CRA Compliance

CRA incident and vulnerability reporting: obligations, timelines, and SME readiness

By CVD Portal
10 min read

Vulnerability reporting and incident reporting are separate obligations under the Cyber Resilience Act. Article 14 establishes two distinct reporting tracks with different triggers and statutory timelines.

Understanding this distinction is essential for building compliant internal escalation processes.

Reporting Obligation Effective Dates

Article 14 vulnerability and incident reporting becomes mandatory on 11 September 2026. This deadline applies to all products with digital elements made available on the EU market that remain in their supported lifetime.

Full product conformity, CE marking, and Annex I technical requirements apply from 11 December 2027. However, the reporting mechanism must be operational by September 2026.

The Two Reporting Tracks

1. Actively Exploited Vulnerabilities

A vulnerability triggers Article 14 reporting when evidence confirms active exploitation in the field. The legal trigger is confirmed malicious use, not CVSS score or internal severity.

The mandatory notification cascade follows this timeline:

  • 24 hours: Early warning to the Single Reporting Platform, routing to ENISA and the national coordinator CSIRT.
  • 72 hours: Detailed technical notification covering severity, affected versions, and user mitigations.
  • 14 days after fix availability: Final report detailing root causes, security updates, and threat actor data.

The 24-hour clock begins the moment the manufacturer becomes aware of active exploitation.

2. Severe Incidents

A severe incident involves an event that impacts the security or functionality of a product. The notification timeline requires:

  • 24 hours: Early warning notification.
  • 72 hours: Detailed incident notification.
  • One month after notification: Final report covering root cause analysis and corrective actions.

Products in Scope

Article 14 applies to all manufacturers of products with digital elements sold in the EU. This includes connected consumer hardware, industrial automation controllers, networking equipment, embedded firmware, and standalone security software.

Importers and distributors carry secondary responsibilities if an overseas manufacturer fails to report.

Single Reporting Platform Routing

The CRA establishes the Single Reporting Platform (SRP) operated by ENISA. Manufacturers submit notifications through one portal.

The system automatically routes the report to ENISA and the designated coordinating CSIRT in the manufacturer's home Member State. Manufacturers should register accounts and test credentials well before September 2026.

Essential Internal Processes

To meet statutory deadlines, manufacturers must establish four operational capabilities:

Detection and escalation routes. Teams must aggregate signals from disclosure portals, threat feeds, customer support, and CSIRT advisories. Escalation to decision-makers must occur within hours of initial detection.

Standing triage authority. Designated technical leaders must hold documented authority to file 24-hour early warnings without requiring executive or legal approval.

Pre-formatted notification templates. Teams must maintain pre-drafted templates aligned with SRP data fields to prevent delays during active incidents.

Immutable audit trails. Every report, triage assessment, and authority filing must be logged with verified timestamps for regulatory review.

Summary

Article 14 compliance requires operational readiness before 11 September 2026. Setting up monitored intake, clear triage authority, and tested reporting workflows ensures compliance.

The SME Readiness Gap

Larger organisations with established PSIRTs and threat intelligence programmes already have most of these capabilities in some form. For the majority of SMEs manufacturing hardware or software for the EU market, none of them exist today.

Building compliant detection, escalation, triage, reporting, and disclosure processes from scratch in the months remaining before September 2026 is achievable. It requires deliberate prioritisation and, for most SMEs, tooling that reduces the engineering burden.

CVD Portal provides the intake, triage, reporting, and audit trail infrastructure required for Article 14 compliance as a service. Manufacturers can be operationally ready with a functioning VDP, structured escalation workflow, pre-built report templates aligned to ENISA’s notification format, and full audit trail without building any of it in-house.

A Deeper Look at Each Obligation

This guide is the single-page overview. Each part of the reporting regime is covered in depth in our six-part series:

The Bottom Line

Vulnerability and incident reporting under the CRA are two distinct obligations with overlapping timelines, separate triggers, and different final report deadlines. Both become enforceable on 11 September 2026, on every product with digital elements in the EU market. The internal processes required to meet those timelines must be in place and tested before that date, not planned for after it.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Get Started for Free

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.