Cyber Resilience Act

The CRA reporting clock starts 11 September 2026

From that date, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities on a 24-hour clock — regardless of when the product shipped.

Last updated 14 August 2026

days to 11 Sep 2026
24hearly warning to ENISA
72hfull notification
14dfinal report after a fix exists
days to 11 Dec 2027
Art. 71full CRA compliance deadline

What actually happens on that date

The EU Cyber Resilience Act's incident and vulnerability reporting obligation (Article 14) becomes enforceable. If your product has digital elements and reaches the EU market, and one of its vulnerabilities is being actively exploited, you are required to notify ENISA and your relevant national CSIRT: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available.

Sources: European Commission — CRA reporting obligations, Crowell & Moring — CRA countdown.

This isn't the only CRA deadline

11 September 2026 only starts the reporting obligation above (Article 14). The bigger deadline is 11 December 2027 (Article 71): from that date, the CRA's full essential cybersecurity requirements, conformity assessment and CE marking apply to every relevant product placed on the EU market. A product that's already handling incident reporting correctly can still be non-compliant against this larger requirement if the underlying design and documentation work hasn't started.

Source: European Commission — Cyber Resilience Act (Article 71).

Who this actually applies to

Products with digital elements: connected hardware, firmware-driven devices, IoT, embedded systems, and the software that ships with them. It applies to products already on the market, not only new launches — a device that shipped years ago is still in scope for as long as it's out there and you're still the manufacturer of record.

The trigger isn't every CVE

Reporting is triggered by active exploitation in the wild, not by every vulnerability disclosure. That's a narrower bar than "any CVE we find" — but it means the clock can start with no warning, on a vulnerability discovered by someone else, at any hour. The obligation is only meetable if the process to run it already exists before that happens.

Questions

What happens on 11 September 2026?

The EU Cyber Resilience Act's incident and vulnerability reporting obligations (Article 14) become enforceable. Manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT — an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure becomes available.

Does this apply to my product?

If it has digital elements and reaches the EU market — hardware with firmware, connected devices, IoT, embedded systems, software — it's almost certainly in scope, including products that shipped years before this deadline. The trigger is active exploitation in the wild, not every CVE, but you need the process in place before it happens, not after.

What do I actually need before September?

A vulnerability-management process you can actually run under a 24-hour clock, a current software bill of materials (SBOM) for what you ship, and a designated route to ENISA and your national CSIRT. If none of that exists yet, the gap is process and documentation, not a lab booking — which is usually the faster part to close.

How is this different from CE/UKCA/FCC certification?

CE, UKCA and FCC are pre-market approvals — you get them once, before you sell. CRA reporting is an ongoing post-market obligation that runs for as long as the product is out there. A product can be fully CE-marked and still be non-compliant with CRA reporting if nobody owns the process.

Is 11 September 2026 the only CRA deadline?

No. 11 September 2026 only starts the incident and vulnerability reporting obligation (Article 14). Full CRA compliance — the essential cybersecurity requirements, conformity assessment and CE marking under the CRA itself (Article 71) — applies to every product placed on the EU market from 11 December 2027. A product can be past the reporting deadline and still have the bigger compliance deadline ahead of it.

Where we fit

We're the project-management layer that gets certification and compliance work actually delivered through accredited partners — CE, UKCA, FCC and now the process work CRA reporting requires. If you don't yet have an SBOM, a vulnerability-management process, or a clear route to ENISA and your national CSIRT, that's exactly the kind of gap a scoping call is for.

Book a scoping call