Skip to content

CRA reporting obligations: 24h, 72h, final report

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products: an early warning within 24 hours, a notification within 72 hours and a final report later. Reports are submitted via the ENISA Single Reporting Platform to the competent CSIRT, in Germany the BSI.

Last updated:

What must be reported?

  • Actively exploited vulnerabilities: vulnerabilities in your product for which there is reliable evidence of exploitation by a malicious actor.
  • Severe incidents affecting the security of your product: incidents that affect or can affect the availability, authenticity, integrity or confidentiality of data or functions, or that led or can lead to malicious code being introduced into the product or user systems.

Timeline

StageDeadlineContent (simplified)
Early warningWithin 24 hours of becoming awareThat the vulnerability or incident exists; member states where the product is available; for incidents, whether a malicious act is suspected
NotificationWithin 72 hours of becoming awareGeneral information on the product, nature of the exploit or incident, corrective or mitigating measures taken and those users can take, sensitivity of the information
Final report (vulnerability)No later than 14 days after a corrective or mitigating measure is availableDescription and severity, information on the malicious actor where available, details of the security update or measures
Final report (incident)Within one month after the incident notificationDetailed description and severity, likely root cause, applied and ongoing mitigation

Where to report

Reports go through the ENISA Single Reporting Platform (SRP), operational since 11 September 2026. They are routed to the CSIRT designated as coordinator in the member state of your main establishment, in Germany the BSI, and made available to ENISA.

Products already on the market

Under Art. 69(3), the reporting obligations also apply to products placed on the market before 11 December 2027. If your software is sold in the EU today, you must be ready to report now.

Micro and small enterprises

Micro and small enterprises cannot be fined for missing the 24-hour early warning deadline. The obligation to report itself still applies, as do the 72-hour and final report deadlines.

Informing users

After becoming aware, you must also inform affected users (and, where appropriate, all users) about the vulnerability or incident and about risk mitigation and corrective measures they can take, where needed in a structured, machine-readable format.

Preparing a reporting runbook

  1. Name owners and deputies who can submit within 24 hours, including weekends.
  2. Register with the ENISA SRP and know your competent CSIRT.
  3. Keep a current product inventory with versions, member states and SBOMs.
  4. Define criteria for "actively exploited" and "severe incident" and a triage path.
  5. Prepare templates for the three report stages and for user communication.
  6. Practise with a tabletop exercise.

How Nuowei helps

Nuowei monitors your repositories and dependencies for known vulnerabilities, keeps an up-to-date SBOM and provides a reporting workflow that prepares the data for each report stage. Submission stays with you as the manufacturer: Nuowei prepares, you review and submit via the SRP.

Join the waitlist

We launch in November. Be the first to get access.