# Vulnerability reporting under the CRA

The reporting obligations that have applied since 11 September 2026

> Manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours through ENISA's Single Reporting Platform. This page covers what to report, the deadlines and what you need in place.

Published: 5 October 2026  
URL: https://sbom.se/en/cra/vulnerability-reporting

The reporting obligations in the Cyber Resilience Act (CRA) have applied since 11 September 2026, more than a year before the rest of the regulation. They cover every product with digital elements in scope, including products placed on the market before the CRA existed. [Cyber Resilience Act (CRA)](https://sbom.se/en/cra/overview) gives an overview of the regulation.

## What must be reported

Manufacturers report two things (Article 14):

* **Actively exploited vulnerabilities** in their products. A vulnerability is actively exploited when there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner.
* **Severe incidents** that affect the security of the product. An incident is severe when it affects, or could affect, the ability of the product to protect sensitive or important data or functions, or when it has led, or could lead, to malicious code being introduced or executed in the product or in a user's systems.

A vulnerability that is known but not exploited is not reported under Article 14. It is handled under the vulnerability handling requirements in Annex I.

## Deadlines

The clock starts when the manufacturer becomes aware of the vulnerability or the incident.

| Step          | Actively exploited vulnerability                                            | Severe incident                              |
| ------------- | --------------------------------------------------------------------------- | -------------------------------------------- |
| Early warning | Within 24 hours                                                             | Within 24 hours                              |
| Notification  | Within 72 hours                                                             | Within 72 hours                              |
| Final report  | No later than 14 days after a corrective or mitigating measure is available | Within one month of the 72-hour notification |

The 72-hour notification contains general information about the product, the nature of the exploit or incident, and corrective or mitigating measures, both those taken and those users can take. The final report for a vulnerability describes its severity and impact, any information about the malicious actor, and the security update or other measure that fixes it.

## Where to report

Reports are submitted through the Single Reporting Platform (SRP), which ENISA operates. A manufacturer reports once. The notification goes to the CSIRT designated as coordinator in the member state where the manufacturer has its main establishment, and ENISA gets access at the same time.

The main establishment is the member state where decisions about the cybersecurity of the products are mainly taken.

## Informing users

After becoming aware of an actively exploited vulnerability or a severe incident, the manufacturer must also inform the affected users, and where appropriate all users. The information should cover the vulnerability or incident and any measures users can take, where appropriate in a structured, machine-readable format.

## What you need in place

Twenty-four hours is short. Whether the deadline can be met is decided before anything happens.

* **An inventory of what each product contains.** When a vulnerability in a component is being exploited, the first question is which products and versions include it. An [SBOM](https://sbom.se/en/sbom/what-is-sbom) for every supported release answers that. [SBOM requirements in the CRA](https://sbom.se/en/cra/sbom-requirements) describes the requirement.
* **Monitoring against exploitation data.** Lists of known exploited vulnerabilities, such as the CISA KEV catalogue, show which vulnerabilities are being exploited. [What is a vulnerability?](https://sbom.se/en/vulnerabilities/what-is-a-vulnerability) describes the sources.
* **A way in for reports.** The CRA requires a contact address for vulnerability reports and a policy on coordinated vulnerability disclosure. Someone has to read what arrives.
* **A named owner and a decision path.** Who decides that a vulnerability is actively exploited, who submits the early warning, and who covers weekends and holidays.
* **Access to the platform.** Register for the Single Reporting Platform before the first report is due.
* **Older products.** The obligation covers products that are already on the market. List them, including those that are no longer sold but still in use.

## Penalties

Failure to meet the obligations in Article 14 can lead to fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Microenterprises and small enterprises are not fined for missing the 24-hour deadline for the early warning.

## Open-source software stewards

According to the European Commission, the reporting obligations for open-source software stewards start on 11 December 2027.

## References

- [European Commission: CRA reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting): The Commission's page on what to report, to whom and when.
- [ENISA: Single Reporting Platform (SRP)](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp): ENISA's page about the platform that manufacturers report through.
- [Regulation (EU) 2024/2847 (Cyber Resilience Act)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng): The reporting obligations are in Article 14. The transitional rule for older products is in Article 69(3).
