• Cybersecurity Glossary
CRA Reporting Obligations from 11 September 2026
From 11 September 2026, the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires manufacturers of products with digital elements to report Actively exploited vulnerabilities and Severe incidents to ENISA and the relevant national CSIRT. Reporting follows a staged cascade: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for severe incidents. These are the first CRA obligations to take effect, well ahead of the December 2027 date for the rest of the regulation, and they apply even to products already on the market. This page explains what must be reported, the deadlines, the ENISA platform and what it means for manufacturers.
What the CRA reporting duty is?
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, is the first EU wide law to set mandatory cybersecurity requirements for products with digital elements, both hardware and software, across their whole lifecycle. Its reporting obligations, set out in Article 14, are the part that takes effect first, from 11 September 2026.
Under this duty, a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting its product’s security, must notify the authorities on a strict timetable. The aim is to give ENISA and national response teams early sight of threats that are already being used against products in the market, so they can coordinate a response before the damage spreads.
What makes this obligation stand out is its timing and reach. It applies more than a year before the rest of the CRA, and it covers products already placed on the EU market, not just new ones. For a European hardware manufacturer such as Teldat, whose routers and gateways are products with digital elements, this is a duty that applies directly, which is why it approaches the CRA as a manufacturer in scope rather than as an outside observer.
What must be reported?
The CRA does not ask manufacturers to report every flaw or glitch. It defines two specific, high threshold triggers, and understanding them is the first step to meeting the obligation without over or under reporting.
The 24h, 72h and 14 day deadlines
The CRA reporting duty follows a three stage cascade, and every stage runs from the moment of awareness. The table sets out each deadline and what it involves, for both triggers.
| Stage | Deadline | What it contains |
|---|---|---|
| Early warning | Within 24 hours of awareness | First alert of an exploited vulnerability or severe incident |
| Full notification | Within 72 hours | Description, technical detail and corrective measures |
| Final report, vulnerability | Within 14 days of a fix being available | Full assessment once a corrective measure exists |
| Final report, severe incident | Within one month of the 72 hour report | Root cause and remediation of the incident |
The clocks do not pause: the 24 hour, 72 hour and final report windows all run from awareness, and nothing stops them for administrative reasons such as registering on the platform. This is why the early warning at 24 hours is the hardest deadline to meet, and why it depends entirely on detecting the exploitation or incident fast in the first place.
The ENISA single reporting platform
Reports under the CRA are not sent by email or to a patchwork of national portals. They go through one central system, and knowing how it works is part of being ready for 11 September 2026.
CRA timeline and key dates
The CRA applies in phases, and the reporting obligation is the first milestone that manufacturers actually have to meet. The table sets out the dates that matter.
| Date | Milestone |
|---|---|
| December 2024 | CRA, Regulation (EU) 2024/2847, enters into force |
| 11 September 2026 | Reporting obligations under Article 14 start to apply |
| 11 December 2027 | The rest of the CRA applies in full, including CE marking |
Why September 2026 comes first: although most of the CRA, including the essential requirements and CE marking, applies from 11 December 2027, the reporting duty is brought forward to 11 September 2026 so that authorities gain early visibility of active threats. Manufacturers cannot treat the CRA as a 2027 problem, because the reporting clock is already live well before then, and covers products already on the market.
Penalties and enforcement
The reporting obligation is described as the first CRA duty with real operational consequences, and it is backed by significant penalties. These are the main points manufacturers need to weigh.
The CRA and Teldat
Teldat is a European manufacturer of products with digital elements, such as routers and network gateways, so the CRA and its reporting obligations apply to Teldat directly. It approaches the regulation not as a compliance vendor but as a manufacturer in scope, subject to the same duties as any other.
A manufacturer’s perspective: because Teldat is itself subject to the CRA, it understands the reporting obligation from the inside. It builds security and vulnerability management into European made hardware under European jurisdiction, which helps its customers align their supply chain with the CRA. Teldat does not certify compliance, and each organization remains responsible for its own obligations, but sourcing from an in scope European manufacturer is a meaningful part of the picture.
FAQ’s about CRA reporting
❯ When do the CRA reporting obligations start?
The Cyber Resilience Act’s reporting obligations apply from 11 September 2026. This is significant because it is the first CRA obligation to take effect: while most of the regulation, including the essential cybersecurity requirements and CE marking, applies from 11 December 2027, the reporting duties under Article 14 come into force more than a year earlier. They also apply to products with digital elements already on the EU market, not only to new products placed after the deadline, so manufacturers cannot wait until 2027 to prepare.
❯ What must be reported under the CRA?
The CRA creates a reporting duty for two specific triggers. The first is any vulnerability in the product that is being actively exploited, meaning attackers are already using it, not merely that a flaw exists. The second is any severe incident that has an impact on the security of the product. The threshold is deliberately high: it is not every bug or glitch, but active exploitation or severe security impact. Deciding whether an event meets this bar is the first operational judgment a manufacturer must make, and it needs to be made quickly because the reporting clock starts from the moment of awareness.
❯ What are the CRA reporting deadlines of 24 hours, 72 hours and 14 days?
The CRA uses a three stage reporting cascade that runs from the moment the manufacturer becomes aware. First, an early warning must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. Second, a full notification with a description and technical detail must follow within 72 hours. Third, a final report must be submitted within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month of the 72 hour notification for a severe incident. None of these clocks pause for administrative reasons such as registering on the reporting platform.
❯ Who do manufacturers report to under the CRA?
Manufacturers must notify ENISA, the European Union Agency for Cybersecurity, and the relevant national CSIRT, the Computer Security Incident Response Team designated as coordinator, at the same time. Reports are filed through ENISA’s Single Reporting Platform (SRP), a centralized system that enables simultaneous notification to ENISA and the relevant national CSIRT from a single submission. Manufacturers should identify their relevant CSIRT in advance and register on the platform as soon as access opens, because the 24 hour clock does not stop while an organization sorts out onboarding or routing.
❯ What are the penalties for breaching CRA reporting obligations?
Breaches of the Cyber Resilience Act can carry significant penalties. For serious breaches, fines can reach up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, under the CRA’s penalty regime. The reporting obligations are described as the first CRA duty with operational teeth, so manufacturers need not just a reporting template but the underlying capability to detect active exploitation and severe incidents quickly enough to meet the 24 hour early warning deadline. This makes continuous product monitoring and vulnerability management a practical necessity rather than an optional extra.
❯ How does the CRA affect Teldat as a European manufacturer?
As a European manufacturer of products with digital elements, such as routers and network gateways, Teldat is itself within the scope of the CRA and its reporting obligations. This means Teldat approaches the CRA not as a compliance vendor but as a manufacturer subject to the same duties as its customers, building security and vulnerability management into its hardware and software lifecycle. For organizations that operate Teldat equipment, sourcing from a European manufacturer that designs for the CRA and operates under European jurisdiction helps align their own supply chain with the regulation, though each organization remains responsible for its own compliance.
Prepare for the CRA with Teldat
As a European manufacturer of products with digital elements, Teldat builds security and vulnerability management into its hardware under European jurisdiction, helping customers align their supply chain with the Cyber Resilience Act.







