The EU Cyber Resilience Act (CRA) introduces binding rules for managing product vulnerabilities. Reporting obligations take effect on 11 September 2026, ahead of the December 2027 full application date.
These reporting duties apply to products already placed on the EU market. Article 69(3) makes Article 14 mandatory for the existing installed base.
Three Input Streams for Vulnerabilities
Vulnerabilities reach manufacturers through three primary channels:
Field reports. Security researchers, customers, and external observers report vulnerabilities discovered in deployed products. Receiving reports requires a public Coordinated Vulnerability Disclosure (CVD) policy under Annex I Part II(5).
Supplier notifications. Component vendors notify manufacturers when vulnerabilities affect integrated software or hardware modules. These notifications feed into internal patch workflows.
Proactive security discovery. Manufacturers identify flaws internally through regular security testing, code analysis, and threat reviews before external discovery.
The Three-Tier Obligation Framework
The CRA establishes three distinct compliance tiers:
Tier 1: Assess all vulnerabilities. Manufacturers must evaluate every potential vulnerability relevant to their products without setting an arbitrary threshold.
Tier 2: Resolve known exploitable vulnerabilities before market release. Manufacturers must fix known exploitable flaws before placing products on the market. If a vulnerability is not exploitable in the product context, the manufacturer must record a documented technical justification.
Tier 3: Report actively exploited vulnerabilities immediately. When an attacker exploits a vulnerability in the field, Article 14(1) requires immediate notification to ENISA and the designated coordinating CSIRT.
The Role of the EU Vulnerability Database
The EU Vulnerability Database (EUVD) is operated by ENISA under NIS2 Article 12(2). While useful for threat intelligence, it is not an exhaustive record of all known vulnerabilities.
Manufacturers cannot rely solely on the EUVD. Robust monitoring requires tracking CVE records, NVD data, upstream supplier advisories, and component SBOM feeds.
Mandatory Reporting Timelines
When an actively exploited vulnerability occurs, manufacturers must meet strict statutory windows:
- Within 24 hours: Submit an early warning indicating where the product is available.
- Within 72 hours: Submit a technical notification with vulnerability details, exploit characteristics, and user mitigations.
- Within 14 days of a fix: Submit a final report detailing severity, root causes, attacker data, and corrective measures.
Severe incidents follow a similar 24-hour and 72-hour alert pattern, followed by a final report within one month of the 72-hour notification.
Reports flow through the Single Reporting Platform operated by ENISA. Submissions route simultaneously to the national coordinator CSIRT and ENISA.
Exploitable vs. Actively Exploited
The legal difference between these terms determines reporting obligations.
An exploitable vulnerability is a security flaw that an attacker could theoretically leverage. These flaws fall under Tier 2 and must be remediated or justified before market release.
An actively exploited vulnerability has reliable evidence of malicious execution against deployed systems. This event triggers the Tier 3 mandatory 24-hour reporting clock.
Conclusion
The 11 September 2026 deadline requires working vulnerability handling processes. Establishing clear CVD policies, supplier tracking, and CSIRT reporting workflows ensures compliance before mandatory reporting begins.
The CRA’s vulnerability handling framework rewards manufacturers who treat security as a continuous operational discipline rather than a pre-release checklist. The regulatory exposure for those who do not is now both concrete and time-bound.