|

The CRA Reporting Deadline This Friday: Are You Ready?

Time Is Almost Up

11 September 2026 — this Friday. Not next month. Not “sometime soon.” This week. From that day, the EU’s Cyber Resilience Act (CRA) requires manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents to EU authorities. If your team hasn’t finished preparing, stop everything else and read this now — there is very little runway left.

CRA Reporting Deadline This Friday: What Happens the Moment It Hits

There is no grace period. No soft launch. The instant Friday arrives, the obligation is live. If your product is hit by an exploited vulnerability or a serious incident after that point, the clock starts the second your team becomes aware — whether or not you feel ready.

The Vulnerability Reporting Countdown: Three Deadlines You Cannot Miss

Once the rule is active, every report must follow this exact sequence, with no flexibility:

  1. Early warning – within 24 hours of becoming aware of the issue.
  2. Full notification – within 72 hours, with fuller details.
  3. Final report – within 14 days after a fix is ready (for vulnerabilities), or within one month for serious incidents.

These are not targets. They are hard legal deadlines. If your team hasn’t rehearsed this even once, the 24-hour window will feel brutally short when it actually matters.

Where the Report Has to Go — Fast

Every report goes through the CRA Single Reporting Platform (SRP), built by ENISA. It reaches your home CSIRT first, which then pushes it out to every other CSIRT across the EU where your product is sold. One late or sloppy report can trigger EU-wide exposure almost instantly. Speed and accuracy are not optional here.

What You Must Check Before Friday — No Exceptions

With days, not weeks, left, skip the perfect system. Focus only on what actually protects you this week.

Name an Owner Right Now

If no single person is clearly responsible for filing a CRA report, fix that today. Figuring out ownership in the middle of a real incident burns hours you will not get back.

Run the Drill Immediately

Ask your team one question right now: “If we found an exploited vulnerability this second, could we hit the 24-hour deadline?” If the answer is unclear, that gap needs fixing before Friday — not after.

Confirm Access Before You Need It

Make sure your team can actually log into the Single Reporting Platform and knows exactly who your local CSIRT contact is. Do not wait until an incident forces you to find out the hard way.

Friday Is a Start, Not a Finish Line

Meeting this deadline does not mean you’re done. The CRA’s full obligations keep phasing in through December 2027, and reporting duties will not go away after Friday — they become part of daily operations from now on. Treat this week as day one of an ongoing obligation, not a box to check once.


Key Takeaways

  • Name an owner today — not tomorrow. If nobody is clearly responsible for CRA reporting, this decision cannot wait until Friday.
  • Run a 24-hour drill immediately. Test right now whether your team could realistically file the first report in time — don’t find out during a real incident.
  • Confirm platform access before Friday. Log into the Single Reporting Platform now and verify your CSIRT contact, so nothing blocks you when it counts.
  • Treat Friday as day one, not the finish line. Reporting duties continue indefinitely — build this into standard operations starting immediately.
  • Escalate any open questions now. If your team is unsure about scope, use the European Commission’s July 2026 guidance before the deadline hits, not after.

Source of Article

European Commission, Cyber Resilience Act – Reporting obligations, Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting

Other posts you may find interesting...