CRA reporting obligations: The 24-hour clock is ticking, but when does it start?
On Friday at 4.30 p.m., within regular business hours, a customer reports that unknown processes are running on several devices and that data is being exfiltrated. Under the Cyber Resilience Act, a notification on Monday may already be late.
While most CRA obligations take effect on 11 December 2027, manufacturers of products with digital elements have been required to submit notification within 24 hours since 11 September 2026 Infringements can be penalised with fines of up to EUR 15 million or 2.5% of global annual revenue.
It is therefore crucial to determine when the deadline begins. The European Commission's guidance clearly states that the deadline does not begin only after the matter has been fully investigated, but rather as soon as an immediate initial assessment establishes a "sufficient degree of certainty" that a vulnerability in the manufacturer's own product is being exploited.
What must be reported?
Both actively exploited vulnerabilities, where there are reliable indications of unauthorised exploitation by a malicious actor, and serious security incidents that compromise product safety are subject to notification. The obligation applies to the manufacturer and covers products that were placed on the market before 11 December 2027, as well as products placed on the market after the end of the support period. Vulnerabilities in third-party components are likewise covered.
Similar to NIS 2, strict deadlines apply:
- Early warning, including the available minimum information on the suspected incident, within 24 hours
- Incident notification, including more detailed information on the incident and the measures taken, within 72 hours
- Final report within 14 days
Notifications are to be submitted via ENISA's single reporting platform. Affected users must be informed without undue delay. In the Commission's view, however, this must be done on a risk-based basis: Technical details do not need to be disclosed if doing so would facilitate further attacks or further impair product security.
The key question: When do I have "awareness"?
The Commission interprets the term in line with NIS 2 and the GDPR. Every signal, whether from a manufacturer's own monitoring or from customers, researchers, authorities, or the media, must be followed by an immediate initial assessment. Awareness exists as soon as that assessment establishes with sufficient certainty that a vulnerability in the manufacturer's own product is being exploited. The mere existence of a vulnerability, however, does not yet trigger a reporting obligation. A root cause analysis, as well as findings on the extent of the damage or on the attacker, are not required at that point; they can be supplemented in later notifications. Since the facts of the case must be set out in the notification, the path from the first signal to the notification should be documented in a traceable manner. If a ticket remains unresolved over the weekend, the notification may therefore already be considered late. However, weekend or on-call service is not mandated. If support tickets are received outside business hours and initially go unnoticed, the deadline does not yet start to run.
Given the short reporting deadlines, the same recommendation applies here as with the GDPR: When in doubt, it is better to report once too often than not at all.
What to do now
- Determine which of your products fall under the CRA, including legacy products already placed on the market.
- Establish a reporting system and define clear criteria for assessing incoming information. Integrate this with the existing GDPR reporting process as much as possible.
- Integrate supply chain and internal processes. Review and update supplier contracts, and align reporting workflows with the CRA, NIS 2, and the GDPR.
The first emergency should also not be your first time dealing with the issue. We support manufacturers in setting up CRA-compliant reporting and decision-making processes and, In the event of an emergency, in quickly and thoroughly assessing whether, when, and how a report must be filed.