The 24h and 72h reports: how the obligation arriving on 11 September works
From 11 September 2026, a manufacturer who learns of an actively exploited vulnerability in its product has 24 hours for the first alert. What gets reported, to whom, through where, and what to prepare beforehand.
- Published
Article 14 of the Cyber Resilience Act is the first major obligation of the regulation to enter into application: on 11 September 2026, fifteen months before full application. From that date, a manufacturer of products with digital elements that becomes aware of an actively exploited vulnerability, or of a severe incident having an impact on the security of the product, enters a timeline measured in hours.
What triggers the obligation
This is the most widely misunderstood point. Article 14 does not cover every vulnerability. It covers two things:
- Actively exploited vulnerabilities: a flaw in the product that is being used in an attack (Art. 3(42));
- Severe incidents having an impact on the security of the product: compromise of availability, authenticity, integrity or confidentiality, with severity criteria in Art. 14(5).
A vulnerability the team discovers and fixes before it is exploited follows the normal vulnerability handling process. It opens no 24-hour clock.
The clock starts the moment the manufacturer becomes aware. The Commission’s guidance clarifies what that means: awareness exists when, after assessing the suspicious event, the manufacturer can conclude with reasonable certainty that there is active exploitation or a severe incident. The deadline runs from the outcome of that triage, which makes triage a formal process, with an owner, rather than a corridor conversation.
The three deadlines
- 24 hours, early warning. Deliberately lean: an actively exploited vulnerability or a severe incident exists, which product is affected, and in which Member States the manufacturer knows the product has been made available.
- 72 hours, notification. General information about the product, the nature of the exploit and of the vulnerability, corrective or mitigating measures already taken and those users can take.
- Final report. For vulnerabilities: within 14 days of a corrective measure becoming available. For severe incidents: within one month of the 72-hour notification. It includes a description, severity and impact, information about the malicious actor where available, and details of the fix.
To whom and through where
You report once, through the Single Reporting Platform (SRP) that ENISA is required to have operational on 11 September 2026. The notification goes in through the endpoint of the coordinating CSIRT of the Member State of the manufacturer’s main establishment (in Portugal, CERT.PT, at the National Cybersecurity Centre) and is simultaneously accessible to ENISA. That CSIRT then disseminates the notification to the CSIRTs of the other Member States where the product is available, and feeds the market surveillance authorities.
In exceptional circumstances, for instance a coordinated disclosure in progress, dissemination can be delayed on cybersecurity grounds, under Delegated Regulation (EU) 2026/881.
A detail with consequences: the “main establishment” is the Member State where decisions about the cybersecurity of the products are predominantly taken. Manufacturers with no establishment in the EU follow a cascade: first the authorised representative, then the importer, then the distributor and, finally, the Member State with the most users. It pays to settle it before an incident, not during one.
The elephant in the room: the platform
As we write, the SRP is not publicly operational, and the obligation carries no waiting clause: nothing in the text makes the deadlines conditional on the platform’s availability. The practical conclusion is the one industry has already drawn: the internal process gets built now, independent of the tool, with clear answers about who does triage, who decides “we have become aware”, who drafts, who approves, and with which pre-written templates.
What this means for manufacturers
The 24-hour report is not a communication problem; it is a problem of readiness. Four pieces any manufacturer, of any size, can put in place before September:
- A defined trigger. Monitoring of the sources that turn “known vulnerability” into “actively exploited”: CISA’s KEV catalogue, advisories for the components in the SBOM, and the channel for receiving external reports (the coordinated vulnerability disclosure policy the CRA itself requires).
- An awareness decision with an owner. Who may declare, and by what criterion, that the company “has become aware”. Without this, the clock starts with nobody noticing.
- The three texts written in advance. The 24h early warning fits on half a page; writing it during the incident is the worst possible time. Fill-in templates for the three phases, approved beforehand.
- The rehearsal. One tabletop exercise per half-year, with a realistic scenario, measuring one thing: how much time passes between the signal and an alert ready to submit.
In a micro-enterprise, all of this fits in half a dozen pages and an afternoon of exercise. What does not fit is improvising it at 3 a.m. on a Thursday.
Sources
- Regulation (EU) 2024/2847, Article 14 — https://eur-lex.europa.eu/eli/reg/2024/2847/oj
- European Commission, Cyber Resilience Act — Reporting obligations — https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- ENISA, Single Reporting Platform (SRP) and factsheet — https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
- Delegated Regulation (EU) 2026/881 (conditions for delaying dissemination) — referenced on the Commission page above
- itemis, CRA Article 14: Reporting Obligations for Manufacturers — https://www.itemis.com/en/blog/compliance-intelligence/cyber-resilience-act/cra-article-14-reporting-process/
- cyberresilienceact.eu, CRA Reporting: 24h, 72h & 14-Day Deadlines — https://www.cyberresilienceact.eu/reporting.html
- CISA, Known Exploited Vulnerabilities Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog