What changed today
The Cyber Resilience Act (CRA) is the EU's baseline cybersecurity law for "products with digital elements" - essentially any hardware or software placed on the EU market that can connect to a device or network. September 11, 2026 is the date its early-warning obligations became mandatory: manufacturers must now notify ENISA and their national CSIRT when they become aware of an actively exploited vulnerability or a severe incident affecting one of their products.
The three-stage reporting clock
The obligation isn't a single notification - it's a sequence, and each stage has its own deadline:
Early warning - 24 hours
An initial notification to ENISA and the national CSIRT within 24 hours of becoming aware of active exploitation, even before the root cause or a fix is understood.
Detailed notification - 72 hours
A fuller report including a preliminary assessment of severity and impact, updating the early warning once more is known.
Final report - at resolution
A closing report once the vulnerability is fixed or the incident resolved, describing the corrective action taken.
Same clock, two triggers
The identical 24/72-hour structure applies both to actively exploited vulnerabilities and to severe incidents with a security impact on the product - not just confirmed breaches.
Don't have an incident-response process that can actually hit a 24-hour clock? Talk to us about a CRA readiness review before an exploited CVE forces the question.
"Products with digital elements" is broader than most teams assume
The scope isn't limited to consumer IoT. It covers any hardware or software product placed on the EU market for commercial purposes that has a direct or indirect logical or data connection to a device or network - which sweeps in SaaS components shipped as part of a product, embedded firmware, industrial software, and libraries distributed commercially, not just finished consumer devices. Purely internal tooling that never reaches an EU customer generally falls outside it; almost anything you sell, license, or bundle into something an EU customer runs does not.
Why this matters even before December 2027
Two things make the reporting duty worth treating seriously now, well ahead of the full 2027 deadline. First, ENISA and national CSIRTs are a new reporting channel most engineering teams have never touched - discovering the process during a live exploitation event is the wrong time to learn it. Second, a functioning 24-hour reporting workflow requires the same underlying capability you need for the 2027 secure-by-design obligations anyway: a real vulnerability-handling process, a named point of contact, and monitoring that can actually detect active exploitation instead of finding out from a customer.
| Obligation | Status | Applies to |
|---|---|---|
| 24h/72h/final vulnerability & incident reporting | In force since Sep 11, 2026 | Manufacturers of products with digital elements placed on the EU market |
| Secure-by-design, vulnerability handling, CE marking | Mandatory from Dec 11, 2027 | Same scope, full conformity assessment regime |
| Support period disclosure | Phasing in alongside 2027 obligations | Products with digital elements sold with a defined support lifecycle |
Key takeaways
- Mandatory reporting of actively exploited vulnerabilities and severe incidents under the CRA began September 11, 2026 - a 24-hour early-warning, 72-hour detailed, and final report sequence.
- Scope is "products with digital elements" placed on the EU market - broader than consumer IoT, and it reaches non-EU vendors selling into the EU.
- The heavier secure-by-design, CE marking, and conformity assessment obligations still land December 11, 2027 - this is the early piece, not the whole Act.
- Building the reporting workflow now doubles as groundwork for the 2027 requirements, rather than a separate compliance project later.
Zetrixweb