Since 11 September 2026, makers of connected products sold in the EU work with a clock. When you learn that attackers use a flaw in your product, you have 24 hours to send a first warning. Two more reports follow, each with its own deadline.
This note walks through that clock one step at a time: what starts it, what each report must contain, where it goes, and what the official reporting platform looks like today. Each step cites the article of the Cyber Resilience Act (CRA), or the official page, that it comes from.
What starts the clock
Two kinds of event start it.
1. An actively exploited vulnerability in your product (Article 14(1)).
Article 3(42)
‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner.
A flaw that nobody has exploited still needs a fix, but it does not start this clock.
2. A severe incident that affects the security of your product (Article 14(3)). An incident is severe when it harms, or can harm, the protection of sensitive or important data or functions, or when it leads, or can lead, to malicious code in your product or in a user’s systems (Article 14(5)).
What about a flaw in a third-party component? It counts when it is exploited in your product. If the vulnerable code cannot be reached in your product, or nobody has exploited it there, it is not a reportable vulnerability for you. The Commission explains this in its guidance on the CRA, paragraph 218. The CRA also asks you to tell the maker of the component (Article 13(6)). Like most duties outside Article 14, that one applies to products placed on the market from 11 December 2027 (Article 69(2)).
When the clock starts
The 24 hours start when you “become aware” (Article 14(2)). The law does not define that moment. The Commission’s guidance of 27 July 2026 explains it.
Commission guidance on the CRA, paragraph 213
The manufacturer is therefore to be regarded as having become aware when, after such an initial assessment, it has a reasonable degree of certainty that: (i) a vulnerability contained in its product with digital elements is being actively exploited; or (ii) a severe incident has occurred and has led to the security of its product with digital elements being compromised.
So the first check must be fast. The guidance says that “the emphasis should be on prompt action to carry out the initial assessment” (paragraph 214). Write down when the report arrived and when your check gave you that reasonable certainty. That moment is your clock.
What about flaws from before the start date? You do not have to report exploitation that you already knew about before 11 September 2026. But if you learn of exploitation after that date, also for an old flaw, the clock applies (paragraph 217).
The three reports for a vulnerability
Within 24 hours: the early warning
You send an early warning “without undue delay and in any event within 24 hours” of becoming aware (Article 14(2)). Where applicable, it says in which Member States your product is available.
On the platform, the early warning asks for the notification type, a title, a summary, the manufacturer name, the Member States where the product is available, the product name and the product version, and the date and time when you became aware. ENISA notes that the date and time field arrives in the next release of the platform (ENISA glossary, version 1.4).
Within 72 hours: the vulnerability notification
Unless you already gave the information, you send a notification within 72 hours of becoming aware (Article 14(2)). It gives general information about the product, the general nature of the exploit and of the vulnerability, the corrective or mitigating measures that you took, and the measures that users can take. It also says how sensitive you consider the information to be.
Watch out for one detail. The platform’s own counter shows this deadline 48 hours after your early warning, so it can show the report as overdue before the 72 hours have passed. ENISA says it will correct this (ENISA FAQ, question 26). The legal deadline runs from the moment you became aware (Commission guidance, paragraph 215). Keep your own clock.
No later than 14 days after a fix: the final report
Unless you already gave the information, you send a final report no later than 14 days after a corrective or mitigating measure is available (Article 14(2)). It includes at least:
- a description of the vulnerability, including its severity and impact;
- where available, information about any malicious actor that exploited it;
- details about the security update or other corrective measures.
For a severe incident, the same rhythm
The steps are the same, with small differences (Article 14(4)):
- Within 24 hours: an early warning that also says whether you suspect unlawful or malicious acts.
- Within 72 hours: an incident notification with the nature of the incident, an initial assessment, and the measures taken and available to users.
- Within one month after the incident notification: a final report with a detailed description, the likely type of threat or root cause, and the mitigation measures.
Where you send the reports
You send every report through the single reporting platform, which ENISA runs (Article 16(1)). It went live on 11 September 2026 at portal.cra-srp.enisa.europa.eu (ENISA).
Inside the platform, the report goes to the CSIRT designated as coordinator in the Member State of your main establishment, and ENISA can see it at the same time (Article 14(7)). A CSIRT is a national computer security incident response team. Your main establishment is where your decisions on product security are mostly taken. If that is not clear, it is where you have the most employees in the EU (Article 14(7)).
Three examples from ENISA’s list of coordinators: CERT-Bund at the BSI in Germany, CERT-FR in France and the NCSC in the Netherlands.
No establishment in the EU? Then you use the coordinator of the first Member State in this order: where your authorised representative for most of your products is, where the importer of most of your products is, where the distributor of most of your products is, or where most of your users are (Article 14(7)).
The coordinator then passes the report to the coordinators of the Member States that you listed (Article 16(2)). In exceptional cases, and on your request for sensitive information, it can delay that step for a limited time (Article 16(2)).
How filing works on the platform today
From the ENISA FAQ, updated 3 October 2026:
- You file through an “Assigned Representative”, who needs an EU Login account with multi-factor authentication (question 9).
- Checks on your representative run in parallel. They do not stop you from filing, and an unchecked representative can send up to 20 notifications (question 9).
- The platform is in English only at launch (question 24). There is no API, so you file through the web interface (question 15).
- If the platform is down, wait and file when it is back. If you must act at once, contact your CSIRT directly, and still file on the platform afterwards (question 25).
Two duties that people forget
- Tell your users. After you become aware, you inform the users who are affected, and where appropriate all users, and tell them what they can do (Article 14(8)). The Commission’s guidance says this is risk-based and “does not imply that such information must be made public” (paragraph 220).
- Answer follow-up questions. The coordinator can ask you for an intermediate report on the status (Article 14(6)).
A note on fines for small companies
Micro and small enterprises cannot get a fine for missing the 24-hour early warning deadlines (Article 64(10)). This covers only the 24-hour deadlines. The other reports, and the duty to report, stay.
Prepare before the first report
- Choose who will file, and create their EU Login accounts with multi-factor authentication.
- Find your coordinating CSIRT on ENISA’s list, based on your main establishment.
- Prepare a draft early warning for each main product: title, summary, Member States, product name and version.
- Keep a log for each event: when the report arrived, when your first check ended, and why you were then reasonably certain.
- Run your own clock outside the platform, from the moment you became aware.
- Prepare a short notice for users, with the measures that they can take.
Where Relvault fits
Relvault prepares the drafts for the early warning, the notification and the final report, and a short runbook for who decides and who files. So the 24 hours go into decisions, not into paperwork. Your company files each report. See how it works and the prices. Read also The email nobody read for a day, about the security inbox that the clock depends on.
Common questions
When does the CRA’s 24-hour clock start?
When you become aware of an actively exploited vulnerability or a severe incident in your product (Article 14(2) and (4)). The Commission’s guidance says this is when, after a prompt first check, you have “a reasonable degree of certainty” (paragraph 213).
Is the 72-hour deadline counted from the early warning?
No. It is counted from the moment you became aware (Article 14(2); Commission guidance, paragraph 215). The platform’s counter currently shows a different time, which ENISA plans to correct.
Do I report flaws that I knew about before 11 September 2026?
Not if you already knew about their exploitation before that date. If you learn of exploitation after it, you report it (Commission guidance, paragraph 217).
Does an exploited flaw in an open-source component count?
Yes, when it is exploited in your product. If the code cannot be reached in your product, or it was not exploited there, you do not have to report it (Commission guidance, paragraph 218). For products placed on the market from 11 December 2027, you also tell the maker of the component (Article 13(6)).
Can I send the report by email?
Normally no. You file on the platform. If the platform is down and you must act at once, contact your CSIRT directly, then file on the platform when it is back (ENISA FAQ, question 25).
Sources
- Regulation (EU) 2024/2847, the Cyber Resilience Act, official text on EUR-Lex. This note uses Articles 3(42), 13(6), 14(1) to (8), 16(1) and (2), 64(10) and 69(2).
- European Commission, guidance on the application of the CRA, C(2026) 5252, 27 July 2026, paragraphs 213 to 220.
- ENISA, the CRA Single Reporting Platform is launched, 11 September 2026.
- ENISA, Single Reporting Platform FAQ, updated 3 October 2026.
- ENISA, Single Reporting Platform glossary, version 1.4, 1 October 2026.
- ENISA, list of CSIRTs designated as coordinators, updated 10 September 2026.