when its conditions apply.

What are the CRA reporting deadlines?

expand_more

Submit an early warning without undue delay and within 24 hours of awareness, then a fuller notification within 72 hours. The final report is due within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the 72-hour notification for a severe incident.

Do products sold before December 2027 fall under the reporting duty?

expand_more

Yes. The reporting obligations apply to in-scope products with digital elements already made available on the EU market before 11 December 2027. A manufacturer does not retrospectively report active exploitation it already knew about before 11 September 2026, but awareness after that date can trigger reporting even for an older vulnerability.

How is a CRA report submitted?

expand_more

The assigned representative submits one notification through ENISA's Single Reporting Platform and selects the appropriate CSIRT designated as coordinator. ENISA says the initial release requires the web interface and EU Login with multi-factor authentication; no reporting API is available at launch.

Does CRA reporting replace other incident notifications?

expand_more

No. A CRA notification does not automatically satisfy NIS2, GDPR, sector regulation, contractual notice, law-enforcement, or customer obligations. Organizations should map overlapping triggers, recipients, deadlines, and confidentiality rules separately.

Official Documentation

View All

Related Categories