Most product teams still talk about the Cyber Resilience Act as a 2027 problem. Part of it is. But the reporting obligations went live on 11 September 2026, and they already apply to products you have on the market today.
What has to be reported
Two things trigger a report under Article 14:
Actively exploited vulnerabilities, meaning flaws being used in real attacks
Severe incidents that significantly affect the security of a product with digital elements
Ordinary bugs and routine patches do not. A vulnerability you find and fix before anyone exploits it does not trigger reporting.
The clock
Deadline | What is due |
|---|---|
24 hours | Early warning that an actively exploited vulnerability or severe incident has occurred |
72 hours | Fuller notification with an initial assessment, severity, impact and available corrective measures |
14 days | Final report once a corrective measure is available, for exploited vulnerabilities |
All deadlines run from the moment you become aware. Reports go to ENISA and to the CSIRT designated as coordinator in the relevant member state, through ENISA's Single Reporting Platform, rather than as separate filings.

One exploited component in the field starts a 24-hour clock for the manufacturer.
In plain language
If someone is exploiting a flaw in a product you sell in the EU, you have 24 hours from when you knew to tell ENISA and the national CSIRT. This applies now, to products already on sale.
What it takes to meet 24 hours
Twenty-four hours is short for a manufacturer. It assumes you can do four things quickly:
Know what is in each product. A software bill of materials per SKU and version, so a component advisory maps to the products affected.
Hear about exploitation. Monitoring of KEV, vendor advisories and your own telemetry, routed to someone who can decide.
Decide fast. A named owner and a definition of "actively exploited" agreed in advance.
File cleanly. Access to the platform and a template ready before the first real event.
The rest of the timeline
Notified body provisions applied from 11 June 2026. Full application, including CE marking against the essential cybersecurity requirements, lands on 11 December 2027. Fines for breaching the essential requirements reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
Next step. Our CRA briefing pack covers scope, the four risk tiers, the reporting clock and the dates that have already slipped. Get the briefing pack →
For any comments or information please reach out to info@astragar.com







