From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents within 24 hours. It is the first hard deadline under the EU Cyber Resilience Act (CRA) — full conformity only follows in December 2027.
The CRA (Regulation (EU) 2024/2847) has been in force since December 2024 but takes effect in phases. The first set of obligations concerns the reporting of vulnerabilities and incidents under Article 14. Reports are filed through the Single Reporting Platform (SRP) run by the EU agency ENISA and go to the relevant national CSIRT and to ENISA — so the burden does not fall on multiple authorities but runs through one central channel.
What applies from 11 September
- Early warning: within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
- Notification: within 72 hours, with technical detail, severity and initial mitigating measures.
- Final report: after 14 days (vulnerability, once a fix is available) or one month (severe incident).
Who is affected — and the role of open source
The rules cover manufacturers of “products with digital elements” made available on the EU market — including products already in circulation, not just new releases. For the open-source world, the CRA creates the special role of the “open-source software steward” (Art. 24): foundations and organisations that support open-source software commercially face lighter but distinct duties — including reporting obligations where they are involved in development. Purely voluntary, non-commercial contributors remain exempt.
Context
The deadline is fixed, but the technology lags: shortly before the cut-off, the ENISA platform was not yet fully operational. Breaches can be fined up to EUR 15 million or 2.5% of global annual turnover. 11 September is therefore a milestone, not an endpoint: full CRA conformity with all manufacturer and product obligations applies from 11 December 2027. Affected parties should define reporting processes and responsibilities now.
Sources: European Commission – CRA Reporting · ENISA – Single Reporting Platform · CRA – Reporting (Art. 14) · Greenbone – CRA reporting duties



















