Skip to content
EU Cyber Resilience Act Reporting Deadlines Now in Effect

EU Cyber Resilience Act Reporting Deadlines Now in Effect

First seen 15 Sep 2026, 08:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 08:51 UTC
  • Manufacturers must report cybersecurity incidents within 24 hours under the CRA.
  • The Single Reporting Platform launched by ENISA streamlines incident reporting.
  • Non-compliance with reporting obligations can lead to significant financial penalties.

As of September 11, 2026, the EU Cyber Resilience Act (CRA) mandates that manufacturers of products with digital elements (PDEs) report actively exploited vulnerabilities and severe incidents within strict deadlines. An early warning must be submitted within 24 hours of awareness, followed by a fuller notification within 72 hours, and a final report within 14 days or one month, depending on the incident type. The Single Reporting Platform (SRP) developed by ENISA facilitates this reporting process, allowing manufacturers to submit notifications electronically to designated Computer Security Incident Response Teams (CSIRTs). This platform is crucial for ensuring timely communication of cybersecurity incidents across the EU market. Non-EU manufacturers are also subject to these obligations if their products are available in the EU. Failure to comply can result in penalties of up to EUR 15 million or 2.5% of global annual turnover. The CRA's implementation is part of broader EU efforts to enhance cybersecurity resilience.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
CRA reporting obligations begin
Manufacturers of PDEs must comply with new reporting deadlines for cybersecurity incidents and vulnerabilities.
Mcdermottlaw
2026-09-11
Single Reporting Platform launched
ENISA activated the SRP to facilitate reporting of cybersecurity incidents for manufacturers in the EU.
Helpnetsecurity

More articles in this cluster (2)

Following this threat?

Track IDScan in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed