Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/Eu cra reporting goes live this friday are you ready
Dev48

© 2026 · All rights reserved.

EU CRA Reporting Goes Live This Friday. Are You Ready?

Источник: HackerOne

EU CRA Reporting Goes Live This Friday. Are You Ready?

Source: HackerOne

The EU Cyber Re ilience Act' mandatory vulnerability reporting requirement take effect September 11. Here' what manufacturer need to know to meet the 24-hour window.

September 26, 2026

If you make covered software or hardware sold in the European Union, this Friday marks the start of mandatory security reporting to EU regulators.

The EU Cyber Resilience Act (CRA) became law in December 2024. It sets baseline cybersecurity requirements for products with digital elements (covering many hardware and software products) sold in the EU. Most requirements don't fully kick in until December 2027, but one critical piece starts this week.

As of September 11, manufacturers must begin reporting certain vulnerabilities and security incidents to the European Union Agency for Cybersecurity (ENISA) through its newly launched Single Reporting Platform.

What the Reporting Requirements Actually Require

Under Article 14 of the CRA, if your company discovers a vulnerability in your product that is being actively exploited or suffers a severe security incident affecting your product, you're required to report it. The timelines are strict:

  • 24 hours after becoming "aware": submit an early warning to ENISA and your national cybersecurity authority
  • 72 hours after becoming "aware": submit a fuller notification with details on the nature of the vulnerability and any initial remediation steps
  • 14 days after a patch is available (for exploited vulnerabilities), or 1 month after the initial notification (for severe incidents): submit a final report

European Commission guidance published in July states that the clock starts once you've done an initial assessment and have reasonable certainty that an actively exploited vulnerability or severe incident exists.

One important note: these obligations apply to manufacturers of products with digital elements, not every tech company. If you're uncertain if that applies to you, consult legal counsel for advice specific to your situation.

Why Remediating Quickly Matters

The best way to avoid triggering the CRA's reporting requirements is to find and fix vulnerabilities before they're actively exploited. That makes fast, proactive vulnerability discovery and remediation more important than ever. Organizations that already have mature processes for finding and fixing issues quickly are far less likely to face the scenario the reporting rules aim to cover.

If you do trigger reporting obligations, speed is vital. Twenty-four hours to file an early warning is a very short window without clear processes for triaging vulnerabilities and escalating to the right people. And there's an additional incentive to patch quickly: the final report isn't due until after a fix is available, so faster remediation means a faster close on your reporting obligation too.

What to Do Right Now

  • Confirm whether your products fall within the CRA's definition of "products with digital elements"
  • Register with ENISA's Single Reporting Platform
  • Verify that your internal processes can actually meet the 24/72-hour reporting windows
  • If you don't yet have a public vulnerability disclosure policy, establish one; it's a vital component of a mature vulnerability discovery process and will be required under the CRA's broader compliance framework by December 2027

Friday's deadline is a major step, not the finish line. Full CRA compliance applies at the end of 2027. But the reporting obligations starting this week signal what the regulation expects: speed, transparency, and operational readiness. Better to build that muscle now.

Start building your vulnerability disclosure program before the 2027 deadline

This post does not constitute legal advice.

About the Author

Michael Woolslayer

Policy Counsel

Michael is Policy Counsel at HackerOne, where he supports public policy efforts to address cybersecurity and AI security challenges and enable good faith security and safety research.

← All articles

More in Cybersecurity

All →
The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
Wiz

The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Rapid7

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Wiz

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

Protéger votre téléviseur connecté et votre boîtier contre le piratage
Kaspersky

Protéger votre téléviseur connecté et votre boîtier contre le piratage

Key source of economic growth in Canada may be overlooked, new research reveals
PwC

Key source of economic growth in Canada may be overlooked, new research reveals

Building trust and governance as agentic AI scales
PwC

Building trust and governance as agentic AI scales

More from HackerOne

CIRCIA Cyber Incident Reporting: HackerOne's Recommendations
HackerOne

CIRCIA Cyber Incident Reporting: HackerOne's Recommendations

CTEM for Enterprise: Scaling Continuous Exposure Management
HackerOne

CTEM for Enterprise: Scaling Continuous Exposure Management

Return on Mitigation
HackerOne

Return on Mitigation

Project Glasswing: Running a Frontier AI Model on Our Codebase
HackerOne

Project Glasswing: Running a Frontier AI Model on Our Codebase