Reminder: The CRA Reporting Deadline September 2026 Is Almost Here
Why This Date Matters to You
Mark your calendar: 11 September 2026. On this date, the first mandatory obligation under the EU’s Cyber Resilience Act (CRA) goes live. From that day, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents to EU authorities. This is not a distant deadline anymore — it is now just weeks away, and many companies still have work to do.
CRA Reporting Deadline September 2026: The Three-Step Clock
Once the rule takes effect, the reporting clock starts the moment a company becomes aware of a problem. There are three stages, each with a strict deadline:
- Early warning – within 24 hours of becoming aware.
- Full notification – within 72 hours.
- Final report – within 14 days after a fix is ready (for exploited vulnerabilities), or within one month for serious incidents.
All reports go through a single channel: the CRA Single Reporting Platform (SRP), built by ENISA. One report to your local CSIRT is automatically shared with other CSIRTs across the EU where your product is sold. The platform is still in testing but is expected to be fully operational by the same 11 September deadline.
A Common Misunderstanding: “We’re Not Ready Yet, So We Have Time”
Many companies believe the reporting duty only applies to products under strict third-party review. This is a myth worth clearing up now, before the deadline arrives.
Reporting Applies to Nearly All Products
Around 90% of digital products fall under the “Default” risk category, meaning manufacturers can self-declare compliance instead of going through third-party assessment. This has led some leaders to assume, “we’re not in a hurry.” But the reporting duty does not depend on risk category. Whether a product is Default, Important, or Critical, the obligation to report exploited vulnerabilities is the same.
Self-Declaration Still Means Full Responsibility
Self-declaration does not mean “no compliance needed.” It means the manufacturer takes on full legal responsibility for meeting the CRA’s technical documentation and safety requirements. Authorities can request proof of compliance at any time. This is an important distinction leadership teams should not overlook.
Why Waiting Is a Real Risk
The penalties for missing the reporting deadline are serious. Under CRA Article 64, fines of up to €15 million, or 2.5% of global annual revenue, can apply once the rule is active — and this applies from 11 September 2026, well before the full compliance deadline in December 2027. This also applies to products already sold in the EU market today, not just future launches.
Supply Chain Pressure Is Already Building
European brand customers are preparing for their own CRA obligations. Many are now asking suppliers, including manufacturers based in Asia, to provide a Software Bill of Materials (SBOM), a documented vulnerability management process, and a named security contact point (PSIRT). Suppliers who can respond to these requests quickly are becoming preferred partners, while those who cannot may face delays or lost opportunities.
What to Do Before 11 September 2026
Getting ready does not require a complete security overhaul overnight, but a few actions matter most right now:
- Confirm who inside your organization owns vulnerability reporting.
- Understand where your products fall under CRA obligations, even if they are already on the market.
- Start building basic documentation like SBOMs and incident response steps.
- Watch for updates on the Single Reporting Platform as it finishes testing.
Time is short, but early movers are turning this deadline into a competitive advantage rather than just a compliance cost.
Key Takeaways
- Start the 24-hour clock exercise now. Run a mock vulnerability report internally to see if your team can realistically meet the 24-hour early warning deadline — most companies discover gaps only when they test it.
- Don’t assume self-declaration means low priority. Confirm with your compliance or legal team whether your product category still requires full reporting readiness, since nearly all digital products do.
- Prepare documentation your EU customers will ask for. Have your SBOM, vulnerability policy, and PSIRT contact ready before customers request it in an RFQ or audit.
- Treat the deadline as retroactive. Products already sold in the EU are covered from day one — review your existing product lines now, not just future launches.
- Use this deadline to strengthen customer trust. Suppliers who can respond quickly to CRA-related requests are more likely to win long-term contracts with European partners.
Source of Article
European Commission, Cyber Resilience Act – Reporting obligations, Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
Not Sure Where to Start?
Request a free initial consultation or product assessment.
Our experts are here to help.
