EU CRA Reporting Goes Live This Friday. Are You Ready?
If you make covered software or hardware sold in the European Union, this Friday marks the start of mandatory security reporting to EU regulators.
The EU Cyber Resilience Act (CRA) became law in December 2024. It sets baseline cybersecurity requirements for products with digital elements (covering many hardware and software products) sold in the EU. Most requirements don't fully kick in until December 2027, but one critical piece starts this week.
As of September 11, manufacturers must begin reporting certain vulnerabilities and security incidents to the European Union Agency for Cybersecurity (ENISA) through its newly launched Single Reporting Platform.
What the Reporting Requirements Actually Require
Under Article 14 of the CRA, if your company discovers a vulnerability in your product that is being actively exploited or suffers a severe security incident affecting your product, you're required to report it. The timelines are strict:
- 24 hours after becoming "aware": submit an early warning to ENISA and your national cybersecurity authority
- 72 hours after becoming "aware": submit a fuller notification with details on the nature of the vulnerability and any initial remediation steps
- 14 days after a patch is available (for exploited vulnerabilities), or 1 month after the initial notification (for severe incidents): submit a final report
European Commission guidance published in July states that the clock starts once you've done an initial assessment and have reasonable certainty that an actively exploited vulnerability or severe incident exists.
One important note: these obligations apply to manufacturers of products with digital elements, not every tech company. If you're uncertain if that applies to you, consult legal counsel for advice specific to your situation.
Why Remediating Quickly Matters
The best way to avoid triggering the CRA's reporting requirements is to find and fix vulnerabilities before they're actively exploited. That makes fast, proactive vulnerability discovery and remediation more important than ever. Organizations that already have mature processes for finding and fixing issues quickly are far less likely to face the scenario the reporting rules aim to cover.
If you do trigger reporting obligations, speed is vital. Twenty-four hours to file an early warning is a very short window without clear processes for triaging vulnerabilities and escalating to the right people. And there's an additional incentive to patch quickly: the final report isn't due until after a fix is available, so faster remediation means a faster close on your reporting obligation too.
What to Do Right Now
- Confirm whether your products fall within the CRA's definition of "products with digital elements"
- Register with ENISA's Single Reporting Platform
- Verify that your internal processes can actually meet the 24/72-hour reporting windows
- If you don't yet have a public vulnerability disclosure policy, establish one; it's a vital component of a mature vulnerability discovery process and will be required under the CRA's broader compliance framework by December 2027
Friday's deadline is a major step, not the finish line. Full CRA compliance applies at the end of 2027. But the reporting obligations starting this week signal what the regulation expects: speed, transparency, and operational readiness. Better to build that muscle now.
Start building your vulnerability disclosure program before the 2027 deadline
This post does not constitute legal advice.