Back to blogSecurity

CRA reporting obligation since 11 September 2026: 24 hours to report an exploited vulnerability

uComply

Team uComply

Author

September 17, 2026

Published

Since 11 September 2026, the reporting obligation of the Cyber Resilience Act (CRA) has been in force. From that date, manufacturers of products with digital elements must report an actively exploited vulnerability within 24 hours. That is more than a year before the regulation applies in full on 11 December 2027.

Many organisations are by now familiar with the reporting obligation under the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), the Netherlands' implementation of NIS2. The CRA adds a second reporting obligation, aimed at the product rather than the organisation.

What is the CRA?

The Cyber Resilience Act is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements: hardware and software that connect directly or indirectly to another device or network. Think of smart devices, network equipment, operating systems, apps and software libraries. The regulation applies directly in all member states; unlike NIS2, no national transposition is required.

The CRA is being phased in. Most requirements, such as security by design, a conformity assessment and CE marking, apply from 11 December 2027. The reporting obligation in Article 14 comes first and has applied since 11 September 2026.

What must you report, and when?

The reporting obligation covers two types of event:

  • Actively exploited vulnerabilities in your product. This is not every weakness discovered, but vulnerabilities for which there is reliable evidence that a malicious actor has actually exploited them.
  • Severe incidents affecting the security of the product. For example, an incident that affects the availability, integrity or confidentiality of sensitive data, or that makes it possible to introduce malicious code into the product or the supply chain.
  • Both follow a staged reporting procedure:

    StepDeadlineContent
    Early warningwithin 24 hours of becoming awarebrief notification that something is happening
    Notificationwithin 72 hoursmore detail: nature, severity, affected product, any mitigation
    Final reportwithin 14 days (vulnerability) or 1 month (incident)root cause, impact, measures taken

    The 24 hours start counting the moment you become aware of the exploitation. Not when your development team has found the cause or the patch is ready.

    Where do you report?

    Reports go through ENISA's Single Reporting Platform. In the Netherlands, the NCSC (National Cyber Security Centre) has been designated as CSIRT coordinator and recipient for manufacturers with their main establishment in the Netherlands. You submit one report; it reaches the NCSC and ENISA and is shared where necessary with the relevant CSIRTs in other member states.

    Who does this apply to?

    The reporting obligation is aimed first and foremost at manufacturers: anyone who places a product with digital elements on the EU market under their own name or brand. That explicitly includes software vendors. The CRA also affects:

  • Importers and distributors, with obligations of their own. They count as manufacturers as soon as they sell a product under their own name or substantially modify it.
  • Open-source software stewards, organisations that support open-source software for commercial purposes, under a lighter regime.
  • A frequently asked question: does the CRA apply to SaaS? A pure cloud service is not a product and does not fall directly under the CRA. In practice, however, many SaaS providers also supply client software, mobile apps, agents or integration components that customers install. Those components are indeed products with digital elements. So determine for each component whether the CRA applies, rather than answering "no" for the service as a whole.

    The CRA alongside Cbw/NIS2 and ISO 27001

    The Cbw governs the resilience of organisations in important and essential sectors; the CRA governs the security of products. An organisation can fall under both, for example a software company that is covered by the Cbw as a supplier and also places products on the market. Both laws require an early warning within 24 hours and a detailed notification within 72 hours.

    Setting up two separate processes for this means duplicate work and the risk that an incident is reported to one authority but not the other. It is smarter to run one incident and vulnerability process with a short decision tree: does this affect our organisation (Cbw), our product (CRA), or both? ISO 27001 fits well here. The controls for incident management, vulnerability management and secure development form the foundation on which both reporting obligations can rest.

    What you need to set up now

    A checklist for the coming weeks:

    1.Product inventory: which products, versions and components do you place on the market, and who owns each product?
    2.Definition of awareness: record when the 24 hours start and who makes that decision.
    3.Signal channels: a contact point for researchers and customers (coordinated vulnerability disclosure), monitoring and information from your own suppliers.
    4.Reporting procedure: who reports, with which information, via which account on the reporting platform, including outside office hours.
    5.Deadline tracking: 24 hours, 72 hours, 14 days and 1 month as hard deadlines in your system, not in someone's head.
    6.Record keeping: log every step so that you can demonstrate afterwards that you acted in time.
    7.Practice: walk through a fictitious exploited vulnerability from start to finish.

    How uComply helps

    In uComply you register incidents and vulnerabilities as controlled processes, not as loose e-mails. Every registration has an owner, a status and the date of awareness, so it is recorded when the clock started. With Reminders you set the reporting deadlines of 24 hours, 72 hours, 14 days and 1 month as scheduled tasks for the responsible colleague; uComply sends automatic reminders before the deadline and logs what was sent and when.

    You record the reporting procedure as a control and link it to the ISO 27001 controls for incident management, vulnerability management and secure development, as well as to the Cbw control framework included in uComply. One control, multiple requirements: the duplicate work for CRA and Cbw disappears. Evidence, such as the NCSC's acknowledgement of receipt, is stored centrally with the registration. Through Flightdeck, management sees the status of controls, open risks and findings at a glance. Because uComply runs within your own Microsoft 365 environment, sensitive incident information stays in your tenant.

    Summary

    The CRA reporting obligation has applied since 11 September 2026 and requires a response within 24 hours to actively exploited vulnerabilities and severe incidents in your products. Manufacturers, and in practice many SaaS providers with client software, would do well to combine their incident and vulnerability process with their Cbw and ISO 27001 approach now. Would you like to see what that looks like in uComply? Book a demo or view our pricing.

    Sources

  • Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex
  • Secure digital products mandatory (CRA), Ondernemersplein (Dutch government business portal)
  • National Cyber Security Centre (NCSC)