The 60-second brief
- 1Since September 11, manufacturers must send an early warning within 24 hours of learning a product flaw is actively exploited.
- 2Reports go through ENISA's new Single Reporting Platform and cover products already on the market before the rules.
- 3Manufacturers must also inform affected users, which pulls product, legal and communications teams into incident response.
- Early warning deadline
- 24 hours
- Full notification deadline
- 72 hours
- Final report, vulnerabilities
- 14 days after a fix is available
- Main CRA obligations apply
- Dec 11, 2027
Why CEOs should care
For boards of companies that sell connected devices or software into Europe, this is now a live compliance duty with a clock measured in hours. Ask management who decides that a flaw is actively exploited, who files the early warning, and whether that process works on a weekend. Law firm Crowell & Moring's checklist starts with basics: identifying the EU main establishment, setting up platform accounts with multifactor authentication, and designating primary and backup authorized representatives.
For CISOs and product security leaders, the trigger is awareness, which Hogan Lovells Cadwalader describes as a reasonable degree of certainty that a flaw is being exploited. That links product security to threat intelligence: reports from customers, researchers or government catalogs may start the clock. Build a documented reportability assessment, templates for the 24-hour and 72-hour filings, and a log of decisions. Crowell & Moring also advises adding vulnerability disclosure terms to supplier contracts, since a component maker's flaw can become your report.
For general counsel and communications chiefs, user notification is the part that reaches customers. Coordinate CRA filings with parallel duties under the NIS2 directive and GDPR so one incident does not produce three inconsistent stories.
Key takeaways
- Since September 11, manufacturers must send an early warning within 24 hours of learning a product flaw is actively exploited.
- Reports go through ENISA's new Single Reporting Platform and cover products already on the market before the rules.
- Manufacturers must also inform affected users, which pulls product, legal and communications teams into incident response.
The news
The European Union's Cyber Resilience Act reporting obligations took effect on September 11, 2026. Manufacturers of hardware and software products sold in the EU must now report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware of them.
According to the European Commission, the early warning is due within 24 hours, a fuller notification within 72 hours, and a final report no later than 14 days after a fix or mitigation is available for a vulnerability, or within a month of the 72-hour notification for a severe incident. Reports go to the national Computer Security Incident Response Team (CSIRT) where the manufacturer has its main EU establishment, and are generally shared at the same time with ENISA, the EU cybersecurity agency.
ENISA launched the Single Reporting Platform for these filings on September 11. Executive Director Juhan Lepassaar said streamlined reporting helps build a more resilient Digital Single Market. ENISA's guidance says the obligations also apply to products placed on the market before the act's main rules take effect, once a manufacturer becomes aware of an exploited flaw after September 11, 2026. Manufacturers without an EU establishment are assigned a CSIRT based on where their authorized representative, importer or distributor sits, or where most users are.
The broader law entered into force on December 10, 2024, and its main product security requirements apply from December 11, 2027. The Commission published practical guidance for manufacturers on July 27, 2026. Reporting duties for open-source software stewards begin on December 11, 2027.
Law firm Hogan Lovells Cadwalader notes that manufacturers must also inform affected users of an actively exploited vulnerability or severe incident, and where appropriate all users, and that obligations continue after a product's support period ends. ENISA defines an actively exploited vulnerability as one with reliable evidence of exploitation by a malicious actor.
The numbers
- Early warning deadline
- 24 hours
- Full notification deadline
- 72 hours
- Final report, vulnerabilities
- 14 days after a fix is available
- Main CRA obligations apply
- Dec 11, 2027
Why CEOs should care
For boards of companies that sell connected devices or software into Europe, this is now a live compliance duty with a clock measured in hours. Ask management who decides that a flaw is actively exploited, who files the early warning, and whether that process works on a weekend. Law firm Crowell & Moring's checklist starts with basics: identifying the EU main establishment, setting up platform accounts with multifactor authentication, and designating primary and backup authorized representatives.
For CISOs and product security leaders, the trigger is awareness, which Hogan Lovells Cadwalader describes as a reasonable degree of certainty that a flaw is being exploited. That links product security to threat intelligence: reports from customers, researchers or government catalogs may start the clock. Build a documented reportability assessment, templates for the 24-hour and 72-hour filings, and a log of decisions. Crowell & Moring also advises adding vulnerability disclosure terms to supplier contracts, since a component maker's flaw can become your report.
For general counsel and communications chiefs, user notification is the part that reaches customers. Coordinate CRA filings with parallel duties under the NIS2 directive and GDPR so one incident does not produce three inconsistent stories.
The bigger picture
The volume question is real. In September alone, the U.S. Cybersecurity and Infrastructure Security Agency added actively exploited flaws in products from Cisco, Check Point, Citrix, Fortinet, F5, MikroTik, Zyxel, Microsoft and others to its catalog. For manufacturers whose products fall within the CRA, each such discovery now starts a European reporting clock. The regime should give EU authorities an early view of which products are under attack, and gives customers a new lever: they can ask suppliers whether they have filed.
The rules also change the math on legacy products. Because reporting duties outlast the support period, according to Hogan Lovells Cadwalader, a product that is no longer sold or patched but is still in customers' hands can generate filings and user notices years later. Product and finance leaders should factor that tail into end-of-life decisions.
What's next
Watch for ENISA and national CSIRTs to publish early statistics on filings, for guidance on edge cases such as cloud-delivered software, and for procurement teams to add CRA reporting commitments to vendor contracts well before the main requirements arrive in December 2027.
Sources
- GovernmentCyber Resilience Act - Reporting obligations— European Commission
- GovernmentCyber Resilience Act— European Commission
- GovernmentThe CRA Single Reporting Platform is launched— ENISA
- GovernmentSingle Reporting Platform: Frequently Asked Questions— ENISA
- ReportEU Cyber Resilience Act: vulnerability and incident reporting obligations now apply— Hogan Lovells Cadwalader
- ReportIt's live: Cyber Resilience Act reporting is mandatory as of 11 September 2026— Crowell & Moring
- GovernmentKnown Exploited Vulnerabilities Catalog (JSON feed)— CISA
Spotted an error? Request a correction. Read our editorial standards and AI policy.
Free newsletters
The technology briefing for people running businesses.
Daily, weekly, bi-weekly or monthly. You choose.