The mandatory vulnerability and security incident reporting obligations under the EU Cyber Resilience Act (CRA) are entering their final countdown phase before official implementation. According to the latest official arrangement of the European Commission, starting from September 11, 2026, manufacturers of all products with digital elements placed on the EU market must fulfill their statutory reporting obligations. This requirement takes effect 15 months earlier than the full application of the CRA (December 11, 2027), and covers all products already on the market — meaning even products launched in the EU years ago must comply with the new rules.
https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
In addition, open-source software stewards have limited reporting obligations. Manufacturers located outside the EU shall submit notifications through their authorized representatives, importers or distributors in the EU.
There is no grandfather clause for reporting obligations: all products with digital elements (including hardware, software, embedded systems, remote data processing solutions, etc.) in circulation on the EU market are subject to the reporting requirements, regardless of whether they were launched before the full entry into force of the CRA.
(一)Actively Exploited Vulnerabilities
Not every vulnerability triggers mandatory reporting. It only applies when there is reliable evidence that a malicious actor has exploited the vulnerability in a system without the permission of the system owner.For ordinary vulnerabilities that are not actively exploited, enterprises only need to remediate them and update security documentation as required, without triggering statutory CRA reporting.
Severe security incidents refer to incidents that negatively affect the availability, authenticity, integrity and confidentiality of products, and reach the "severe" level, mainly including two categories:
In addition to mandatory reporting, enterprises may also voluntarily report ordinary vulnerabilities, cyber threats, near-miss security incidents and other information through the official platform.
| Reporting Stage | Timeline for Actively Exploited Vulnerabilities | Timeline for Severe Incidents | Core Requirements |
|---|---|---|---|
| Early Warning Notification | Within 24 hours of awareness | Within 24 hours of awareness | Initial notification of the incident, indicating the Member States where the product is available |
| Full Notification | Within 72 hours of awareness | Within 72 hours of awareness | Submission of product information, overview of the incident/vulnerability, mitigation measures taken, and countermeasures available to users |
| Final Report | Within 14 days after corrective measures are released | Within one month after the full notification | Submission of complete technical details, impact assessment, details of remediation measures, and information about the attacker (if available) |
It is recommended that enterprises fully retain information and decision records at each time node as compliance evidence.
ENISA has successively released operation guidelines for the SRP, covering user registration, notification submission, and interface functions. Enterprises may follow the official updates in advance.
In addition to reporting to the authorities, enterprises must also promptly inform affected users of the details of vulnerabilities or incidents, as well as risk mitigation measures that users can take.
The CRA does not set a fixed time limit for user notification. However, if an enterprise fails to fulfill the notification obligation in a timely manner, the competent CSIRT has the right to directly disclose relevant information to users.
Exemption Rules: Micro and small enterprises are not subject to administrative fines for failing to meet the 24-hour early warning deadline; violations by open-source software stewards are also not subject to fines.
Follow official updates:Pay attention to the SRP registration, testing and training arrangements released by ENISA, and complete account preparation and process drills in advance.