EU requires cyber reports for digital products within 24 hours
September 11, 2026

Since September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents through a new EU platform. The first warning is due within 24 hours.
What this is about
As of September 11, 2026, a central part of the EU Cyber Resilience Act (CRA) applies: manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents. On the same day, the EU Agency for Cybersecurity, ENISA, launched the Single Reporting Platform (SRP), which is designed to route one report to the relevant European authorities.
This does not concern only traditional IT vendors. Connected devices, hardware containing software, desktop programs, mobile apps and other digital products placed on the EU market may be covered. The CRA's broader security and conformity obligations generally apply from December 11, 2027. Reporting starts earlier.
What the new reporting duty actually does
Manufacturers must use the SRP to report two categories: actively exploited vulnerabilities and severe incidents affecting the security of a product with digital elements. According to the European Commission, an early warning is due within 24 hours of awareness. A more detailed notification follows within 72 hours.
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective measure becomes available. For a severe incident, the final report is due no later than one month after the 72-hour notification. A manufacturer reports once through the SRP. The responsible national Computer Security Incident Response Team receives the report and generally distributes it to other affected CSIRTs, while ENISA receives it at the same time.
There is an important distinction for open-source software. According to the Commission page, the obligations for open-source software stewards under Article 24(3) apply from December 11, 2027. Whether a specific project, company or product falls under the CRA still depends on its role, how it is supplied and its business model.
Why it matters
The clock does not wait until a patch is ready or an investigation is complete. The 24-hour warning starts when a manufacturer becomes aware of a reportable case. Detection, internal escalation, legal review and regulatory reporting therefore become one operational process. A company that collects security reports in an unattended mailbox can miss the deadline quickly.
For buyers, the rule may lead to faster visible responses to vulnerabilities that attackers are actually exploiting. For manufacturers, it creates an incentive to maintain clear ownership, product inventories and reliable records. Raspberry Pi notes in its explanation that the reporting duty can also affect products already on the market.
The platform is also a coordination mechanism. Companies should not have to submit the same report separately to many authorities. ENISA nevertheless says the SRP will continue to be expanded in the coming months based on operational experience. Launching the platform therefore does not mean that every borderline case has already been settled.
In plain language
The system resembles a Europe-wide emergency line for digital products. If a manufacturer learns that intruders are already exploiting a flaw, it cannot wait for the full repair before speaking up. It sends a short initial alert, adds the key details within 72 hours and files the final report later.
A practical example
A mid-sized manufacturer sells 40,000 connected heating controllers across several EU countries. At 9:00 a.m. on Tuesday, its security team confirms that attackers are actively exploiting a remote-maintenance flaw. If the case meets the CRA criteria, an early warning must be filed through the SRP by 9:00 a.m. on Wednesday. The detailed notification, including what is known about the attack and mitigations, follows by 9:00 a.m. on Friday.
The manufacturer releases a security update ten days later. For an actively exploited vulnerability, this starts the deadline for the final report, which is due no later than 14 days after the corrective measure becomes available. The example shows why timestamps, defined escalation paths and prepared backup staff matter more than a manual written only after an incident begins.
Scope and limits
- Not every vulnerability is automatically reportable. Relevant questions include whether it is actively exploited or whether a severe security incident has occurred.
- The SRP does not replace patch management, customer communication or other statutory reporting channels. Additional duties may apply to a particular case.
- This overview is not legal advice. Manufacturers must assess their role, products and exposure against the CRA and current official guidance.
The CRA's general requirements for product security, technical documentation and conformity have also not all taken effect on September 11, 2026. Today's milestone primarily concerns reporting actively exploited vulnerabilities and severe incidents.
SEO & GEO keywords
EU Cyber Resilience Act, CRA, ENISA, Single Reporting Platform, SRP, 24-hour reporting, vulnerability reporting, security incident, digital products, CSIRT, product security, open-source software
π‘ In plain English
Since September 11, 2026, manufacturers of digital products must report certain actively exploited flaws and severe security incidents to the EU. The first warning may be due within 24 hours.
Key Takeaways
- βThe CRA reporting duty for manufacturers applies from September 11, 2026.
- βActively exploited vulnerabilities and severe security incidents must be reported through ENISA's platform.
- βThe early warning is due within 24 hours and the more detailed notification within 72 hours.
- βMost general CRA product requirements apply from December 11, 2027.
- βCompanies need prepared ownership, timestamps and escalation paths.
FAQ
What must be reported within 24 hours?
An early warning about an actively exploited vulnerability or severe security incident, if the CRA criteria are met.
Where is the report submitted?
Through the Single Reporting Platform operated by ENISA.
Does the entire CRA apply now?
No. The broader requirements generally apply from December 11, 2027; reporting starts earlier.
Are open-source projects immediately covered?
For open-source software stewards under Article 24(3), the Commission identifies December 11, 2027. Specific roles and business models require individual assessment.