Summary
- Cyber Resilience Act reporting obligations for manufacturers begin on 11 September 2026.
- Actively exploited vulnerabilities and severe product-security incidents trigger 24-hour, 72-hour, and final-report deadlines.
- ENISA’s platform requires one notification, but manufacturers must identify the coordinating national CSIRT and manage reporting across their corporate structure.
Manufacturers selling connected hardware and software into the European Union enter a new incident-reporting regime on 11 September, when mandatory Cyber Resilience Act notifications begin and ENISA’s Single Reporting Platform becomes operational.
ENISA updated its operational guidance on 8 September, setting out how manufacturers will report actively exploited vulnerabilities and severe incidents affecting products with digital elements. The change brings one of the Cyber Resilience Act’s earliest binding obligations into effect more than a year before most of the regulation’s wider product requirements apply.
An early warning must be submitted without undue delay and, in any event, within 24 hours of a manufacturer becoming aware of a reportable vulnerability or incident. A more detailed notification follows within 72 hours. For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. Severe incidents carry a final-report deadline of one month after the 72-hour notification.
The threshold is narrower than the discovery of an ordinary vulnerability. The Act defines an actively exploited vulnerability as one for which there is reliable evidence that a malicious actor has exploited it without the system owner’s permission. Severe incidents are those that negatively affect, or are capable of negatively affecting, a product’s ability to protect the availability, authenticity, integrity, or confidentiality of data or functions.
Manufacturers submit one notification through the Single Reporting Platform and select the Computer Security Incident Response Team designated as coordinator. ENISA receives the notification simultaneously, while the coordinating CSIRT distributes relevant information to other national CSIRTs in member states where the product is available and, where necessary, to market-surveillance authorities.
A multinational manufacturer therefore avoids filing the same incident separately with every member state, but responsibility for the initial decision remains with the company. ENISA says manufacturers must identify the correct coordinating CSIRT and coordinate internally so that branches, subsidiaries, or a non-EU parent company do not generate conflicting submissions.
The first 24 hours are likely to test those internal arrangements. Product-security investigations frequently begin before scope, affected versions, exploitability, customer exposure, or remediation options are fully understood. Engineering, vulnerability management, incident response, legal, and regulatory functions will have to establish enough reliable information to determine whether the legal threshold has been reached while the investigation is still developing.
The regime also reaches products placed on the EU market before the Cyber Resilience Act’s broader requirements become fully applicable in December 2027, provided those products fall within the Act’s scope. Manufacturers that have treated CRA preparation primarily as a future secure-development or conformity project therefore face an earlier operational obligation.
ENISA’s launch configuration remains relatively manual. Assigned representatives require an EU Login account with multi-factor authentication, and the agency says no application programming interface will be available initially. Companies can automate internal reporting workflows, but submissions themselves must go through the platform interface.
Open-source software stewards operate on a later timetable. Their corresponding mandatory reporting obligations under Article 24(3) begin in December 2027, while voluntary notifications through the platform are also scheduled for a later phase.
Cyber Insider covered preparations for the reporting platform earlier this month. ENISA’s latest guidance fills in operational details around registration, reporting fields, CSIRT selection, internal coordination, and the sequence of submissions immediately before the regime takes effect.
From 11 September, the practical measure of CRA readiness will include whether a manufacturer can recognise a reportable event, establish what it knows at that point, nominate the right people to submit it, and meet a legal clock measured in hours rather than patch cycles.




