ConfirmedEU-wideCyber Resilience Act

CRA: mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA/CSIRT

4 days from today

What changes

Manufacturers of products with digital elements (hardware and software, including SaaS-connected devices and standalone apps) must report actively exploited vulnerabilities and severe security incidents through ENISA's single reporting platform: early warning within 24 hours, full notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents). It applies to products already on the market.

Who is affected

Any manufacturer that sells software or connected hardware in the EU, including small software vendors and open-source projects run commercially. Non-commercial open source is largely exempt.

Sizes: micro, small, medium, large · Sectors: Software / SaaS, Hardware / electronics, Manufacturing · Applies if: We make connected hardware / devices; We sell online

What to do

Set up an internal process to detect and triage exploited vulnerabilities and incidents in your products. Register on the ENISA single reporting platform and identify your national CSIRT. Draft report templates and an on-call rota so you can meet the 24h/72h clocks. Inform affected users of fixes.

Penalty

Up to €15M or 2.5% of worldwide turnover

Sources

Last verified 7 September 2026. Informational only, not legal advice.

More Cyber Resilience Act deadlines