EU Cyber Resilience Act
Last updated 31stJuly 2026 - page created
Mandatory reporting obligations under the CRA commence on 11th September 2026—over a year ahead of full technical product compliance rules (December 2027). All entities in scope must report actively exploited vulnerabilities and severe incidents starting on this date.
What is the Cyber Resilience Act?
Entered into force on 10th December 2024, the Cyber Resilience Act (CRA) introduces mandatory cybersecurity standards for hardware and software products made available on the EU market. Manufacturers remain responsible for vulnerability handling throughout a product's full operational lifecycle.
Core Objectives
- Enforce secure-by-design principles during product development.
- Mandate active vulnerability management and lifecycle patching.
- Enhance user transparency regarding support periods and updates.
- Create a harmonised cybersecurity baseline across all EU Member States.
Products in Scope
Applies to Products with Digital Elements (PDEs)—any hardware or software that connects directly or indirectly to a network (e.g., laptops, smart devices, OS, mobile apps, industrial IoT).
Note: There are specific exemptions for offline products and strictly excluded sectors, however manufacturers must undertake their own appropriate legal and technical assessment to determine if their products fall within these exemptions.
Mandatory Reporting Thresholds
Starting 11th September 2026, manufacturers of products made available in the EU market must report two categories of security events affecting their products:
1. Actively Exploited Vulnerabilities
Any software or hardware flaw where reliable evidence shows a malicious actor is actively exploiting the vulnerability in the wild.
2. Severe Incidents
Any operational security incident that negatively affects (or could affect) a product's security functions, data confidentiality, or system integrity.
Third-Party Components: If an actively exploited vulnerability or a severe incident occurs in a third-party component integrated into your product, you, as the final product manufacturer, are required to report once you confirm your product is affected.
Legacy Products: Products placed on the market prior to December 2027 are exempt from design rules, but are fully subject to reporting obligations if currently available on the EU market.
Statutory Reporting Timelines
Notifications are submitted sequentially via the ENISA Single Reporting Platform (SRP):
24 Hours
Early Warning Notification
- Submitted within 24 hours of becoming aware of an active exploit or severe incident.
- A baseline notice highlighting suspected malicious intent and impacted Member States.
- Do not delay submission pending a deep technical analysis.
+48 Hours
Detailed Notification ("72-Hour Report")
- Must be submitted within 48 hours of the Early Warning submission (72 hours total from initial awareness).
- Provides initial severity assessments, root causes, nature of the event, and temporary mitigations/workarounds.
Final
Final Report
- Active Exploits: Submitted within 14 days after a corrective patch or workaround is made available.
- Severe Incidents: Submitted no later than 1 month after the Stage 2 Detailed Notification.
- Contains complete root-cause analysis, patch details, and corrective actions taken.
Platform Submission & Emergency Protocol
All CRA notifications must be submitted through ENISA's Single Reporting Platform (SRP), which automatically routes reports to the relevant national CSIRT and ENISA simultaneously.
Emergency Fallback Protocol (SRP Offline Only)
In the event that the SRP experiences an outage, a fallback mechanism will be activated.
Strict Usage Condition:
Submissions via email will ONLY be accepted when the SRP is officially declared offline by ENISA via their official status portal. Reports sent to this address while the SRP is operational will not fulfill your statutory legal obligations.
Notifications submitted via email must use ENISA's official templates.
An emergency reporting email address will be provided from the 11th September 2026.