Overview
- The EU turned on the CRA rapid reporting regime on Sept. 11, 2026, requiring manufacturers to submit a first warning within 24 hours after they become aware of an actively exploited vulnerability or a severe security incident.
- The law sets a staged filing schedule with a fuller notification due within 72 hours, a vulnerability final report within 14 days of a fix being available, and a severe‑incident final report one month after the 72‑hour filing.
- All reports must be filed once through ENISA’s Single Reporting Platform, which forwards notifications to the designated national CSIRT coordinator and makes information available to ENISA and other national teams, while manufacturers must also notify affected users.
- The CRA covers hardware and software ‘products with digital elements,’ can apply to commercially supplied open‑source products and some crypto wallets, and reaches products already on the EU market through Dec. 11, 2027, including offerings from non‑EU companies.
- Security experts say the 24‑hour clock will push firms to automate SBOMs, asset inventories, exploit detection and reporting workflows, create demand for new compliance tools and services, and raise enforcement stakes through fines or market actions if organisations fail to comply.