CRA · Reporting Obligations

Manufacturer reporting from 11 Sep 2026 —
what to prepare now

The earliest obligation under the EU Cyber Resilience Act starts on 11 September 2026. Before any certification work, what you need first is a vulnerability and incident reporting capability. Here are the essentials.

Applies from 11 Sep 2026Basis: Regulation (EU) 2024/2847, Art. 14Sources: EUR-Lex · EC · ENISA

At a glance

From when
11 Sep 2026 — the first CRA obligation
(15 months ahead of full application on 11 Dec 2027)
Who
Manufacturers of products with digital elements (PDE) placed on the EU market
What
① Actively exploited vulnerabilities ② Severe incidents
Deadlines
Early warning 24h · notification 72h · final 14 days / 1 month
Where
Your CSIRT + the ENISA Single Reporting Platform (SRP)
due to go live 11 Sep
If you don't
Up to €15M or 2.5% of turnover · market withdrawal

01Why “now”

Most CRA obligations apply in full from December 2027. But the manufacturer reporting obligation (Article 14) starts 15 months earlier, on 11 September 2026the first real obligation companies will face. And the 24/72-hour clocks run in calendar time, not business days: once an incident hits, it is too late to prepare. That is why the reporting capability comes before certification and conformity work.

02What to report, and by when

Two triggers create the obligation — ① an actively exploited vulnerability, ② a severe incident. On becoming aware, you submit once via the Single Reporting Platform (SRP) to your CSIRT and ENISA, on a three-stage clock.3

StageActively exploited vulnerabilitySevere incident
Early warningWithin 24 hoursWithin 24 hours
NotificationWithin 72 hoursWithin 72 hours
Final reportWithin 14 days of a fix being availableWithin 1 month of the notification

03Three things that catch teams out

Preparation is trickier than it looks. These three points are where teams get stuck.

① The portal (SRP) opens on 11 September — before that, you cannot register at all (the platform URL is published at launch). You can create an EU Login account now, but that alone is not submission access, and ENISA advises registering “only when you need to submit.” So the job now is not to register, but to set up a named responsible person · a registration/verification plan · a reporting process — so that after 11 September you are not doing register-verify-submit all inside 24 hours of your first incident.1
② 24 hours cannot be done reactively — on-call coverage, severity-decision authority, and an approval line must stand in advance to meet the clock. A spreadsheet won’t warn you about the deadline.
③ Where you report — one place, not many — even with several markets, you submit to a single coordinating CSIRT, and which country that is depends on your product and corporate structure.

And the specific answers — whether your product is in scope, which class and which CSIRT, and what to prepare by when — differ for every product and corporate structure.

04If you don't comply

Penalties (Art. 64)
Breaching the essential requirements or Articles 13–14 carries fines of up to €15,000,000 or 2.5% of worldwide annual turnover, whichever is higher, plus market-surveillance orders for correction, recall, or market withdrawal.2 With the earliest deadline and calendar-time clocks, the risk is real.

05The minimum to have in place

These are the minimum items to have before 11 September. The real work is checking how far along each one is for your product and structure.

·Map your CSIRT·Security contact for authorities·Product & EU-country inventory·24-hour on-call coverage·EU Login · named SRP contact·Reporting drill

But once you put this into practice — the 24/72-hour clocks run in calendar time, the submission is in English, people make the calls and sign off, and the evidence has to last 10 years. Hold it together with spreadsheets, email and memory, and when a real incident hits, the scattered pieces become the wall.

CRA reporting as one system — deadline tracking · step-by-step report drafting · roles and sign-off · 10-year evidence retention.

cradle.acelabs.co.kr →

The legal reporting subject is always the manufacturer. CRAdle is the tool that lets that manufacturer carry it on their own.

First — how far along is your company?

From scope and classification to your reporting setup, on-call coverage, and responsible-person checks — ACE LABS starts with a readiness assessment. (Pre-certification readiness & gap advisory)

Sources

  1. 1SRP go-live date (11 Sep 2026), pre-launch testing and status — European Commission, “CRA — Reporting obligations” (EC) · ENISA, “Single Reporting Platform (SRP)” (ENISA — check for the latest status). Not yet in full operation as of mid-2026.
  2. 2Fines and penalties — Regulation (EU) 2024/2847, Article 64 (EUR-Lex)
  3. 3Reporting triggers and deadlines — the same Regulation, Articles 14 and 16 (EUR-Lex)

This article is general information based on the public law Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14, 16 and 64 and public materials from the European Commission and ENISA. It is not legal advice or a conformity determination. Whether and how the obligations apply, the exact deadlines, and the SRP's go-live and operational details require the original texts, the latest official guidance, and a case-by-case review. ACE LABS Inc. is an independent advisory firm for pre-certification readiness and gap assessment — not a certification body.