At a glance
(15 months ahead of full application on 11 Dec 2027)
— due to go live 11 Sep
01Why “now”
Most CRA obligations apply in full from December 2027. But the manufacturer reporting obligation (Article 14) starts 15 months earlier, on 11 September 2026 — the first real obligation companies will face. And the 24/72-hour clocks run in calendar time, not business days: once an incident hits, it is too late to prepare. That is why the reporting capability comes before certification and conformity work.
02What to report, and by when
Two triggers create the obligation — ① an actively exploited vulnerability, ② a severe incident. On becoming aware, you submit once via the Single Reporting Platform (SRP) to your CSIRT and ENISA, on a three-stage clock.3
| Stage | Actively exploited vulnerability | Severe incident |
|---|---|---|
| Early warning | Within 24 hours | Within 24 hours |
| Notification | Within 72 hours | Within 72 hours |
| Final report | Within 14 days of a fix being available | Within 1 month of the notification |
03Three things that catch teams out
Preparation is trickier than it looks. These three points are where teams get stuck.
And the specific answers — whether your product is in scope, which class and which CSIRT, and what to prepare by when — differ for every product and corporate structure.
04If you don't comply
05The minimum to have in place
These are the minimum items to have before 11 September. The real work is checking how far along each one is for your product and structure.
But once you put this into practice — the 24/72-hour clocks run in calendar time, the submission is in English, people make the calls and sign off, and the evidence has to last 10 years. Hold it together with spreadsheets, email and memory, and when a real incident hits, the scattered pieces become the wall.

CRA reporting as one system — deadline tracking · step-by-step report drafting · roles and sign-off · 10-year evidence retention.
cradle.acelabs.co.kr →The legal reporting subject is always the manufacturer. CRAdle is the tool that lets that manufacturer carry it on their own.
First — how far along is your company?
From scope and classification to your reporting setup, on-call coverage, and responsible-person checks — ACE LABS starts with a readiness assessment. (Pre-certification readiness & gap advisory)
Sources
- 1SRP go-live date (11 Sep 2026), pre-launch testing and status — European Commission, “CRA — Reporting obligations” (EC) · ENISA, “Single Reporting Platform (SRP)” (ENISA — check for the latest status). Not yet in full operation as of mid-2026.
- 2Fines and penalties — Regulation (EU) 2024/2847, Article 64 (EUR-Lex)
- 3Reporting triggers and deadlines — the same Regulation, Articles 14 and 16 (EUR-Lex)
This article is general information based on the public law Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14, 16 and 64 and public materials from the European Commission and ENISA. It is not legal advice or a conformity determination. Whether and how the obligations apply, the exact deadlines, and the SRP's go-live and operational details require the original texts, the latest official guidance, and a case-by-case review. ACE LABS Inc. is an independent advisory firm for pre-certification readiness and gap assessment — not a certification body.