CRA Dossier

Vulnerability Handling under CRA: the 11 September 2026 Reporting Obligations

by Daniel Thompson-Yvetot

From 11 September 2026, the Cyber Resilience Act's vulnerability and incident reporting obligations apply to manufacturers, and they cover products already on the market, not just new ones. This dossier sets out the 24-hour and 72-hour reporting deadlines, and the 14-day final-report deadline for actively exploited vulnerabilities: what actually triggers them and how to be ready before the clock starts.

← Back to shop

Written for product security and compliance leads.

Why it matters

CRA Article 14 introduces one of the Cyber Resilience Act’s first operational compliance duties, roughly 15 months before the Regulation’s general application date. It covers products already on the market, not only new ones.

The clock that matters starts on awareness of active exploitation, not on discovery of the underlying flaw: the CRA’s 24-hour reporting deadline starts when the manufacturer becomes aware of active exploitation, rather than when the responsible reporting team identifies the underlying flaw. Not every known vulnerability triggers Article 14, only one that is being actively exploited. Strong vulnerability handling helps you spot the difference and act before the clock starts. This dossier sets out where that line sits and what needs to be ready.

What is inside

  • The legal basis for CRA vulnerability reporting: Article 14, Article 3’s definitions of “actively exploited vulnerability”, “incident” and “severe incident”, and the standing vulnerability-handling duties in Annex I, Part II that reporting sits on top of.
  • The two triggers and the three-stage cascade: 24 hours, 72 hours, and a final vulnerability report no later than 14 days after a corrective or mitigating measure becomes available (or a final report within one month for severe incidents).
  • How the ENISA-operated Single Reporting Platform routes a single notification to the CSIRT of the manufacturer’s main establishment.
  • Why “actively exploited” is a narrower gate than “known”, and what that means for the 24-hour clock.
  • The reporting duty’s reach into products already on the market, ahead of the CRA’s general application date.
  • Seven recommended actions, including a CRA reporting runbook with named decision-makers for the 24-hour and 72-hour notification milestones and the applicable final-report deadline.

Who is it for

Product Security and Compliance leads, and whoever owns incident response, at any manufacturer with a product with digital elements already on the EU market.

Basis. CRA Articles 14 and Annex I, Part II; entry-into-application provisions; ENISA Single Reporting Platform.

Written by Daniel Thompson-Yvetot, based on Article 14 and Annex I, Part II of the CRA (8 June 2026).

If you need advice tailored to your product, reporting process or compliance obligations, our CRA experts can help you identify the appropriate next steps.

Contact a CRA expert