EU Enforces Strict 24-Hour Cyber Resilience Act Reporting

Cyber Resilience Act reporting platform interface for vulnerability submission

On September 11, manufacturers of digital products sold in the European Union became obligated to report actively exploited vulnerabilities and severe security incidents to the authorities. They must send an initial warning within 24 hours of discovering the problem, and prepare a more detailed notification within a maximum of 72 hours. One of the most practical components of the Cyber Resilience Act has transitioned from a future requirement into an active mandate.

The Unified Reporting Platform

To facilitate these vital submissions, ENISA announced that the CRA Single Reporting Platform is launched and fully operational. A manufacturer only needs to submit the critical information once. The system seamlessly transmits the notification directly to ENISA and the national CSIRT designated as the primary coordinator. Subsequently, competent authorities in other EU nations where the affected product is sold can readily access the critical data.

This profound obligation does not apply to every discovered flaw. The CRA explicitly defines an actively exploited vulnerability as a weakness possessing reliable evidence of malicious exploitation without the authorization of the system owner. A vulnerability uncovered by a security researcher, a standard bug bounty test, or a routine patch does not inherently trigger the 24-hour countdown.

Deadlines for Severe Security Incidents

Severe incidents are subject to the exact same initial deadline. The manufacturer must dispatch an early warning no more than 24 hours after becoming aware of the incident. Within 72 hours, they must provide all available details regarding the nature of the attack, a preliminary assessment of the consequences, and the defensive measures implemented. The regulation specifically categorizes severe events as those capable of compromising the confidentiality, integrity, authenticity, or availability of vital data and functions, as well as those leading to the injection or execution of malicious code.

The 72-hour mark does not conclude the regulatory procedure. For an actively exploited vulnerability, the manufacturer must submit a final report no later than 14 days after deploying a patch or an alternative defensive measure. In the event of a severe incident, authorities require the final report within one month following the 72-hour notification. This comprehensive document must encompass the ultimate consequences, the root causes of the incident, explicit details regarding the exploitation, and all deployed patches or protective measures.

Market Scope and Punitive Consequences

These stringent new rules apply not only to products launching after the CRA comes into full effect. The European Commission clarifies that the reporting mandates encompass all applicable products featuring digital elements currently available on the EU market. Therefore, developers of active software versions, network equipment, connected devices, and other products governed by the CRA must adhere to this new paradigm immediately.

However, this requirement is not retroactive. If a manufacturer knew before September 11 that a specific vulnerability was facing active exploitation, they are not obligated to report it again solely because the CRA launched. Yet, if evidence of exploitation surfaces after September 11, the reporting mandate firmly applies, even for an archaic and long-documented vulnerability.

The initial 24-hour report functions strictly as an early warning; thus, the regulator does not expect a comprehensive investigation of the attack within a single day. By the 72-hour milestone, the volume of required information increases significantly. ENISA anticipates detailed data concerning the affected product, the precise nature of the exploitation or incident, the scale of the impact, and the available mitigations. At launch, the platform lacks an automated API, forcing entities to submit these mandatory notifications manually through a secure web interface.

Violating Article 14 carries severe punitive consequences. The CRA permits staggering administrative fines reaching up to 15 million euros or up to 2.5% of the company’s total worldwide annual turnover for the preceding financial year, whichever figure is higher. The regulation provides a specific exemption for micro and small enterprises regarding financial penalties for missing the initial 24-hour deadline.

The Future of the Cyber Resilience Act

Meanwhile, the entire Cyber Resilience Act has not yet reached full operational capacity. The foundational requirements concerning the design, development, updates, and lifecycle management of digital products will become absolutely mandatory on December 11, 2027. On that exact date, the Article 14 mandates will also extend to the stewards of open-source projects designated by the CRA. For commercial manufacturers, however, the grace period has vanished. As of September 11, 2026, the 24-hour and 72-hour countdowns trigger the very moment a company becomes aware of an actively exploited vulnerability or a critical security incident.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply