EU CRA: reporting obligations from 11 September 2026
Manufacturers selling into the EU must now report actively exploited vulnerabilities and severe incidents within 24 hours. Here is what applies, and the inventory you need to meet it.
- From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents.
- 24-hour early warning, 72-hour notification, then a final report.
- Reports go through ENISA’s Single Reporting Platform.
- SBOM obligations under Annex I apply from 11 December 2027.
What changed on 11 September 2026
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies in stages [3]. Its reporting obligations for manufacturers of products with digital elements apply from 11 September 2026 [1]. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products [1][4]. This applies to products already on the EU market, not only new ones.
Reporting timelines
| Step | Deadline |
|---|---|
| Early warning | Within 24 hours of becoming aware |
| Vulnerability or incident notification | Within 72 hours |
| Final report, actively exploited vulnerability | No later than 14 days after a corrective or mitigating measure is available |
| Final report, severe incident | Within one month of the 72-hour notification |
Source: European Commission [1].
Where reports go
Reports are submitted through ENISA’s CRA Single Reporting Platform (SRP) [2]. Notifications reach the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment and are shared with ENISA [1]. Open-source software stewards have reporting obligations from 11 December 2027 [1].
What comes next: 11 December 2027
The CRA’s main obligations, including the essential cybersecurity requirements in Annex I, apply from 11 December 2027 [3]. Among the vulnerability-handling requirements, manufacturers must identify and document the components in their products, including by drawing up a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies [3].
Why the 24-hour clock is an inventory problem
To send an early warning within 24 hours, a manufacturer must be able to answer quickly:
- Which of our products and versions contain the affected component?
- Is the vulnerability exploitable in those products (VEX status)?
- Which of them are on the EU market, and in which member states?
- Who owns the fix, and when will a mitigation be available?
Without current SBOMs linked to products, releases and markets, the first day is spent searching.
A readiness checklist
- SBOMs for every product and supported release, kept current.
- Continuous monitoring for known-exploited vulnerabilities against those SBOMs.
- A documented triage and VEX process with named decision-makers.
- A reporting workflow with templates for the 24h, 72h and final reports, and access to the SRP.
- A product-to-market register showing where each product is sold.
- Evidence retention for every decision and submission.
How IntelliXBOM helps
IntelliXBOM maintains product and release SBOMs, correlates them with newly exploited vulnerabilities, records VEX decisions and owners, and provides the timestamped evidence trail behind each report. The submission itself is made through ENISA’s platform.
This article summarises public information for general guidance and is not legal advice.
Frequently asked questions
When do CRA reporting obligations apply?
Manufacturers' obligations to report actively exploited vulnerabilities and severe incidents apply from 11 September 2026. The CRA's main obligations, including the Annex I essential requirements, apply from 11 December 2027.
What are the CRA reporting deadlines?
An early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within 14 days of a corrective measure being available for exploited vulnerabilities, or within one month for severe incidents.
Does the CRA require an SBOM?
Yes. From 11 December 2027, Annex I requires manufacturers to identify and document components, including by drawing up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies.
Sources
- Cyber Resilience Act, Reporting obligationsEuropean Commissiondigital-strategy.ec.europa.eu/en/policies/cra-reporting
- Single Reporting Platform (SRP)ENISAwww.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
- Regulation (EU) 2024/2847, Cyber Resilience ActEUR-Lexeur-lex.europa.eu/eli/reg/2024/2847/oj
- EU Cyber Resilience Act: Vulnerability and incident reporting obligations now applyHogan Lovellswww.hlc.com/en/publications/eu-cyber-resilience-act-vulnerability-and-incident-reporting-obligations-now-apply
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.