EU Cyber Resilience Act: 24-Hour Vulnerability and Incident Reporting Duties Apply
On September 11, 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) begins to apply, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents affecting product security. Reports follow a staged timeline: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days for exploited vulnerabilities or one month for severe incidents. Notifications go to the CSIRT designated as coordinator in the relevant Member State and are made available simultaneously to ENISA through a single reporting platform.
Key Analytics
Impact Analysis
This deadline lands more than a year before the CRA's main obligations apply on December 11, 2027, and it reaches further than many teams expect: under the transitional rules in Article 69(3), the reporting duties also cover in-scope products already placed on the market, not just new releases. Any company selling hardware or software with digital elements into the EU, including US vendors, needs a triage process that can distinguish an actively exploited vulnerability or severe incident from routine findings and escalate to regulators within 24 hours. Incident response plans built around GDPR's 72-hour personal data breach clock will need a faster, product-security-specific track, since the CRA clock starts at awareness of exploitation rather than confirmation of a data breach.
Recommended Actions
- Inventory products with digital elements sold into the EU and confirm which fall within CRA scope, including products already on the market.
- Update incident response and vulnerability handling procedures to meet the 24-hour early warning and 72-hour notification deadlines, with documented criteria for what qualifies as an actively exploited vulnerability or severe incident.
- Identify the CSIRT designated as coordinator for your EU main establishment and monitor ENISA guidance on onboarding to the CRA single reporting platform.
- Align the CRA reporting track with existing GDPR and NIS2 notification workflows so a single incident triggers all applicable regulator notifications without duplicated triage.
- Run a tabletop exercise simulating an actively exploited vulnerability to verify your team can produce a compliant early warning within 24 hours.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›CRA scoping of products with digital elements sold into the EU
- ›Incident response update for the 24-hour and 72-hour reporting clocks
- ›Triage criteria for actively exploited vulnerabilities and severe incidents
- ›Tabletop exercise against the 24-hour early warning
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 95 to 205 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.