Summary
- Cyber Resilience Act vulnerability and incident reporting obligations take effect on 11 September 2026.
- ENISA’s Single Reporting Platform will provide one route for notifications rather than separate submissions across affected member states.
- Manufacturers face 24-hour early-warning and 72-hour notification deadlines once they become aware of reportable events.
Manufacturers selling connected and software-based products in the European Union are entering the operational phase of the Cyber Resilience Act, with mandatory reporting of actively exploited vulnerabilities and severe product-security incidents due to begin on 11 September.
The European Union Agency for Cybersecurity, ENISA, has updated guidance on the Single Reporting Platform that organisations will use to meet those obligations. The platform is intended to give manufacturers and open-source software stewards a single reporting route rather than requiring parallel notifications to authorities across multiple EU member states.
Under the process described by ENISA, manufacturers will submit notifications electronically and select the Computer Security Incident Response Team designated as their coordinator. In most cases, the appropriate CSIRT will be determined by the manufacturer’s main place of establishment. ENISA receives the notification, while the coordinating CSIRT handles distribution to other relevant national teams and market-surveillance authorities.
The reporting regime covers two categories of event: actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. An actively exploited vulnerability requires reliable evidence that a malicious actor has used the flaw without the system owner’s permission, while a severe incident is one capable of materially compromising the availability, authenticity, integrity, or confidentiality of a product’s data or functions.
The timetable is considerably tighter than traditional product-security disclosure cycles. Manufacturers must send an early warning without undue delay and, in any event, within 24 hours of becoming aware of a reportable vulnerability or incident. A fuller notification follows within 72 hours. Final reports are then required within 14 days of a corrective measure becoming available for a vulnerability, or within one month of the initial notification for a severe incident.
Those deadlines move vulnerability handling from a largely technical disclosure function into regulated incident-management territory. Determining whether there is reliable evidence of exploitation, identifying which products are affected, establishing the correct reporting entity, and preparing information suitable for authorities may have to happen while an investigation and patching effort are still under way.
The platform also has implications for organisations with complicated product and supply chain structures. A vulnerability discovered in a component may affect products distributed across several countries, while the organisation legally responsible for reporting may not be the engineering team that first detects the problem. Internal escalation, legal ownership, product inventory, and vulnerability intelligence therefore become part of the same reporting process.
ENISA says the platform has been designed to protect confidentiality, although the CRA provides for notifications to be disseminated among relevant authorities. In exceptional circumstances, a coordinating CSIRT may delay or withhold wider dissemination where specified security conditions apply.
The September deadline is only one part of the CRA’s phased implementation, but it is the point at which vulnerability management acquires an immediate statutory reporting dimension. Organisations that manufacture or commercially distribute products with digital elements will no longer be able to treat evidence of active exploitation solely as an internal patch-prioritisation issue.
The technical operation of the Single Reporting Platform will determine how smoothly the first wave of notifications is handled. ENISA says additional user material, including guidance and tutorials, will accompany the platform as it goes live.





