Guide
The CRA reporting timeline: 24 hours, 72 hours, final report
From September 11, 2026, every manufacturer of connected products must be able to notify ENISA about exploited vulnerabilities and severe incidents on a strict clock. Here is what triggers it, how the timeline works, and how to be ready before it starts.
What triggers a mandatory report
Two events, defined in Article 14: an actively exploited vulnerability in your product (someone is using the flaw in the real world, not merely a published CVE), and a severe incident having an impact on the security of your product. A vulnerability that exists but shows no sign of exploitation does not trigger Article 14, it triggers your normal handling process (fix without delay, free security update). Knowing the difference is exactly what keeps teams calm at 3 a.m.
The clock: 24 hours, 72 hours, then the final report
Step 1, the early warning, within 24 hours of becoming aware: a short "we have detected X" to ENISA and your national CSIRT, via the single reporting platform. Step 2, the full notification, within 72 hours: nature of the incident or vulnerability, impact assessment, corrective measures taken or planned. Step 3, the final report: within 14 days of a corrective measure being available for an exploited vulnerability, or within one month for an incident. Deadlines run from awareness, not from convenience, weekends included.
What good preparation looks like before September 2026
1) A qualification checklist so anyone on call can decide in minutes whether an event is reportable. 2) Pre-filled report templates with your product data, so the 24-hour warning takes ten minutes, not a night of panic. 3) A live countdown per incident with the three deadlines computed from detection time. 4) An immutable audit trail proving when you knew, what you did, and when you notified, your evidence if questions come later. 5) A dry run: simulate one incident end-to-end before the real one.
One clarification that lowers the blood pressure
Over-reporting is not penalised; under-reporting is. If a case is genuinely ambiguous after checking the criteria, notifying is the safe move. And the report is a legal act of the manufacturer: tooling can prepare everything, qualification, forms, countdowns, evidence, but a human reviews and submits. Any vendor promising fully automatic submission to a regulator is promising something you should not want.
Step zero: know what's inside your product today
You cannot qualify an incident on a component you don't know you ship. Start with a free SBOM scan of your product, free account, no credit card.
Run the free scan →This guide is general information, not legal advice. Sources: Regulation (EU) 2024/2847, Article 14; ENISA reporting guidance.