
The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements: hardware and software placed on the EU market. Most obligations apply from 11 December 2027, but one part starts earlier: from 11 September 2026, manufacturers must report certain vulnerabilities and incidents.
What must be reported
Manufacturers report:
- actively exploited vulnerabilities in their products, and
- severe incidents having an impact on the security of their products.
Reports go through the single reporting platform run by ENISA, to the CSIRT designated as coordinator and to ENISA.
The deadlines
For an actively exploited vulnerability, the manufacturer sends:
- an early warning within 24 hours of becoming aware of it;
- a vulnerability notification within 72 hours, with more details and the measures taken or recommended;
- a final report within 14 days after a corrective or mitigating measure is available.
Severe incidents follow a similar pattern: an early warning within 24 hours, a notification within 72 hours and a final report within one month.
The clock starts when you become aware, which is why knowing your products and their components matters before anything happens.
How to prepare now
- List your products with digital elements, their versions and who is responsible for each.
- Know their components. A software bill of materials (SBOM) shows which libraries and parts each product contains, so you can tell quickly whether a new vulnerability affects you.
- Set up vulnerability handling. A way to receive reports, rate them, fix them and track due dates.
- Decide the support period. Under the CRA, you provide security updates for the expected time of use, normally at least five years.
- Rehearse reporting. Decide who files reports, who approves them and how you reach ENISA's platform.
Does it apply to software as a service?
Pure software as a service is generally outside the CRA, unless it is remote data processing a product needs in order to work. Products you sell, ship or let customers install are in scope. Check the definitions in the regulation for your case.
CloudSignLab keeps your products, versions, support periods and SBOM files, tracks vulnerabilities, and shows the 24-hour and 72-hour deadlines when a vulnerability is actively exploited. See the Cyber Resilience Act page.
Start free

