EU CRA
Cyber Resilience Act — Regulation (EU) 2024/2847
Standard Introduction
The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity rules for products with digital elements. Its first major operational deadline is 11 September 2026, when manufacturers must begin reporting actively exploited vulnerabilities and severe product-security incidents through ENISA's Single Reporting Platform.
The main product-security, technical-documentation, conformity-assessment, and CE-marking duties apply from 11 December 2027. Reporting starts earlier and reaches in-scope products already made available on the EU market, so product inventories, triage criteria, reporting authority, and evidence workflows need to be operational now.
Reporting Starts 11 September 2026
Manufacturers must use ENISA's Single Reporting Platform for actively exploited vulnerabilities and severe product-security incidents from this date, before the CRA's main product requirements apply.
24-Hour and 72-Hour Stages
An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours and a final report on the applicable vulnerability or incident timetable.
Earlier Products Are Included
The reporting duty reaches in-scope products already made available on the EU market before 11 December 2027, not only products launched after full CRA application.
list_alt CRA Reporting Readiness
- Identify in-scope products with digital elements
- Define actively exploited vulnerability and severe incident decision criteria
- Assign 24-hour triage and reporting authority
- Prepare 72-hour evidence and final-report workflows
- Select the responsible CSIRT designated as coordinator
- Create EU Login accounts with multi-factor authentication for assigned representatives
- Coordinate one notification across subsidiaries and product teams
- Link reporting to user notification, remediation, and evidence retention
Who Needs to Comply?
Manufacturers placing products with digital elements on the EU market are the principal Article 14 reporters. From 11 September 2026, the duty also applies to in-scope products placed on the market before full CRA application. Open-source software stewards have related reporting duties under Article 24 when the statutory conditions are met. Importers and distributors should maintain escalation paths because they must respond when they identify or suspect non-conformity.
Key Requirements
Classify Reportable Events
Document how product-security teams distinguish an actively exploited vulnerability from a severe incident and from events that do not meet Article 14 thresholds.
Submit the 24-Hour Early Warning
Notify through the Single Reporting Platform without undue delay and no later than 24 hours after awareness, using the available facts and affected-market information.
Complete the 72-Hour Notification
Provide the fuller product, exploit or incident, severity, impact, mitigation, and sensitivity information required at the second reporting stage.
Close with the Final Report
For an actively exploited vulnerability, report no later than 14 days after a corrective or mitigating measure becomes available; for a severe incident, report within one month after the 72-hour notification.
Coordinate Users and Evidence
Connect regulatory reporting to affected-user communication, corrective measures, incident and vulnerability records, management escalation, and product-level ownership.
Implementation Roadmap
Map products and reporting ownership
Identify every product with digital elements made available in the EU, including products launched before full CRA application. Assign the legal manufacturer, product-security owner, assigned representatives, approving executive, and CSIRT designated as coordinator.
Define Article 14 decision rules
Translate the legal definitions of actively exploited vulnerability and severe incident into triage criteria. Specify when awareness starts the clock, how third-party component signals are assessed, and who can decide that an event is reportable.
Build and exercise the reporting workflow
Prepare EU Login accounts with multi-factor authentication, reporting templates, evidence sources, approval paths, user-notification steps, and 24-hour, 72-hour, and final-report handoffs. Run a timed tabletop exercise with an incomplete-information scenario.
Operate reporting and full CRA readiness
Monitor vulnerability and incident signals, submit required notifications, preserve decision evidence, and review each case. In parallel, continue secure-design, support-period, technical-documentation, conformity-assessment, declaration, and CE-marking work for full application on 11 December 2027.
Compliance Checklist
checklist Products, roles, and access
checklist Triage and notification
checklist Exercise and evidence
CRA Reporting Versus Full CRA Application
The early reporting duty and the later product-compliance regime have different dates and operational owners.
| Area | Applies from | Primary owner | Immediate evidence |
|---|---|---|---|
| Article 14 reporting | 11 September 2026 | Manufacturer product-security and incident teams | Awareness time, triage decision, staged notifications, platform receipts, user communications |
| Open-source steward reporting | 11 September 2026 | Qualifying open-source software steward | Deployment involvement, reportability assessment, staged notifications, coordination records |
| Main product and conformity duties | 11 December 2027 | Manufacturer product, engineering, compliance, and conformity teams | Risk assessment, technical documentation, vulnerability handling, support period, declaration, CE marking |
Common Misconceptions
Nothing under the CRA is mandatory until December 2027.
Article 14 reporting starts on 11 September 2026, fifteen months before the main product requirements apply.
Only products launched after the full CRA deadline need incident reporting.
The reporting duty applies to in-scope products already made available on the EU market before 11 December 2027.
Every software vulnerability must be reported within 24 hours.
Mandatory Article 14 reporting concerns actively exploited vulnerabilities contained in the product and severe incidents affecting product security, using the statutory definitions and criteria.
A single group security team can file separate reports for every subsidiary without coordination.
ENISA states that only one notification is required for a reportable event even where the manufacturer has multiple EU branches or a non-EU parent, so internal coordination and authority must be explicit.
Penalties & Enforcement
CRA penalties depend on the breached provision and national enforcement. The regulation requires maximum administrative fines of at least EUR 15 million or 2.5% of worldwide annual turnover for breaches of essential cybersecurity obligations, EUR 10 million or 2% for other obligations, and EUR 5 million or 1% for incorrect, incomplete, or misleading information. Market-surveillance measures can also restrict or withdraw products.
Frequently Asked Questions
When do CRA reporting obligations start?
expand_more
Article 14 reporting obligations apply from 11 September 2026. The CRA's main product cybersecurity and conformity obligations apply from 11 December 2027, but reporting is an earlier operational deadline.
What must be reported under the CRA?
expand_more
Manufacturers must report actively exploited vulnerabilities contained in an in-scope product and severe incidents affecting the security of that product. Open-source software stewards have related duties under Article 24 when its conditions apply.
What are the CRA reporting deadlines?
expand_more
Submit an early warning without undue delay and within 24 hours of awareness, then a fuller notification within 72 hours. The final report is due within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the 72-hour notification for a severe incident.
Do products sold before December 2027 fall under the reporting duty?
expand_more
Yes. The reporting obligations apply to in-scope products with digital elements already made available on the EU market before 11 December 2027. A manufacturer does not retrospectively report active exploitation it already knew about before 11 September 2026, but awareness after that date can trigger reporting even for an older vulnerability.
How is a CRA report submitted?
expand_more
The assigned representative submits one notification through ENISA's Single Reporting Platform and selects the appropriate CSIRT designated as coordinator. ENISA says the initial release requires the web interface and EU Login with multi-factor authentication; no reporting API is available at launch.
Does CRA reporting replace other incident notifications?
expand_more
No. A CRA notification does not automatically satisfy NIS2, GDPR, sector regulation, contractual notice, law-enforcement, or customer obligations. Organizations should map overlapping triggers, recipients, deadlines, and confidentiality rules separately.
Official Documentation
Official PDF for EU CRA
Official publication or summary for EU CRA
Official online resource
European Union guidance and reference material
Implementation toolkit
Templates, guidance, or companion resources for EU CRA