What you must be able to report by 11 September 2026
Most of the Cyber Resilience Act's obligations apply from December 2027. One part arrives more than a year earlier: from 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products. If your organization has no process for this yet, this is the deadline that should be on your calendar.
What triggers a report
Two events start the clock:
- You become aware of an actively exploited vulnerability in your product — someone is using it in the wild, not just a finding in a scan.
- You become aware of a severe incident having an impact on the security of your product.
The timeline is the hard part
Reports go to your national CSIRT and ENISA through a single reporting platform, in stages:
- Within 24 hours of awareness: an early warning.
- Within 72 hours: a fuller notification with what you know about the vulnerability or incident and any corrective measures.
- A final report once the situation is handled — for vulnerabilities, after a fix is available.
Twenty-four hours is not much time. It has to cover detection, internal escalation, an assessment of whether the threshold is met, and the submission itself — potentially over a weekend. That only works if the path is defined before the first real case: who is on call, who decides, who submits, and what information is captured at each step.
Users have to be told, too
Beyond the authorities, manufacturers must inform affected users about the vulnerability or incident and about the corrective measures they can take — which means your process also needs a communication channel to customers, not just a form for regulators.
What "ready" looks like
- A defined intake for vulnerability reports from researchers, customers, and your own monitoring — with someone actually watching it.
- Clear criteria and decision ownership for "actively exploited" and "severe incident."
- An escalation path that works within 24 hours, including outside business hours.
- Report templates prepared in advance, so the early warning is a fill-in exercise rather than a drafting exercise.
- At least one dry run. The first time you exercise the process should not be the first real case.
The good news: compared to the rest of the CRA, the reporting process is a contained, well-defined piece of work. For most organizations it's a matter of weeks to set up properly — but only if it's started before the deadline, not after the first incident.
Want a quick assessment of whether your reporting process would hold up?
Book an intro call