The EU Cyber Resilience Act: your 24-hour vulnerability reporting clock.
Starting September 11, 2026, manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities within 24 hours — regardless of where the company is headquartered. Here's what Article 14 actually requires, who it applies to, and how to be ready.
Update (July 27, 2026): The European Commission published its first substantive CRA implementation guidance (Communication C(2026) 5252) — non-binding, with 67 practical examples aimed at microenterprises and SMEs. It clarifies the scope of free and open-source software and remote data processing solutions, defines "substantial modification," and details support-period requirements. It does not change the September 11, 2026 or December 11, 2027 dates already in effect. Read the brief for what it means for open-source software →
Correction (September 9, 2026): An earlier version of the Single Reporting Platform section stated that unverified manufacturer accounts were capped at ten notifications and advised completing registration early. Both were wrong. ENISA's own FAQ, updated September 4, 2026, puts the cap at 20 notifications per manufacturer before validation becomes mandatory, and recommends against registering before an actual notification is ready. The section below has been corrected against that primary source.
A hard mandate arrives while everyone's watching the 2027 deadline.
Most CRA preparation conversations center on December 11, 2027 — the full-application date requiring CE marking, conformity assessment, and complete technical documentation. That focus is understandable, but it's masking a much closer deadline with real operational teeth.
Article 14 of the Cyber Resilience Act — the vulnerability and incident reporting obligation — takes effect September 11, 2026. Regulation (EU) 2024/2847, Article 71(2), states plainly: "Article 14 shall apply from 11 September 2026." This is a detection-to-disclosure workflow that has to function correctly the first time a reportable event occurs, because the reporting clock starts the moment your organization becomes aware of the issue — not when you're ready to report it. The obligation applies to products already on the EU market, not just new releases; legacy products shipped years ago are in scope if they're still available in the EU today.
Broader than most companies assume — including yours, possibly.
Any "product with digital elements" made available on the EU market. This spans far beyond IoT devices — software, embedded systems, operational technology, medical equipment, and networking gear are all in scope if they connect to a network or process data.
Any manufacturer whose products reach the EU market, regardless of where the company is headquartered or the product is built. Non-EU manufacturers — including US-based companies — must designate an authorized EU representative to interface with the reporting platform and national CSIRTs.
Only two categories — an actively exploited vulnerability, or a severe incident affecting product security. Vulnerabilities discovered and patched before exploitation don't trigger the Article 14 clock; they're handled through ordinary vulnerability management.
Three deadlines, starting the moment you become aware.
Article 14 defines a strict three-stage reporting sequence. Each stage has its own clock, and all three clocks start from the same trigger: the moment your organization becomes aware of active exploitation or a severe incident.
A preliminary notification to ENISA and the relevant national CSIRT with initial information on the affected product, the nature of the vulnerability, and potential impact. Speed matters more than completeness at this stage.
A more detailed technical assessment, expanding on the initial warning with fuller information about the vulnerability and its scope.
Vulnerabilities: within 14 days after a corrective or mitigating measure becomes available. Severe incidents: within one month after the initial 72-hour notification. Closes the loop with root-cause analysis and corrective action taken.
The ENISA Single Reporting Platform (SRP).
All Article 14 reports go through the ENISA Single Reporting Platform — a single entry point that automatically routes each notification to the CSIRT in the manufacturer's designated member state and, in most cases, to ENISA simultaneously. Manufacturers report once; the platform handles cross-border distribution to CSIRTs in every EU member state where the affected product is available.
The SRP became operational in mid-August 2026, ahead of the September 11 compliance date. Per ENISA's own FAQ, non-validated Assigned Representatives may submit up to 20 notifications for one manufacturer before validation becomes mandatory; validation runs in parallel with reporting and does not block a manufacturer from submitting while it's pending. Registration requires an EU Login account secured with multi-factor authentication; each manufacturer designates one Primary Assigned Representative, who can authorize up to 20 Secondary Representatives to file on the organization's behalf. ENISA's guidance recommends against registering before it's needed — to limit validation workload on national CSIRTs, organizations are advised to begin registration only when they have an actual notification to submit. If your organization already has an active EU Login account with MFA enabled, ENISA states registration on the platform itself takes just a few minutes: the preparation worth doing now is making sure that EU Login account exists and is ready, not completing the SRP registration early.
There is no API at initial launch. Notifications must be submitted through the platform's interface directly. Organizations planning to integrate CRA reporting into their own internal systems can build that internal workflow now, but should not expect an API to submit through at launch.
Only mandatory reporting works on September 11. The platform will accept Article 14/24 mandatory notifications — actively exploited vulnerabilities and severe incidents — at launch. Voluntary reporting under Article 15 is not available yet and will come in a later phase.
Known platform quirk: in the SRP's current release, the 72-hour countdown starts from when the 24-hour early warning was submitted, not from the actual moment of awareness — so a notification can display as “overdue” before the true 72 hours have elapsed. ENISA states this will be corrected in a future release. A false “overdue” flag is not a compliance failure.
Non-compliance with CRA reporting obligations carries fines up to €15 million or 2.5% of global annual turnover, whichever is higher, for serious breaches. This penalty structure applies specifically to the reporting failures under Article 14 — separate from the broader conformity-assessment penalty framework that applies once the 2027 full-application deadline arrives.
Because enforcement of a missed 24-hour window doesn't require the extended audit cycle that conformity-assessment enforcement does, this is likely to be where the CRA's first real fines originate — well before the 2027 deadline most organizations are focused on.
Don't confuse the reporting deadline with the conformity deadline.
| Article 14 — Vulnerability Reporting | Full CRA Conformity | |
|---|---|---|
| Effective date | September 11, 2026 | December 11, 2027 |
| What it requires | 24hr/72hr/14-day reporting of actively exploited vulnerabilities and severe incidents | CE marking, full conformity assessment, complete technical documentation |
| Scope | Products already on the EU market, including legacy products | Governs new product placement and ongoing compliance |
| Enforcement pattern | Real-time — a missed 24-hour window is immediately visible | Audit-based — surfaces through conformity assessment reviews |
Organizations already subject to NIS2 incident-reporting obligations as regulated entities, and separately in scope for the CRA as product manufacturers, carry two notification regimes at once. Their triggers, timeframes, and receiving authorities do not align cleanly, so a single detected event can surface conflicting internal deadlines. Map the two side by side before you need to file under either.
Some existing EU type-examination certificates and approval decisions can remain valid until June 11, 2028 unless they expire earlier — but that transitional allowance applies to conformity assessment, not to the September 2026 reporting obligation, which has no such grace period.
CRA Article 14 readiness checklist.
Many products in scope carry significant open-source dependencies — the same components generating the report-volume pressure we track on our Open-Source Coordination Programs card (Akrites, Athena). That volume is exactly what your SBOM and triage process need to be able to absorb before September 11.
The gap this checklist closes is measurable. ENISA surveyed 194 organizations across 31 EU member states in February and March 2026 and found incident response and product lifecycle management to be the two weakest capability domains industry-wide — the exact two the September 11 reporting obligation depends on.
The EU Cyber Resilience Act, answered.
What is the EU Cyber Resilience Act's vulnerability reporting deadline?
Article 14 (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements sold into the EU to report actively exploited vulnerabilities and severe security incidents starting September 11, 2026 — separate from full conformity and CE-marking requirements, which apply from December 11, 2027.
Does the EU Cyber Resilience Act apply to US companies?
Yes. The CRA applies to any manufacturer whose products reach the EU market, regardless of where the company is headquartered or the product is built. Non-EU manufacturers must designate an authorized EU representative to interface with the ENISA Single Reporting Platform and relevant national CSIRTs.
What are the CRA's vulnerability reporting deadlines?
A three-stage ladder: a 24-hour early warning to ENISA and the relevant national CSIRT from the moment of becoming aware of active exploitation, a 72-hour full notification, and a final report within 14 days of a corrective measure becoming available (or one month after the initial notification, for severe incidents).
What triggers CRA Article 14 reporting?
Only actively exploited vulnerabilities and severe incidents affecting product security. Vulnerabilities discovered and patched before exploitation occurs are handled through ordinary vulnerability management and do not trigger the Article 14 clock.
What are the penalties for missing a CRA reporting deadline?
Fines of up to €15 million or 2.5% of global annual turnover, whichever is higher, for serious breaches of the Article 14 reporting obligation.