Joglekar.
CRA · Article 14

What you must be able to report by 11 September 2026

June 2026 · Jyohan Joglekar

Most of the Cyber Resilience Act's obligations apply from December 2027. One part arrives more than a year earlier: from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products. If your organization has no process for this yet, this is the deadline that should be on your calendar.

What triggers a report

Two events start the clock:

The timeline is the hard part

Reports go to your national CSIRT and ENISA through a single reporting platform, in stages:

Twenty-four hours is not much time. It has to cover detection, internal escalation, an assessment of whether the threshold is met, and the submission itself — potentially over a weekend. That only works if the path is defined before the first real case: who is on call, who decides, who submits, and what information is captured at each step.

Users have to be told, too

Beyond the authorities, manufacturers must inform affected users about the vulnerability or incident and about the corrective measures they can take — which means your process also needs a communication channel to customers, not just a form for regulators.

What "ready" looks like

The good news: compared to the rest of the CRA, the reporting process is a contained, well-defined piece of work. For most organizations it's a matter of weeks to set up properly — but only if it's started before the deadline, not after the first incident.

Want a quick assessment of whether your reporting process would hold up?

Book an intro call