← CRA FAQReporting and vulnerability handling

When does the CRA reporting clock start?

Also asked

  • Does receiving a vulnerability report start the 24-hour clock?
  • Do I have to report vulnerabilities that were already being exploited before 11 September 2026?
  • Does the reporting obligation stop when the support period ends?
  • Do I report a vulnerability in a third-party component I have integrated?

The clock starts when you become aware, and Commission guidance now defines that moment. On detecting a suspicious event or receiving a report from a researcher, customer or authority, assess it immediately. You become aware once that initial assessment gives you a reasonable degree of certainty that a vulnerability in your product is being actively exploited, or that a severe incident has compromised your product's security. Receiving a report does not by itself start the clock, and neither does a vague suspicion you have not yet examined.

The Commission deliberately aligned this test with the NIS2 implementing regulation and the EDPB breach-notification guidelines, so a manufacturer caught by several regimes can apply one awareness standard rather than three.

At a glance

Trigger
Reasonable degree of certainty after an immediate initial assessment
Early warning
Without undue delay and within 24 hours of becoming aware
Notification
Without undue delay and within 72 hours of becoming aware
Final report, exploited vulnerability
Within 14 days of a corrective or mitigating measure being available
Final report, severe incident
Within one month of the 72-hour notification
Obligation starts
11 September 2026

Last reviewed 27 July 2026

Verified against Regulation (EU) 2024/2847 Articles 14, 15 and 69(3) as published in OJ L, 20.11.2024, and Commission guidance C(2026) 5252 final of 27 July 2026, points 209 to 221.

What counts as becoming aware

Article 14 sets every deadline by reference to the moment the manufacturer becomes aware, but the regulation does not define that moment.[1] Commission guidance C(2026) 5252 fills the gap. Where a manufacturer detects a suspicious event, or a third party such as a researcher, customer, authority or media organisation brings something to its attention, the manufacturer should assess it immediately. Awareness arises when, after that initial assessment, there is a reasonable degree of certainty that a vulnerability contained in the product is being actively exploited, or that a severe incident has occurred and has compromised the security of the product.[4]

The practical consequence is that a short, documented triage window sits before the clock starts. That window is not open-ended. The guidance stresses prompt action to carry out the initial assessment, particularly where the vulnerability may pose a significant risk.

CRA referenceArticle 14(1) and (3)

Why the test matches NIS2 and GDPR

The Commission did not invent a new standard. It aligned the CRA reading with recital 31 of Implementing Regulation (EU) 2024/2690 under NIS2, and with Section II(A) of the EDPB guidelines on personal data breach notification under the GDPR.[4][5] The stated purpose is to let manufacturers subject to comparable obligations under different EU acts apply the concept consistently.

That matters operationally. One event can trigger CRA, NIS2 and GDPR notification duties at once. A single documented awareness determination, recorded with its timestamp and the reasoning behind it, can anchor all three timelines instead of three separate judgements that later turn out to disagree.

CRA referenceArticle 14

What the clock then requires

Once awareness is established, the cadence is fixed. An early warning notification goes to the coordinating CSIRT and ENISA without undue delay and in any event within 24 hours.[1] A fuller notification follows within 72 hours. The complete report is due within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the 72-hour notification for a severe incident.[4]

Manufacturers are expected to update notifications progressively as the investigation advances. The 24-hour filing is an early warning containing limited information, so a thin first submission is the design rather than a failure.

CRA referenceArticle 14(2) and (4)

Three limits worth knowing

First, there is no retroactive reporting. Active exploitation a manufacturer had already become aware of before 11 September 2026 does not have to be reported. Where a vulnerability was known before that date but its exploitation was not, and exploitation occurs or comes to light afterwards, the obligation applies.[4]

Second, a vulnerability in an integrated third-party component is only reportable where it is actively exploited in your product. Where the vulnerable code is unreachable, or exploitation has not occurred in your product, no mandatory report arises, although voluntary notification under Article 15 stays open and upstream reporting under Article 13(6) is still required.[4][2]

Third, the reporting obligations outlive the support period. Vulnerability handling under Annex I Part II stops when support ends, and Article 14 reporting does not.[4]

CRA referenceArticles 14, 15 and 69(3)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 14(1) to (8) · CELEX:32024R2847 · OJ L, 20.11.2024

    an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours

    Accessed 2026-07-27

  2. [2]

    Publications Office of the European Union · Article 13(6) · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-07-27

  3. [3]

    Publications Office of the European Union · Article 15 · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-07-27

  4. [4]

    European Commission · C(2026) 5252

    Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.

    Accessed 2026-07-27

  5. [5]

    Publications Office of the European Union · Recital 31 · CELEX:32024R2690

    Accessed 2026-07-27

  6. [6]

    Publications Office of the European Union · Article 33(1) · CELEX:32016R0679

    Accessed 2026-07-27

Follow-up questions

How long can the initial assessment take?+

The guidance sets no fixed period, because it depends on the event. In some cases active exploitation is clear from the outset. In others it takes time to establish whether the product is affected and whether a malicious actor is exploiting it. The stated expectation is prompt action, so an assessment that drifts for days without progress would be difficult to defend.

What if we are unsure whether an incident is severe?+

Assess it immediately and record the reasoning. Awareness attaches to reasonable certainty that a severe incident has compromised the product's security. Where the assessment concludes it has not, keep the determination. Voluntary reporting under Article 15 remains available where you would rather notify anyway.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.