Skip to content

The EU Cyber Resilience Act's Incident and Vulnerability Reporting Requirements

Debevoisedatablog • September 22, 2026

The EU’s Cyber Resilience Act (“CRA”) imposes end-to-end, product-level cybersecurity standards, risk management, and oversight obligations on those involved in the manufacture and supply of products with digital elements. It applies broadly to cover essentially all connected software and hardware products, from IoT devices and industrial control systems, to smart cards.

While fully applicable from 11 December 2027, mandatory reporting obligations for “actively exploited vulnerabilities” and “severe incidents” came into force on 11 September 2026, with 24 hour initial reporting deadlines. Those who manufacture CRA-covered products should consider taking steps to address these new requirements in their existing incident response and vulnerability management processes.

What products are covered?

The reporting obligations apply to all CRA-covered products, including those first placed on the market before 11 December 2027. Manufacturers are not, however, required to retrospectively report an AEV or Severe Incident if they were already aware of it before 11 September 2026.

This differs from the majority of CRA obligations which will apply only to covered products placed on the market after substantive obligations come into force on 11 December 2027.

What are the regulatory reporting triggers?

The CRA requires manufacturers to report to the relevant authorities:

Actively Exploited Vulnerabilities (“AEV”): Vulnerabilities in CRA-covered products where there is reliable evidence that they have been exploited by a malicious actor; and

Severe Incidents: Incidents having a severe impact on the security of a CRA-covered product. This includes incidents that negatively affect the product’s availability, authenticity, integrity or confidentiality.

What is the reporting timeline?

Manufacturers’ reporting obligations are triggered when they become aware of an AEV or Severe Incident and they have must report in stages:

an early warning notification within 24 hours;

a more detailed intermediate report within 72 hours; and

a final report no later than 14 days after a corrective or mitigating measure is available for an AEV, or within one month from the 72-hour notification for Severe Incidents.

To whom do you report and how?

Manufacturers must submit notifications to the Computer Security Incident Response Team (“CSIRT”) of the Member State in which they have their main establishment.

Once submitted, the notification is simultaneously made available to the European Union Agency for Cybersecurity (“ENISA”). The CSIRT disseminates the information without delay to other relevant CSIRTs in Member States where the product is also available. CSIRTs may also information with their respective market surveillance authorities (i.e., the Member State-level regulators responsible for enforcing CRA compliance).

Notifications are made via ENISA’s Single Reporting Platform (“SRP”). Overtime, the SRP hopes to become a one-stop-shop for EU cyber reporting, adopting a one-to-many reporting model that will allow a single report to reach multiple regulators.

Further details on the SRP and how it operates can be found here and here .

Do users have to be informed?

In addition to regulator notification obligations, manufacturers must also inform “impacted users” of AEVs and Severe Incidents in a “timely manner”, including, where necessary, details of risk mitigation and corrective measures that they can take to mitigate the impact. If manufacturers fail to notify users appropriately, the competent CSIRT may do so.

What should businesses do to prepare?

Manufacturers of CRA-covered products may wish to, in particular:

Revisit and review their existing cyber incident and vulnerability response procedures to ensure they allow the business to identify and respond promptly to product-level incident and vulnerabilities and meet the initial 24 hour reporting timeline;

Establish clear responsibility for, and oversight of, the reporting process. This will allow the relevant personnel to be registered for and able to access the SRP before an AEV or Sever Incident occurs; and

Exercise those new reporting procedures through a tabletop exercise simulation, to ensure internal alignment on how they work in practice and not just in theory.

The cover art used in this blog post was generated by ChatGPT

Extracted Entities

Domains (1)