Mandatory CRA reporting starts on 11 September 2026

30 Jul 2026 Author: Maria Ohnivchuk

H‑X launches a 24-hour reporting readiness service

On 27 July 2026, the European Commission published new practical guidance on applying the Cyber Resilience Act. It clarifies the scope of the CRA, substantial product modifications, support periods, cybersecurity risk assessments and reporting obligations. With 67 practical examples and visual decision aids, the non-binding guidance shows how the Commission expects organizations to apply the Regulation in practice.

Most CRA requirements take effect on 11 December 2027, but Article 14 reporting obligations begin much earlier — on 11 September 2026.

What manufacturers must report

Mandatory reporting does not cover every discovered vulnerability or every security incident:

  • an actively exploited vulnerability is a vulnerability in a product with digital elements for which there is reliable evidence that a malicious actor has exploited it without the system owner’s permission;
  • a severe product security incident is an event meeting the criteria in Article 14(5), including an impact on the protection of important data or functions or the introduction or execution of malicious code.

Manufacturers must use ENISA’s forthcoming Single Reporting Platform to notify the coordinating national CSIRT and ENISA simultaneously:

  1. an early warning without undue delay and no later than 24 hours after becoming aware;
  2. a more detailed notification no later than 72 hours after becoming aware;
  3. a final vulnerability report no later than 14 days after a corrective or mitigating measure becomes available;
  4. a final severe-incident report within one month of the 72-hour incident notification.

Manufacturers must also inform affected users and, where appropriate, all users about the vulnerability or incident and the measures available to reduce its impact.

Article 14 also matters for legacy products. Its reporting obligations apply to in-scope products with digital elements placed on the EU market before 11 December 2027. Organizations therefore cannot postpone all CRA preparation until the end of 2027.

Why the 24-hour deadline makes CRA an operational challenge

ENISA expects the Single Reporting Platform to be operational by 11 September 2026. Manufacturer representatives will need an EU Login account, but the platform URL has not yet been announced, representative validation will depend on the relevant national CSIRT, and no API is planned for the initial release.

A policy document alone will not make an organization ready. Manufacturers need to establish in advance:

  • which teams and sources may first detect a relevant event;
  • when an unverified signal reaches the threshold for manufacturer awareness;
  • how to distinguish malicious exploitation from a proof of concept or good-faith research;
  • how to establish whether a vulnerable third-party component is present and exploitable in a specific product;
  • who approves the legal classification and who is authorized to submit the notification;
  • how investigation, remediation, user communications and evidence preservation will run in parallel.

New H‑X service: CRA Article 14 Reporting Readiness

H‑X Technologies is launching CRA Article 14 Reporting Readiness: Exploited Vulnerability & Severe Incident Workflow. This is not a general CRA audit. We design and exercise a specific operating process:

detection → exploit-status verification → technical and legal classification → 24-hour early warning → 72-hour notification → follow-up reporting → remediation evidence.

The engagement includes:

  • a map of products, versions, EU markets, organizational roles and the coordinating CSIRT;
  • signal integration across PSIRT, SOC/MDR, support, telemetry, threat intelligence, vulnerability disclosure and component suppliers;
  • decision trees for handling actively exploited vulnerabilities and severe incidents;
  • a RACI matrix, alternates and night/weekend escalation;
  • templates for 24-hour, 72-hour, intermediate and final submissions;
  • user-communication and information-sensitivity templates;
  • an evidence package covering logs, chronology, SBOMs, exploitability analysis, patches, testing, release records and submission receipts;
  • a tabletop exercise run against an actual 24-hour clock.

H‑X performs the technical and compliance analysis and prepares draft notifications. The manufacturer’s authorized decision-maker, supported by legal counsel, approves the final legal classification; the manufacturer or a duly authorized representative submits the report.

The service combines H‑X expertise in CRA compliance, product security and DevSecOps, threat intelligence and incident investigation.

The remaining time before 11 September should be used not merely to write a policy, but to verify that the workflow works at night, over a weekend and with incomplete information. H‑X can deliver a focused readiness sprint, notification templates and a timed simulation before mandatory reporting begins.

Contact us today.

Other news

13/07/2026
H-X Technologies expands its compliance practice across SOC 2, NIS2, DORA, and MiCA
19/06/2026
H-X Technologies at Incrypted Conference 2026