CRA reporting obligations: 24h, 72h, final report
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products: an early warning within 24 hours, a notification within 72 hours and a final report later. Reports are submitted via the ENISA Single Reporting Platform to the competent CSIRT, in Germany the BSI.
Last updated:
What must be reported?
- Actively exploited vulnerabilities: vulnerabilities in your product for which there is reliable evidence of exploitation by a malicious actor.
- Severe incidents affecting the security of your product: incidents that affect or can affect the availability, authenticity, integrity or confidentiality of data or functions, or that led or can lead to malicious code being introduced into the product or user systems.
Timeline
| Stage | Deadline | Content (simplified) |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | That the vulnerability or incident exists; member states where the product is available; for incidents, whether a malicious act is suspected |
| Notification | Within 72 hours of becoming aware | General information on the product, nature of the exploit or incident, corrective or mitigating measures taken and those users can take, sensitivity of the information |
| Final report (vulnerability) | No later than 14 days after a corrective or mitigating measure is available | Description and severity, information on the malicious actor where available, details of the security update or measures |
| Final report (incident) | Within one month after the incident notification | Detailed description and severity, likely root cause, applied and ongoing mitigation |
Where to report
Reports go through the ENISA Single Reporting Platform (SRP), operational since 11 September 2026. They are routed to the CSIRT designated as coordinator in the member state of your main establishment, in Germany the BSI, and made available to ENISA.
Products already on the market
Under Art. 69(3), the reporting obligations also apply to products placed on the market before 11 December 2027. If your software is sold in the EU today, you must be ready to report now.
Micro and small enterprises
Micro and small enterprises cannot be fined for missing the 24-hour early warning deadline. The obligation to report itself still applies, as do the 72-hour and final report deadlines.
Informing users
After becoming aware, you must also inform affected users (and, where appropriate, all users) about the vulnerability or incident and about risk mitigation and corrective measures they can take, where needed in a structured, machine-readable format.
Preparing a reporting runbook
- Name owners and deputies who can submit within 24 hours, including weekends.
- Register with the ENISA SRP and know your competent CSIRT.
- Keep a current product inventory with versions, member states and SBOMs.
- Define criteria for "actively exploited" and "severe incident" and a triage path.
- Prepare templates for the three report stages and for user communication.
- Practise with a tabletop exercise.
How Nuowei helps
Nuowei monitors your repositories and dependencies for known vulnerabilities, keeps an up-to-date SBOM and provides a reporting workflow that prepares the data for each report stage. Submission stays with you as the manufacturer: Nuowei prepares, you review and submit via the SRP.