CRA reporting obligations are effective from 11.9.2026
CRA reporting obligations in a nutshell
EU’s CRA (Cyber Resilience Act) will come into full effect in December 2027
CRA reporting obligations will begin on 11.9.2026
The reporting obligations apply to actively exploited vulnerabilities and severe incidents
The CRA (Cyber Resilience Act) will come into full effect in December 2027. However, the CRA reporting obligations will begin in less than a month, on September 11, 2026. Is your company ready for the CRA and its reporting obligations? Read more about the topic in this blog article.
What do CRA reporting obligations mean for a company
The CRA reporting obligations mean companies must notify authorities of actively exploited vulnerabilities and severe incidents that affect digital products.
Companies must:
Submit an early warning within 24 hours of becoming aware of the situation
Make a full notification within 72 hours
Submit a final report within 14 days after a corrective measure is available for actively exploited vulnerabilities (within a month for severe incidents)
The report must be made through the CRA Single Reporting Platform (SRP). The SRP will be available by September 11, 2026.
What is an actively exploited vulnerability according to CRA
In the CRA, an actively exploited vulnerability is defined as a vulnerability in a digital product that an outsider has exploited without the system owner's permission. In practice, an actively exploited vulnerability is a defect in a system that an outsider has already been able to misuse.
The CRA reporting obligation does not apply when a vulnerability is detected without intent to misuse it.
What is a severe incident according to CRA
In CRA, a severe incident is a situation that significantly affects the security of a digital product. A severe incident can be, for example, an event or situation that affects the availability, authenticity, integrity, or confidentiality of a digital product.
A serious incident can occur at different points in the life cycle of a digital product: during development, production or maintenance. An example of a severe incident could be an attacker injecting malware into a product update.
Where to get help with compliance and meeting CRA obligations
If you are not sure if the CRA applies to your company, you can read more about it in our blog article: Does the Cyber Resilience Act apply to your SaaS product. We also have a free CRA guide available in Finnish that you can access here. And if you need a CRA expert to help with your situation, contact us via our contact page!
Our sources in this blog article
More information about CRA reporting obligations you can find on the European Commission’s website and Traficom’s website. More information about the SRP you can find on Enisa’s website.