Manufacturers of hardware and software covered by the European Union’s Cyber Resilience Act are now required to report actively exploited vulnerabilities and severe security incidents under deadlines that begin as early as 24 hours after discovery.

The reporting provisions took effect on September 11, 2026, more than a year before the CRA becomes fully applicable in December 2027. The rules matter beyond Europe because the regulation applies to products with digital elements that are made available on the EU market, including products from manufacturers based elsewhere.

For Asia-Pacific software and hardware companies that sell into the EU, the practical change is that incident-response processes now need to account for a regulatory clock as well as technical containment and customer communication.

Early warning is due within 24 hours

Under the European Commission’s reporting guidance, manufacturers must submit an early warning within 24 hours after becoming aware of an actively exploited vulnerability or a severe incident affecting the security of a covered product.

A fuller notification is due within 72 hours. For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, a final report is due within one month of the 72-hour submission.

Reports are filed through the CRA Single Reporting Platform established by the European Union Agency for Cybersecurity, or ENISA. The notification is addressed to the relevant Computer Security Incident Response Team and, except in specific circumstances, is made available to ENISA as well.

The framework is intended to avoid manufacturers having to submit the same CRA notification separately to multiple national authorities, although the initial CSIRT can distribute the information to other member states where the product is available.

The reporting duty starts before most CRA product requirements

The CRA entered into force on December 10, 2024 and becomes fully applicable on December 11, 2027. The vulnerability and incident reporting obligations in Article 14 were deliberately scheduled earlier.

The Commission’s legislative summary says the reporting obligations apply to all products with digital elements that have been made available on the Union market, including products placed on the market before the full December 2027 application date.

The broader CRA covers hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. It imposes cybersecurity requirements on manufacturers across product design, development, production and vulnerability handling, subject to exclusions and specific rules in the regulation.

APAC vendors need reporting paths that cross teams

A 24-hour early-warning deadline makes internal escalation especially important. A vulnerability may first be discovered by an engineer, security researcher, customer, cloud team or external partner, while the organization responsible for the legal notification may sit in another country and function.

Companies that sell covered products into Europe therefore need to know who decides whether an issue meets the CRA threshold, which entity is the manufacturer of record, what information can be assembled within the initial window and how the final notification is coordinated with remediation and customer communications.

The requirement also creates another reason to maintain clear software inventories and ownership records. If an actively exploited vulnerability appears in a component, organizations need to understand which shipped products include it and whether those products fall within the regulation’s scope.

TNGlobal’s recent Q&A with Ensign InfoSecurity highlighted a related operational point: even as AI increases attack speed, identity controls, segmentation, endpoint detection and behavioral monitoring still create defensive choke points. The CRA adds a reporting discipline on top of those technical controls.

September 11 is the operational start line

Most of the CRA’s product obligations are still more than a year away, but the reporting regime is no longer a future compliance project.

For manufacturers already serving the EU market, the immediate question is whether vulnerability and incident processes can identify a reportable event and get the first notification out within 24 hours without waiting for every technical fact to be settled.

AI attacks are faster, but defensive choke points remain, says Ensign InfoSecurity’s Teo Xiang Zheng [Q&A]