CRA reporting: actively exploited vulnerabilities and severe incidents
Article 14 of the Cyber Resilience Act has applied since 11 September 2026, ahead of the rest of the Regulation. It covers every product with digital elements in scope, including products placed on the market before 11 December 2027 (Article 69(3)).
Checked against the sources on 7 October 2026
What must be reported
- an actively exploited vulnerability in your product that you become aware of (Article 14(1));
- a severe incident having an impact on the security of your product (Article 14(3)): one that affects, or can affect, the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or can lead to malicious code being introduced or run in the product or in a user's systems (Article 14(5)).
Deadlines, counted from when you become aware
| Step | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 hours, naming the Member States where you know the product is available. | Within 24 hours, also saying whether unlawful or malicious acts are suspected. |
| Notification | Within 72 hours: the product, the nature of the exploit and the vulnerability, measures taken and measures users can take, and how sensitive you consider the information. | Within 72 hours: the nature of the incident, an initial assessment, measures taken and measures users can take, and how sensitive you consider the information. |
| Final report | No later than 14 days after a corrective or mitigating measure is available: the vulnerability with its severity and impact, any malicious actor, and the security update. | Within one month after the notification: a detailed description, the likely threat or root cause, and the mitigation measures. |
The CSIRT that receives the notification may ask for an intermediate report on status updates (Article 14(6)).
Where to report
Through ENISA's Single Reporting Platform, which opened on 11 September 2026. You submit to the CSIRT designated as coordinator in the Member State of your main establishment in the EU, which is where decisions on your products' cybersecurity are mainly taken. ENISA receives the notification at the same time, and the CSIRT passes it on to the other Member States where the product is available (Articles 14(7) and 16).
Manufacturers outside the EU
Without a main establishment in the EU, report to the CSIRT of the first Member State in this list that applies (Article 14(7)):
- where the authorised representative acting for the highest number of your products is established;
- where the importer placing the highest number of your products on the market is established;
- where the distributor making the highest number of your products available is established;
- where the highest number of your products' users are located.
Tell your users
Inform the affected users, and where appropriate all users, of the vulnerability or incident and of the measures they can take, where appropriate in a structured, machine-readable format (Article 14(8)). If you do not do so in time, the CSIRT may inform them.
Get ready before it happens
- register on the Single Reporting Platform (ENISA publishes a user guide);
- decide who judges, within 24 hours, whether a vulnerability is actively exploited or an incident severe;
- keep a list of the Member States where each product is sold, and of your authorised representative, importers and distributors;
- prepare a template for the notice to users.
Which class is your product in, and does it need a notified body? See the Cyber Resilience Act page.