PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance3 min readReviewed September 20264 sources

EU CRA: reporting obligations from 11 September 2026

Manufacturers selling into the EU must now report actively exploited vulnerabilities and severe incidents within 24 hours. Here is what applies, and the inventory you need to meet it.

Key takeaways
  • From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents.
  • 24-hour early warning, 72-hour notification, then a final report.
  • Reports go through ENISA’s Single Reporting Platform.
  • SBOM obligations under Annex I apply from 11 December 2027.

What changed on 11 September 2026

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies in stages [3]. Its reporting obligations for manufacturers of products with digital elements apply from 11 September 2026 [1]. From that date, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products [1][4]. This applies to products already on the EU market, not only new ones.

Reporting timelines

StepDeadline
Early warningWithin 24 hours of becoming aware
Vulnerability or incident notificationWithin 72 hours
Final report, actively exploited vulnerabilityNo later than 14 days after a corrective or mitigating measure is available
Final report, severe incidentWithin one month of the 72-hour notification

Source: European Commission [1].

Where reports go

Reports are submitted through ENISA’s CRA Single Reporting Platform (SRP) [2]. Notifications reach the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment and are shared with ENISA [1]. Open-source software stewards have reporting obligations from 11 December 2027 [1].

What comes next: 11 December 2027

The CRA’s main obligations, including the essential cybersecurity requirements in Annex I, apply from 11 December 2027 [3]. Among the vulnerability-handling requirements, manufacturers must identify and document the components in their products, including by drawing up a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies [3].

Why the 24-hour clock is an inventory problem

To send an early warning within 24 hours, a manufacturer must be able to answer quickly:

  1. Which of our products and versions contain the affected component?
  2. Is the vulnerability exploitable in those products (VEX status)?
  3. Which of them are on the EU market, and in which member states?
  4. Who owns the fix, and when will a mitigation be available?

Without current SBOMs linked to products, releases and markets, the first day is spent searching.

A readiness checklist

  • SBOMs for every product and supported release, kept current.
  • Continuous monitoring for known-exploited vulnerabilities against those SBOMs.
  • A documented triage and VEX process with named decision-makers.
  • A reporting workflow with templates for the 24h, 72h and final reports, and access to the SRP.
  • A product-to-market register showing where each product is sold.
  • Evidence retention for every decision and submission.

How IntelliXBOM helps

IntelliXBOM maintains product and release SBOMs, correlates them with newly exploited vulnerabilities, records VEX decisions and owners, and provides the timestamped evidence trail behind each report. The submission itself is made through ENISA’s platform.

This article summarises public information for general guidance and is not legal advice.

Frequently asked questions

When do CRA reporting obligations apply?

Manufacturers' obligations to report actively exploited vulnerabilities and severe incidents apply from 11 September 2026. The CRA's main obligations, including the Annex I essential requirements, apply from 11 December 2027.

What are the CRA reporting deadlines?

An early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within 14 days of a corrective measure being available for exploited vulnerabilities, or within one month for severe incidents.

Does the CRA require an SBOM?

Yes. From 11 December 2027, Annex I requires manufacturers to identify and document components, including by drawing up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies.

Sources

  1. Cyber Resilience Act, Reporting obligationsEuropean Commissiondigital-strategy.ec.europa.eu/en/policies/cra-reporting
  2. Single Reporting Platform (SRP)ENISAwww.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
  3. Regulation (EU) 2024/2847, Cyber Resilience ActEUR-Lexeur-lex.europa.eu/eli/reg/2024/2847/oj
  4. EU Cyber Resilience Act: Vulnerability and incident reporting obligations now applyHogan Lovellswww.hlc.com/en/publications/eu-cyber-resilience-act-vulnerability-and-incident-reporting-obligations-now-apply

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related Programme guides

Across the BOM Suite

See it on your own stack.Programme & regulation with continuous correlation and timestamped evidence.