Skip to main content

← All articles

CRA reporting obligations in force since 11 September

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities. Deadlines, reporting route and to-dos for mid-sized firms, sourced from the EU Commission and BSI.

Sebastian LangSebastian LangOctober 6, 20269 min read
CRA reporting obligations in force since 11 September

The Cyber Resilience Act reporting obligations have applied since 11 September 2026: manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The Federal Office for Information Security (BSI) announced the start on the same day in a press release, and the EU Commission updated its page on reporting obligations the same day.

If you make software or connected devices, you now need a reporting route that works within hours. This post summarises what the authorities have published and keeps our own recommendations clearly separate. Our post on prompt injection and protecting AI agents explains what attacks that can trigger such reports look like.

As of 6 October 2026

TL;DR

  • Since 11 September 2026, according to the EU Commission, manufacturers must report actively exploited vulnerabilities and severe incidents: an early warning notification within 24 hours, a notification within 72 hours, then a final report.
  • You report once, through the ENISA single reporting platform. The recipients are the designated CSIRT (in Germany, CERT-Bund at the BSI) and ENISA.
  • According to the BSI, the main obligations apply from 11 December 2027. Responsibility, contact and the internal reporting chain must work now for the reporting obligations that already apply.

What has applied since 11 September

The reporting obligations of the Cyber Resilience Act (CRA), EU Regulation 2024/2847, have applied since 11 September 2026. According to the EU Commission, manufacturers have been required since that day to report actively exploited vulnerabilities and severe incidents that affect the security of products with digital elements. The BSI describes it the same way in its press release.

The reporting obligations for manufacturers have applied since 11 September 2026; the main obligations follow on 11 December 2027. According to the BSI, the CRA is being implemented in stages up to 2027. On its CRA overview, the Commission gives 11 September 2026 as the date for the reporting obligations and 11 December 2027 for the main obligations.

Who is affected

Manufacturers of products with digital elements are affected. On its CRA page, the BSI explains that this covers not only connected hardware but also pure software products; its examples are accounting software, computer games and mobile apps. According to the BSI, B2B software and complex industrial systems are expressly included. Non-commercial open-source software is exempt from the CRA.

So the answer to whether the CRA also applies to pure software is: yes, to software as a product. According to the BSI, the CRA also applies to manufacturers outside the EU if they place products on the EU market. According to the BSI, distributors and importers must ensure compliance with the rules. These pages do not specify in detail which distributor or importer submits the report in an individual case. According to the Commission and the BSI, the reporting obligation itself is addressed to the manufacturer.

Whether software developed in-house and used only internally falls under it is not answered by those pages. That is a question for legal counsel; for details, the Commission refers to its CRA guidelines and FAQ.

Template

AI policy with an agent annex

Request the template

What must be reported and within which deadlines

Two things must be reported: actively exploited vulnerabilities and severe incidents that affect the security of a product with digital elements. As examples of severe incidents, the BSI names the possibility of manipulating program code and a compromised update mechanism. According to the Commission, the 24- and 72-hour deadlines start as soon as the manufacturer becomes aware of the issue.

The Commission describes three stages:

  1. Early warning notification within 24 hours after the manufacturer becomes aware. This answers the question of what must be reported within 24 hours: the first notification that an actively exploited vulnerability or a severe incident exists.
  2. Full notification within 72 hours. The BSI says that further information must be added where available.
  3. Final report. For vulnerabilities, no later than 14 days after a corrective measure is available. For security incidents, within one month: the Commission counts from the 72-hour notification, the BSI on its CRA page from the first notification. For planning, it is worth assuming the earlier point in time and, in case of doubt, asking the BSI.

The BSI describes this timing as „21 Monate nach Inkrafttreten der Verordnung“ (unofficial translation: "21 months after the regulation entered into force"), that is, from 11 September 2026. The pages we read do not state any fine amounts for infringements, so we do not go into them here.

How reporting works

Manufacturers report only once and only through the platform, says the Commission: ENISA operates the CRA single reporting platform (SRP), which has been in operation since 11 September 2026, and manufacturers must submit their notifications through it. The ENISA page on the Single Reporting Platform links to the portal as well as an FAQ, user manual, glossary and a tutorial video.

This is how the Commission and the BSI describe the path of a notification:

  • The notification goes to the coordinating CSIRT of the country in which the manufacturer has its main establishment. In Germany that is CERT-Bund at the BSI.
  • Unless there are particularly exceptional circumstances, the information is made available to ENISA at the same time.
  • As a rule, the CSIRT that receives the notification first passes it on without delay to other competent CSIRTs; under exceptional circumstances the forwarding can be delayed. According to the BSI, one notification thus reaches several countries.
  • According to the BSI, prior registration is not required; registration and reporting are possible within a few minutes if needed. The ENISA guides additionally describe registering "Assigned Representatives" of the manufacturer. Consult the ENISA guide for the detailed procedure before the first real incident.
  • For manufacturers without a main establishment in the EU, responsibility follows the criteria in Article 14(7) CRA, for example the location of an authorised representative, importer or distributor, or the availability of the product (BSI).

The ENISA platform is the answer to the question "What is the ENISA Single Reporting Platform?": the central, confidential reporting route of the CRA for manufacturers, operated by the EU cybersecurity agency.

What is still to come by December 2027

The reporting obligations have applied since 11 September 2026; the main obligations follow. According to the BSI, all CRA requirements apply on 11 December 2027, including the essential cybersecurity requirements before a product is placed on the market, vulnerability handling across the whole lifecycle, and transparency towards users. According to the BSI, the procedure includes a risk assessment, a declaration of conformity, a software bill of materials (SBOM, which does not have to be published) and a support period communicated by the manufacturer, which is usually five years.

The BSI names two further dates: by 11 December 2026, member states are to ensure that enough notified bodies are available for conformity assessments. For open-source software stewards, the reporting obligations apply only from 11 December 2027, according to the Commission.

According to the BSI, most products are standard products that the manufacturer assesses itself. "Important" and "critical" products in Annexes III and IV, such as password managers, firewalls or smart cards, are subject to stricter procedures.

What mid-sized manufacturers should prepare now

This section is our recommendation and not a requirement from the CRA. We derived it from the obligations described above, especially the 24-hour deadline: a deadline that starts when you find out can only be met if someone knows they are responsible.

  1. Take an inventory of your products. A list of all products with digital elements that you make available on the EU market: software, apps, connected devices, also components you deliver to customers. Without this list you cannot say what the reporting obligation applies to.
  2. Clarify responsibility and cover. One person who triggers notifications and one deputy, including at weekends. Get familiar with the platform before it gets serious (see the ENISA guides).
  3. Determine the competent CSIRT. With a main establishment in Germany, it is CERT-Bund according to the BSI. For manufacturers outside the EU, the criteria from Article 14(7) CRA apply.
  4. Define intake channels. As sources of awareness, the BSI names for example IT security service providers, customers, external tips and the analysis of log data. Each of these channels needs a fixed address in the company where the information reaches the responsible person.
  5. Set the internal reporting chain. Who checks whether a vulnerability is being actively exploited, who decides on the notification, who submits it, who informs management and customers. For AI incidents, our free AI policy template contains a section on reporting incidents that you can use as a starting point for the internal chain. It does not replace CRA reporting processes.
  6. Rehearse the real thing once. An exercise with a made-up incident shows whether the 24 hours are realistic. Missing credentials can delay the notification, so check access during the exercise.

AI agents in the product or in development add new attack paths. How to prepare for them is described in our post on GDPR and agentic AI in production.

FAQ

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is an EU regulation on the cybersecurity of products with digital elements. According to the Commission, it sets binding requirements for manufacturers, from planning and development through to maintenance. As a regulation, it applies directly in all member states according to the BSI; no national implementation is needed.

When do the CRA reporting obligations apply?

Since 11 September 2026. The EU Commission gives this date on its page on reporting obligations, and the BSI announced the start on the same day. According to the BSI, the main obligations apply from 11 December 2027.

Who has to report under the CRA?

Manufacturers of products with digital elements that are made available on the EU market, even if they are based outside the EU. According to the Commission, open-source software stewards are subject to the reporting obligations only from 11 December 2027.

What must be reported within 24 hours?

The early warning notification, as soon as the manufacturer learns of an actively exploited vulnerability or a severe security incident affecting its product. The full notification follows within 72 hours, then the final report. The 24- and 72-hour deadlines start with awareness. For final reports, the different starting points described above apply.

Does the CRA also apply to pure software?

Yes. The BSI expressly names pure software products such as accounting software, computer games and mobile apps, as well as B2B software. Non-commercial open-source software is exempt. Whether a specific product falls under the rules should be checked case by case.

What is the ENISA Single Reporting Platform?

The Single Reporting Platform (SRP) is ENISA's online tool through which manufacturers submit their CRA notifications. It has been in operation since 11 September 2026. A notification goes to the competent CSIRT. As a rule, ENISA also receives the information; the first CSIRT informs other competent CSIRTs. Exceptions apply for exceptional circumstances.

Sources

Template

AI policy with an agent annex

An editable Word template for approvals, data classes, roles, AI literacy and AI agents. Free by email.

Sebastian Lang

About the author

Sebastian Lang

Co-Founder · Business & Content Lead

Co-Founder of Sentient Dynamics. 15+ years of business strategy (incl. SAP), MBA. Writes about EU AI Act compliance, ROI measurement and how Mittelstand CTOs actually adopt agentic AI.

Keep reading

Once a month. Only substance.

No motivational fluff. No tool lists. Only what CTOs, COOs and MDs in DACH really need to know about AI adoption.