CRA reporting starts 11 September 2026: 21-day countdown for products with digital elements
The Cyber Resilience Act’s first operational obligation lands on 11 September 2026: manufacturers of products with digital elements — software included — must report actively exploited vulnerabilities and severe incidents affecting product security to their CSIRT and ENISA. The main body of CRA obligations (secure-by-design requirements, conformity assessment, CE marking) applies from 11 December 2027, but reporting comes first — and reporting readiness is an operational capability, not a document.
What the duty looks like
- Early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
- Notification within 72 hours with an assessment, and a final report as prescribed.
- Scope is broad: if you place software or connected products on the EU market under your name, assume you are in until analysis says otherwise.
Readiness in five moves
- Decide who becomes aware. The clock starts at awareness — define detection sources and an internal route that survives weekends.
- Map your reporting endpoints (national CSIRT, ENISA platform) and pre-draft the templates.
- Connect vulnerability handling to legal. Exploited-in-the-wild triage must trigger reporting analysis automatically.
- Flow the duty down to suppliers — contractual notice obligations, SBOM expectations and response times.
- Rehearse once before September. A two-hour tabletop now is cheaper than a first live run against a 24-hour clock.
For organisations also in NIS2 or DORA scope, align the three reporting tracks — same facts, different regulators and thresholds — into one incident playbook.
Sources: Regulation (EU) 2024/2847 (CRA) · European Commission — CRA reporting obligations