SSolarc Labs
Buyer-intent answers

EU Cyber Resilience Act · reporting · 11 September 2026

CRA Reporting From 11 September 2026: What the 24h and 72h Steps Mean

An evidence-backed operating answer for manufacturers preparing for the Cyber Resilience Act reporting obligations that apply from 11 September 2026, including the 24-hour early warning, 72-hour notification and later final-report stages.

Primary query: CRA reporting obligations 24 hours 72 hours 11 September 2026 · Updated 2026-09-10

Direct answer

What must manufacturers report under the CRA from 11 September 2026, and when?

From 11 September 2026, Article 14 of the Cyber Resilience Act applies to manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The European Commission says manufacturers need an early warning within 24 hours of becoming aware and a full notification within 72 hours through the CRA Single Reporting Platform. The Commission also describes later final-report deadlines: no later than 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability, and within one month from the 72-hour submission for a severe incident.

Practical sequence

What to do next

  1. 01

    Assign a named CRA reporting owner and backup before an event occurs, with a documented escalation path to security, product, legal and operational decision-makers.

  2. 02

    Preserve the earliest reliable awareness timestamp and the evidence that supports it; do not reconstruct the reporting clock from memory after the incident has progressed.

  3. 03

    Separate confirmed technical and product-impact facts from assumptions, and use the organisation’s approved legal and security process to decide whether the event meets the CRA reporting trigger.

  4. 04

    Prepare the 24-hour early warning through the official CRA Single Reporting Platform without waiting for a perfect investigation file if the reporting obligation has been determined to apply.

  5. 05

    Continue evidence collection for the 72-hour notification, including technical facts, affected products, impact, mitigation activity and unresolved uncertainty required by the applicable reporting process.

  6. 06

    Track corrective or mitigating measures and retain proof of the reporting trail so the later final-report deadline can be managed and audited.

Decision facts

Application date

Article 14 CRA reporting obligations apply from 11 September 2026.

Initial timing

The Commission describes an early warning within 24 hours of awareness and a full notification within 72 hours.

Reporting channel

Manufacturers report through the CRA Single Reporting Platform established by ENISA.

Later reports

The Commission describes a 14-day-after-corrective-measure deadline for actively exploited vulnerabilities and a one-month-from-72h deadline for severe incidents.

Boundaries

  • This page explains the published reporting sequence; it does not decide whether a product is in scope, whether a vulnerability is actively exploited, whether an incident is severe, or whether a specific event is legally reportable.
  • Use the current Regulation, European Commission guidance, the official Single Reporting Platform and your organisation’s legal/security process for a live reporting decision.
  • Do not enter vulnerability secrets, credentials, personal data or confidential incident evidence into a public web form or third-party tool unless your approved process explicitly permits it.

Primary sources

Free proof before paid workflow

Validate the job with a bounded proof path first.

Run the free CRA 24h / 72h preflight