Logo Teldat

• Cybersecurity Glossary

CRA Reporting Obligations from 11 September 2026

From 11 September 2026, the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires manufacturers of products with digital elements to report Actively exploited vulnerabilities and Severe incidents to ENISA and the relevant national CSIRT. Reporting follows a staged cascade: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for severe incidents. These are the first CRA obligations to take effect, well ahead of the December 2027 date for the rest of the regulation, and they apply even to products already on the market. This page explains what must be reported, the deadlines, the ENISA platform and what it means for manufacturers.

What the CRA reporting duty is?

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, is the first EU wide law to set mandatory cybersecurity requirements for products with digital elements, both hardware and software, across their whole lifecycle. Its reporting obligations, set out in Article 14, are the part that takes effect first, from 11 September 2026.

Under this duty, a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting its product’s security, must notify the authorities on a strict timetable. The aim is to give ENISA and national response teams early sight of threats that are already being used against products in the market, so they can coordinate a response before the damage spreads.

What makes this obligation stand out is its timing and reach. It applies more than a year before the rest of the CRA, and it covers products already placed on the EU market, not just new ones. For a European hardware manufacturer such as Teldat, whose routers and gateways are products with digital elements, this is a duty that applies directly, which is why it approaches the CRA as a manufacturer in scope rather than as an outside observer.

What must be reported?

The CRA does not ask manufacturers to report every flaw or glitch. It defines two specific, high threshold triggers, and understanding them is the first step to meeting the obligation without over or under reporting.

1
Actively exploited vulnerabilities
The first trigger is a vulnerability in the product that is being actively exploited, meaning attackers are already using it in the wild. The mere existence of a flaw does not start the clock; what matters is evidence that it is being exploited. This keeps the focus on real, present threats rather than theoretical weaknesses.
2
Severe incidents affecting security
The second trigger is a severe incident that has an impact on the security of the product. This covers events beyond a single vulnerability, such as a compromise that affects how the product protects its users or data. As with exploitation, the bar is severity, not any minor operational hiccup.
3
Products with digital elements
The duty falls on manufacturers of products with digital elements, a broad category covering both hardware and software that can connect or process data, from network routers to applications. Crucially, it includes products already on the EU market, so existing product lines are in scope, not just future releases.
4
The awareness trigger
The reporting clock starts from the moment the manufacturer becomes aware of the exploitation or severe incident. This makes fast detection essential: an organization can only act within the deadlines if it knows quickly, so continuous monitoring and vulnerability intelligence sit behind the whole obligation.

The 24h, 72h and 14 day deadlines

The CRA reporting duty follows a three stage cascade, and every stage runs from the moment of awareness. The table sets out each deadline and what it involves, for both triggers.

Stage Deadline What it contains
Early warning Within 24 hours of awareness First alert of an exploited vulnerability or severe incident
Full notification Within 72 hours Description, technical detail and corrective measures
Final report, vulnerability Within 14 days of a fix being available Full assessment once a corrective measure exists
Final report, severe incident Within one month of the 72 hour report Root cause and remediation of the incident

The clocks do not pause: the 24 hour, 72 hour and final report windows all run from awareness, and nothing stops them for administrative reasons such as registering on the platform. This is why the early warning at 24 hours is the hardest deadline to meet, and why it depends entirely on detecting the exploitation or incident fast in the first place.

The ENISA single reporting platform

Reports under the CRA are not sent by email or to a patchwork of national portals. They go through one central system, and knowing how it works is part of being ready for 11 September 2026.

1
One platform, simultaneous notification
Manufacturers file through ENISA’s Single Reporting Platform, a centralized system that sends the notification to ENISA and the relevant national CSIRT at the same time. This replaces fragmented national channels with a single submission, so a manufacturer does not have to report separately to each authority.
2
Report to ENISA and the CSIRT
The notification reaches both ENISA and the CSIRT designated as coordinator. For an EU established manufacturer the relevant CSIRT is generally in its own member state. Identifying the correct CSIRT in advance means the routing decision is already made when an incident occurs and the clock is running.
3
Register early, before you need it
Access to the platform requires registration, and because the reporting clock does not pause for onboarding, manufacturers should register as soon as access opens. Setting up primary and backup representatives in advance ensures someone can always file on the manufacturer’s behalf when it matters.
4
Sensitivity and confidentiality controls
The framework recognizes that early reports can be sensitive. Manufacturers can flag narrow conditions that limit what is shared until a fix is ready, with the receiving CSIRT deciding on onward dissemination. This balances rapid warning with the need not to advertise an exploitable flaw before it can be fixed.

CRA timeline and key dates

The CRA applies in phases, and the reporting obligation is the first milestone that manufacturers actually have to meet. The table sets out the dates that matter.

Date Milestone
December 2024 CRA, Regulation (EU) 2024/2847, enters into force
11 September 2026 Reporting obligations under Article 14 start to apply
11 December 2027 The rest of the CRA applies in full, including CE marking

Why September 2026 comes first: although most of the CRA, including the essential requirements and CE marking, applies from 11 December 2027, the reporting duty is brought forward to 11 September 2026 so that authorities gain early visibility of active threats. Manufacturers cannot treat the CRA as a 2027 problem, because the reporting clock is already live well before then, and covers products already on the market.

Penalties and enforcement

The reporting obligation is described as the first CRA duty with real operational consequences, and it is backed by significant penalties. These are the main points manufacturers need to weigh.

1
Fines up to 15 million euros or 2.5%
For serious breaches of the CRA, fines can reach up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher. This places CRA non compliance firmly at board level, on a par with other major EU regulatory regimes, and makes the reporting duty a business risk, not just a technical one.
2
Detection is the real requirement
Meeting a 24 hour deadline is impossible without knowing quickly that a vulnerability is being exploited. The obligation therefore implies continuous product monitoring, threat intelligence and vulnerability management, not just a reporting template. In practice, detection capability is what makes compliance achievable.
3
Existing products are in scope
Because the duty covers products already on the market, manufacturers cannot rely on a clean start with new lines. Every supported product with digital elements needs to be within the monitoring and reporting process, which can be a significant undertaking for a broad portfolio.
4
Preparation before the platform is live
Readiness means more than waiting for the platform. Manufacturers should prepare reporting templates, decide who can approve a submission within hours, identify their CSIRT and set up monitoring now, so that when an incident occurs the process runs rather than being improvised under time pressure.

The CRA and Teldat

Teldat is a European manufacturer of products with digital elements, such as routers and network gateways, so the CRA and its reporting obligations apply to Teldat directly. It approaches the regulation not as a compliance vendor but as a manufacturer in scope, subject to the same duties as any other.

1
A European manufacturer in scope
As a maker of network hardware with digital elements, Teldat falls squarely within the CRA. This means it shares the same reporting duties as its customers and builds around them from the manufacturer’s side, rather than treating the regulation as someone else’s problem.
2
Security across the product lifecycle
The CRA expects security to be designed in and maintained across a product’s life. As a manufacturer, Teldat works vulnerability management and secure maintenance into its hardware and software, which is the foundation the reporting obligation ultimately rests on.
3
European jurisdiction and supply chain
For organizations that operate Teldat equipment, sourcing hardware from a European manufacturer that designs for the CRA and works under European jurisdiction helps align their own supply chain with the regulation, one element of the wider third party and sovereignty considerations across EU cyber law.
4
Detection that supports fast reporting
Because the 24 hour clock depends on fast detection, the monitoring and visibility that Teldat builds into its network and security portfolio, including be.Safe XDR, support the kind of rapid awareness that any reporting regime, the CRA included, ultimately requires.

A manufacturer’s perspective: because Teldat is itself subject to the CRA, it understands the reporting obligation from the inside. It builds security and vulnerability management into European made hardware under European jurisdiction, which helps its customers align their supply chain with the CRA. Teldat does not certify compliance, and each organization remains responsible for its own obligations, but sourcing from an in scope European manufacturer is a meaningful part of the picture.

FAQ’s about CRA reporting

❯ When do the CRA reporting obligations start?

The Cyber Resilience Act’s reporting obligations apply from 11 September 2026. This is significant because it is the first CRA obligation to take effect: while most of the regulation, including the essential cybersecurity requirements and CE marking, applies from 11 December 2027, the reporting duties under Article 14 come into force more than a year earlier. They also apply to products with digital elements already on the EU market, not only to new products placed after the deadline, so manufacturers cannot wait until 2027 to prepare.

❯ What must be reported under the CRA?

The CRA creates a reporting duty for two specific triggers. The first is any vulnerability in the product that is being actively exploited, meaning attackers are already using it, not merely that a flaw exists. The second is any severe incident that has an impact on the security of the product. The threshold is deliberately high: it is not every bug or glitch, but active exploitation or severe security impact. Deciding whether an event meets this bar is the first operational judgment a manufacturer must make, and it needs to be made quickly because the reporting clock starts from the moment of awareness.

❯ What are the CRA reporting deadlines of 24 hours, 72 hours and 14 days?

The CRA uses a three stage reporting cascade that runs from the moment the manufacturer becomes aware. First, an early warning must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. Second, a full notification with a description and technical detail must follow within 72 hours. Third, a final report must be submitted within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month of the 72 hour notification for a severe incident. None of these clocks pause for administrative reasons such as registering on the reporting platform.

❯ Who do manufacturers report to under the CRA?

Manufacturers must notify ENISA, the European Union Agency for Cybersecurity, and the relevant national CSIRT, the Computer Security Incident Response Team designated as coordinator, at the same time. Reports are filed through ENISA’s Single Reporting Platform (SRP), a centralized system that enables simultaneous notification to ENISA and the relevant national CSIRT from a single submission. Manufacturers should identify their relevant CSIRT in advance and register on the platform as soon as access opens, because the 24 hour clock does not stop while an organization sorts out onboarding or routing.

❯ What are the penalties for breaching CRA reporting obligations?

Breaches of the Cyber Resilience Act can carry significant penalties. For serious breaches, fines can reach up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, under the CRA’s penalty regime. The reporting obligations are described as the first CRA duty with operational teeth, so manufacturers need not just a reporting template but the underlying capability to detect active exploitation and severe incidents quickly enough to meet the 24 hour early warning deadline. This makes continuous product monitoring and vulnerability management a practical necessity rather than an optional extra.

❯ How does the CRA affect Teldat as a European manufacturer?

As a European manufacturer of products with digital elements, such as routers and network gateways, Teldat is itself within the scope of the CRA and its reporting obligations. This means Teldat approaches the CRA not as a compliance vendor but as a manufacturer subject to the same duties as its customers, building security and vulnerability management into its hardware and software lifecycle. For organizations that operate Teldat equipment, sourcing from a European manufacturer that designs for the CRA and operates under European jurisdiction helps align their own supply chain with the regulation, though each organization remains responsible for its own compliance.

Prepare for the CRA with Teldat

As a European manufacturer of products with digital elements, Teldat builds security and vulnerability management into its hardware under European jurisdiction, helping customers align their supply chain with the Cyber Resilience Act.