Takes Effect on September 11! Mandatory Reporting Under EU CRA: Fines Up to 2.5% of Global Turnover
Views:42
Time:2026-08-26 11:27:11


The mandatory vulnerability and security incident reporting obligations under the EU Cyber Resilience Act (CRA) are entering their final countdown phase before official implementation. According to the latest official arrangement of the European Commission, starting from September 11, 2026, manufacturers of all products with digital elements placed on the EU market must fulfill their statutory reporting obligations. This requirement takes effect 15 months earlier than the full application of the CRA (December 11, 2027), and covers all products already on the market — meaning even products launched in the EU years ago must comply with the new rules.



https://digital-strategy.ec.europa.eu/en/policies/cra-reporting


一、Responsible Entities and Covered Products



(一)Responsible Entities: Beyond Manufacturers
The core bearers of CRA reporting obligations are product manufacturers: any natural or legal person who develops or manufactures products with digital elements, or markets such products under its own name or trademark, whether for payment, monetization or free of charge.The following entities shall also be deemed as manufacturers and bear the same reporting obligations:
  • Importers and distributors that place products on the market under their own name or trademark
  • Entities that carry out substantial modifications to products and make the modified products available on the EU market

In addition, open-source software stewards have limited reporting obligations. Manufacturers located outside the EU shall submit notifications through their authorized representatives, importers or distributors in the EU.


(二)Scope of Application: Covering Both New and Existing Products

There is no grandfather clause for reporting obligations: all products with digital elements (including hardware, software, embedded systems, remote data processing solutions, etc.) in circulation on the EU market are subject to the reporting requirements, regardless of whether they were launched before the full entry into force of the CRA.


二、Two Categories of Mandatory Reporting Scenarios



The CRA establishes two mandatory reporting tracks, and not all security issues require reporting:

(一)Actively Exploited Vulnerabilities

Not every vulnerability triggers mandatory reporting. It only applies when there is reliable evidence that a malicious actor has exploited the vulnerability in a system without the permission of the system owner.For ordinary vulnerabilities that are not actively exploited, enterprises only need to remediate them and update security documentation as required, without triggering statutory CRA reporting.


(二)Severe Security Incidents

Severe security incidents refer to incidents that negatively affect the availability, authenticity, integrity and confidentiality of products, and reach the "severe" level, mainly including two categories:

  • Incidents that impair the product's ability to protect sensitive or important data and functions
  • Incidents that lead to the implantation of malicious code into the product or users' network information systems

In addition to mandatory reporting, enterprises may also voluntarily report ordinary vulnerabilities, cyber threats, near-miss security incidents and other information through the official platform.


三、Reporting Timelines



The CRA adopts a staged reporting mechanism. The timeline starts when the enterprise becomes aware of the incident, and information shall be submitted in three phases:

Reporting StageTimeline for Actively Exploited VulnerabilitiesTimeline for Severe IncidentsCore Requirements
Early Warning NotificationWithin 24 hours of awarenessWithin 24 hours of awarenessInitial notification of the incident, indicating the Member States where the product is available
Full NotificationWithin 72 hours of awarenessWithin 72 hours of awarenessSubmission of product information, overview of the incident/vulnerability, mitigation measures taken, and countermeasures available to users
Final ReportWithin 14 days after corrective measures are releasedWithin one month after the full notificationSubmission of complete technical details, impact assessment, details of remediation measures, and information about the attacker (if available)

Key Reminder: How to Determine the Starting Point of the Timeline
  • The clock does not start after the investigation is fully completed. Once the enterprise reaches "reasonable certainty" that the incident meets the reporting criteria, the timeline has already started.
  • Unverified user feedback, media reports, or clues from security researchers do not directly trigger the reporting obligation, but the enterprise must immediately launch an assessment without delay.
  • It is recommended that enterprises fully retain information and decision records at each time node as compliance evidence.

四、Unified Entry Point: The Single Reporting Platform (SRP)



All CRA notifications shall be submitted through the Single Reporting Platform (SRP), which is developed by the European Union Agency for Cybersecurity (ENISA). The SRP will be officially launched on September 11, 2026, with a testing period before going live.

Notification Flow Rules:
  1. After an enterprise submits a notification through the SRP, the information will be simultaneously sent to the CSIRT (Computer Security Incident Response Team) of the Member State where the enterprise's main establishment is located, and to ENISA.
  2. The CSIRT that initially receives the notification will immediately share it with CSIRTs of all Member States where the product is available.
  3. Under exceptional circumstances, the CSIRT may delay the cross-border dissemination of information on justified cybersecurity grounds.

ENISA has successively released operation guidelines for the SRP, covering user registration, notification submission, and interface functions. Enterprises may follow the official updates in advance.


五、Compliance Pitfalls to Avoid



(一)Do Not Overlook the User Notification Obligation

In addition to reporting to the authorities, enterprises must also promptly inform affected users of the details of vulnerabilities or incidents, as well as risk mitigation measures that users can take.

The CRA does not set a fixed time limit for user notification. However, if an enterprise fails to fulfill the notification obligation in a timely manner, the competent CSIRT has the right to directly disclose relevant information to users.


(二)The SRP Is Not a One-Stop Reporting Portal for All Regulations
The SRP is only the unified reporting channel for the CRA, and cannot replace reporting obligations under other regulations. The same security incident may trigger multiple reporting requirements under the GDPR, NIS 2 Directive, DORA and other regulations. Enterprises need to ensure process alignment for parallel compliance with multiple regulations.

(三)Top-Tier Penalties for Non-Compliance
Violation of CRA reporting obligations falls under the highest penalty tier of the regulation: Administrative fines of up to 15 million euros, or up to 2.5% of the enterprise's total worldwide annual turnover in the preceding financial year, whichever is higher.

Exemption Rules: Micro and small enterprises are not subject to administrative fines for failing to meet the 24-hour early warning deadline; violations by open-source software stewards are also not subject to fines.


六、Enterprise Compliance Preparation Checklist



With less than one month left before September 11, enterprises are advised to prioritize the following preparations:
Conduct a product inventory:Comprehensively take stock of all products with digital elements placed on the EU market, covering new products on sale, products in circulation, and different software and hardware versions.
Clarify responsible entities:Sort out reporting responsibilities under group internal structures, OEM/white-label scenarios, and third-party component scenarios; non-EU enterprises shall confirm the counterpart entity in the EU (authorized representative/importer) in advance.
Establish internal response proceduresConnect the collaboration links among security, product, legal, compliance, customer service and other departments, and establish a 7×24-hour emergency response mechanism to ensure assessment and reporting can be completed within the 24-hour and 72-hour windows.
Prepare reporting templates in advanceIn accordance with the SRP field requirements released by ENISA, pre-produce three-level templates for early warning, full notification and final report, covering both vulnerability and incident scenarios.
Develop user notification plans:Prepare user notification scripts and release processes for different levels, balancing the need for risk disclosure and the security risk of vulnerability proliferation.

Follow official updates:Pay attention to the SRP registration, testing and training arrangements released by ENISA, and complete account preparation and process drills in advance.


七、Conclusion



The CRA is one of the most representative product cybersecurity legislations worldwide. As the core requirement to take effect first, the reporting obligation is not only a compliance red line that enterprises must abide by, but also an important starting point for building a full-lifecycle product security system.For further information, please consult Wiselink!


Contact Us
Fill Form
Whether you need more information or wish to cooperate with us, we will guide you through every step of the regulatory process. Subscribe to our newsletter for the latest global regulatory updates.