What are the CRA reporting obligations?

The CRA reporting obligations are the duties in Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847) that require manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents within 24 hours through ENISA’s Single Reporting Platform. They have applied since 11 September 2026, more than a year before the regulation’s essential requirements. Crucially, they also cover products that have been on the market for years, such as a PLC, HMI or IIoT gateway already running in an existing plant.


🗓️ When do the CRA reporting obligations apply?

Date Milestone
20 November 2024 CRA published in the Official Journal of the EU
10 December 2024 Regulation enters into force
11 June 2026 Rules on notified bodies (conformity assessment) apply
11 September 2026 Article 14 reporting obligations apply; ENISA launches the Single Reporting Platform
11 December 2027 Full application: essential requirements, CE marking and support period

Reporting is an exception to the transitional rules. Products placed on the market before 11 December 2027 only need to meet the essential requirements after a substantial modification, but Article 69(3) makes Article 14 apply to every in-scope product, including the existing installed base.


🧱 Who has to report, and what?

The duty lies with the manufacturer: whoever places a product with digital elements on the EU market under its own name or trademark, regardless of company size. Importers and distributors only report when they sell a product under their own brand or substantially modify it. Open-source software stewards only get a lighter regime from 11 December 2027, and only to the extent that they are involved in developing the product.

Two events trigger a report:

  • Actively exploited vulnerability — there is reliable evidence that a malicious actor has exploited the vulnerability in a system without permission. A flaw you find yourself, a penetration test finding or a report received through responsible disclosure without evidence of exploitation is not reportable.
  • Severe incident having an impact on product security — an incident that negatively affects, or is capable of affecting, the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or can lead to malicious code being introduced or executed in the product or in users’ systems, for example through a compromised update channel.

Article 15 adds a voluntary route: manufacturers and other parties may also notify unexploited vulnerabilities, cyber threats and near misses to a CSIRT or ENISA.

The difference from NIS2 incident reporting is fundamental: the CRA looks at the product and its manufacturer, not at the organisation operating it.


⏱️ What deadlines apply to a CRA report?

Stage Vulnerability Severe incident
Early warning Within 24 hours of becoming aware, listing the member states where the product is available Within 24 hours, stating whether unlawful or malicious acts are suspected
Notification Within 72 hours: product, nature of the exploit and vulnerability, measures taken and measures users can take Within 72 hours: nature of the incident, initial assessment, measures
Intermediate report On request of the CSIRT On request of the CSIRT
Final report No later than 14 days after a corrective or mitigating measure is available Within one month of the 72-hour notification

The final report for a vulnerability describes its severity and impact, any available information about the actor exploiting it, and the details of the security update. In the 72-hour notification, the manufacturer also indicates, where applicable, how sensitive it considers the information to be.


🔧 How does the Single Reporting Platform work?

ENISA runs the Single Reporting Platform (SRP), which went live on 11 September 2026. A manufacturer reports once and the submission reaches ENISA and the CSIRT designated as coordinator in the member state of the manufacturer’s main establishment simultaneously. That CSIRT then disseminates the information to the CSIRTs of the member states where the product is on the market.

Member states may connect their own electronic notification end-points to the SRP. In the Netherlands, the NCSC is the CSIRT coordinator: Dutch manufacturers preferably report through the MijnNCSC portal (login via eHerkenning or SSOnRijk), where organisations under the Dutch Cybersecurity Act are already registered, or through a web form that needs no registration. Market surveillance for the CRA sits with the Dutch Authority for Digital Infrastructure (RDI).

Dissemination may be delayed on justified security grounds, for example when coordinated disclosure is still under way or when exploitation is confined to a single member state.


📣 How must users be informed?

Besides notifying the authorities, the manufacturer must inform impacted users about the vulnerability or incident and about mitigating measures they can take themselves, where necessary in a structured, machine-readable format. In practice that means a CSAF advisory: the Common Security Advisory Framework 2.0 has been an OASIS standard since November 2022 and is already used by many OT vendors. If the manufacturer fails to inform users in time, the CSIRT may do so itself.


🔄 How do CRA reporting and Cybersecurity Act reporting differ?

Aspect CRA reporting Dutch Cybersecurity Act (Cbw) reporting
Who reports Manufacturer of the product Essential or important entity (operator)
What Actively exploited vulnerability or severe incident in the product Significant incident affecting its own services
Deadlines 24 hours / 72 hours / 14 days after fix or one month 24 hours / 72 hours / one month
Recipient CSIRT coordinator and ENISA via the SRP Sectoral CSIRT and supervisory authority
Applies since 11 September 2026 15 August 2026
Maximum fine EUR 15 million or 2.5% of worldwide turnover Depends on entity type, up to EUR 10 million or 2%

A single event can trigger both. If a drinking water company is hit through an exploited vulnerability in a PLC, the utility reports under the Cbw and the PLC manufacturer reports under the CRA.


🏭 What do the CRA reporting obligations mean for OT vendors and their customers?

For vendors of PLCs, HMIs, firmware, engineering software and IIoT devices, the main change is speed. A 24-hour deadline calls for a prepared, step-by-step approach:

  1. Product inventory — record which products, versions and SBOMs are on the market in which member states, including discontinued series
  2. Monitor signals — track the CISA Known Exploited Vulnerabilities catalogue, ENISA’s EU Vulnerability Database (live since May 2025, with a dedicated view of exploited vulnerabilities) and customer reports
  3. Set up a PSIRT — a product security incident response team reachable around the clock, with a triage process aligned with IEC 62443-4-1
  4. Register in advance — an account on MijnNCSC or directly on the SRP, with product details pre-filled
  5. Automate advisories — CSAF documents with CVE identifiers and VEX status for the 72-hour and final stages
  6. Link to CVD — a coordinated vulnerability disclosure policy is itself one of the vulnerability handling requirements in Annex I, Part II (point 5) of the CRA

For asset owners, the obligations mean faster and better-structured advisories. Feeding CSAF advisories into your own asset inventory shows immediately which installations are affected, so patch management and vulnerability management can be prioritised accordingly.


❓ Frequently asked questions

Do I have to report every vulnerability under the CRA reporting obligations?

No, the CRA reporting obligations only cover actively exploited vulnerabilities and severe incidents. A vulnerability you find yourself or receive through responsible disclosure becomes reportable only when there is reliable evidence of exploitation. You may still report it voluntarily, and from 11 December 2027 the essential requirements oblige you to fix it and disclose it through your CVD process.

Do the CRA reporting obligations apply to products already sold?

Yes, the CRA reporting obligations apply to all in-scope products with digital elements, including those placed on the market before 11 December 2027. A PLC series that has been running in factories for ten years is therefore covered as soon as one of its vulnerabilities is actively exploited.

Where do Dutch manufacturers submit a CRA report?

Dutch manufacturers preferably submit CRA reports through MijnNCSC or the NCSC’s CRA web form. The NCSC is the Dutch CSIRT coordinator, and the report flows through ENISA’s Single Reporting Platform so that other member states are informed as well.

What is ENISA’s Single Reporting Platform (SRP)?

The Single Reporting Platform is the central EU portal for the CRA reporting obligations, in operation since 11 September 2026. A manufacturer reports once and the submission reaches ENISA and the CSIRT of the member state of its main establishment at the same time.

What is the fine for breaching the CRA reporting obligations?

A breach of the CRA reporting obligations can lead to a fine of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Micro and small enterprises are not fined for missing the 24-hour early-warning deadline, but remain liable for other infringements.

Does an OT operator also have to report under the CRA?

No, an OT operator does not report under the CRA unless it places products with digital elements on the market itself. An operator covered by the Dutch Cybersecurity Act or another NIS2 transposition does report significant incidents to its own CSIRT and supervisor, independently of the manufacturer’s CRA report.


📌 In summary

Since 11 September 2026, the CRA reporting obligations require manufacturers to report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform in 24-hour, 72-hour and final-report stages, even for products that have been on the market for years. For OT vendors this means a PSIRT ready to act within a day and machine-readable advisories; for their customers it means faster and more actionable information about exploited vulnerabilities.