The new obligations under Article 14 require manufacturers to submit an early warning to cybersecurity authorities within 24 hours of becoming aware of an actively exploited vulnerability. A more detailed notification must follow within 72 hours, and a final report on corrective measures must be filed within 14 days of making a fix available. For severe security incidents, the final report deadline is one month after the initial report.
Reports must be submitted through ENISA's Single Reporting Platform (SRP) to the coordinating computer security incident response team (CSIRT). EU-based manufacturers report to their home member state's CSIRT, while separate rules determine the coordinator for non-EU manufacturers. Manufacturers are also required to inform affected users about vulnerabilities and available mitigations without undue delay.
Darren Anstee, CTO for security at Netscout, said the deadlines introduce needed urgency. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said. "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."
The reporting duties are classified as core CRA responsibilities, meaning non-compliance can trigger maximum fines. These rules are part of a phased rollout of the Act; most remaining provisions, including requirements for security by design, no default passwords, and mandatory security updates, become applicable on December 11, 2027. At that point, covered products must also undergo conformity assessments and bear a CE mark.
The CRA also aims to improve software supply chain visibility. The tight reporting deadlines mean manufacturers must maintain a comprehensive understanding of their products and any related items sharing vulnerabilities throughout the product lifecycle – a requirement that will eventually include producing a software bill of materials (SBOM).