CRA Vulnerability Reporting: 8 Days to September 11

Daniel Okafor··5 min read
Software engineer reviewing code on screen ahead of the EU Cyber Resilience Act reporting deadline

Eight days from now, the EU Cyber Resilience Act stops being a future obligation. From September 11, 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents under Article 14 of the CRA, according to the European Commission's CRA reporting page. It is the first hard deadline of the regulation, arriving more than a year before the full set of CRA obligations applies, and it comes with a clock that starts at 24 hours.

If your organization ships software, firmware or connected hardware into the EU market, this applies to you, and the products already on the market are not exempt. The remaining eight days are not enough to build a reporting capability from scratch, but they are enough to test whether the one you have actually works.

September 11: The First Hard CRA Deadline

The CRA phases in over several years, and its full obligations, including security-by-design requirements and conformity assessment, apply from December 11, 2027. But the reporting duties come first, and they come alone. As Crowell and Moring's client alert emphasizes, the September 2026 reporting duty applies even to products that were placed on the market long before the CRA existed. There is no grandfathering for the installed base: if your product is out there and you become aware of active exploitation, you report.

Awareness has a defined meaning here. Per the Crowell analysis, a manufacturer is aware once it has a reasonable degree of certainty that active exploitation of a vulnerability, or a severe incident, has occurred. You do not need a completed forensic investigation to be on the clock, and waiting for perfect information is not a defense. The moment credible evidence crosses that threshold, the timeline below is running.

The Reporting Cascade: 24 Hours, 72 Hours, Final Report

Article 14 establishes a three-stage cascade for actively exploited vulnerabilities:

  • Early warning within 24 hours of becoming aware
  • Full notification within 72 hours, with general information on the vulnerability, its severity and any corrective or mitigating measures taken or available
  • Final report within 14 days after a corrective measure is available

Severe incidents follow the same 24-hour and 72-hour rhythm, with the final report due within one month. Readers who work in EU financial services or critical infrastructure will recognize the pattern: the CRA borrows the multi-stage reporting design already familiar from NIS2, whose requirements we covered when the directive took effect. The EU is standardizing on the idea that regulators want an early, imperfect signal fast, followed by structured detail as the picture clarifies.

One Report, One Platform: The SRP

The mechanics are deliberately centralized. Manufacturers submit a single report through the CRA Single Reporting Platform (SRP), which routes it to the CSIRT of the manufacturer's main establishment and shares it with ENISA, as described on the ENISA SRP page. One submission satisfies the notification duty; there is no need to notify 27 national authorities separately.

ENISA has been publishing SRP registration instructions, training material and dry-run exercises since June 2026, and the platform must be operational by September 11. Two practical details matter for planning. First, registration is a prerequisite: an organization that has not onboarded to the SRP before its first incident will be doing account setup while its 24-hour clock runs. Second, there is no API at launch, so submissions are manual. Whoever owns reporting in your organization needs working credentials and hands-on familiarity with the forms, not a bookmark and good intentions.

The 24-Hour Clock Is a People Problem

Strip away the legal language and the CRA reporting duty reduces to a simple operational question: when evidence of active exploitation first touches your organization, how long does it take to reach the person who can file? That first contact is rarely the CISO. It is a support engineer reading a strange customer ticket, a developer triaging a crash report that looks deliberate, a community manager seeing a proof-of-concept posted publicly, or a sales engineer forwarded a security researcher's email.

Each of those people either recognizes the signal and escalates it, or the 24-hour window quietly closes. That makes CRA readiness a security awareness training problem as much as a process problem. Support, development, product and security staff need to know three things cold: what active exploitation evidence looks like from their seat, who to escalate it to, and that speed beats certainty, because the reasonable-certainty threshold arrives earlier than most engineers instinctively assume. Documented training on this escalation path also becomes part of your due-diligence evidence if a report is ever late and a market-surveillance authority asks why.

Tabletop the scenario before September 11: hand the support team a fake exploitation report on a Friday afternoon and time how long it takes to reach the person with SRP credentials. The stopwatch will tell you more than any policy review.

What This Means for Your Organization

Eight days is enough time to verify readiness, if you focus on the failure points that actually burn the clock:

  • Confirm scope now. If you manufacture products with digital elements sold in the EU, including products already on the market, the duty applies to you from September 11.
  • Register on the SRP and have at least two people with working credentials who have practiced the manual submission flow using ENISA's materials.
  • Define awareness internally. Write down what reasonable certainty of active exploitation means for your products and who makes the call, so the 24-hour clock has an unambiguous start.
  • Train the front line. Support, dev and security staff must recognize exploitation signals and know the escalation path; run the tabletop this week, not after the first real report.
  • Pre-draft the templates. An early-warning skeleton with placeholders turns a 24-hour scramble into a fill-in exercise.

December 2027 will bring the CRA's heavyweight obligations, but September 11 is the day EU regulators start seeing which manufacturers can execute under time pressure. Make sure the first thing they learn about your organization is not a missed deadline.

Share: