Estimated reading time: 5 minutes · Last updated:
The Cyber Resilience Act (CRA) now forces vendors selling products in the European Union to notify the European Union Agency for Cybersecurity (ENISA) within 24 hours when they have a reasonable indication of an actively exploited vulnerability or a severe product security incident. A fuller notice must follow within 72 hours, a formal security report within a few weeks after a patch is available, and a final report within one month. Failure to meet the deadlines can trigger fines of up to 15 million euros or 2.5% of global annual turnover. The CRA’s wider obligations remain phased in through December 2027, but the reporting window fast-tracked to begin on 11 September 2026. This summary is based on reporting by Nate Nelson, as first reported by Dark Reading.
Based on quantitative data from the OWASP SAMM Benchmarking project, we know that organizations are actually pretty good at those, and especially when it comes to incident response.
Dr. Aram Hovsepyan, CEO and founder of Codific and founding board member of OWASP EU
Key takeaways
- Immediate reporting: Vendors with products sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours.
- Follow-up windows: A more detailed notification is due within 72 hours, a formal security report comes within weeks of a fix, and a full report is due within one month.
- Penalties: Failing to report can lead to fines up to 15 million euros or 2.5% of a company’s total worldwide annual revenue.
- Small-vendor carve-outs: Microenterprises (<10 employees and <2 million euros turnover) and small enterprises (<50 people and <10 million euros turnover) are exempt from 24-hour fines.
- Phased enforcement: The fast-tracked reporting rules take effect on 11 September 2026; the CRA’s remaining rules become strictly enforced in December 2027.
Table of contents
What the fast-tracked CRA reporting cycle requires
The fast-tracked element of the Cyber Resilience Act centres on rapid notification to ENISA. From 11 September 2026, vendors who sell connected hardware or software anywhere in the EU must submit an initial flag to ENISA’s Single Reporting Platform within 24 hours of a reasonable indication that an actively exploited vulnerability or a severe security incident has occurred.
That initial notice is a trigger, not the end of the paperwork: CRA demands a fuller notification within 72 hours that adds details on impact, severity and interim mitigations users should apply. After a technical fix is ready, vendors must file a formal security report within a matter of weeks, and then a comprehensive final report within one month that documents remediation and residual risk.
The rules apply to both device and software vendors regardless of corporate location, provided their products are distributed in EU member states. The CRA excludes certain already-regulated technologies and open source software, and it allows limited delay of public dissemination under Article 16(2) where manufacturers can justify sensitivity on cybersecurity grounds.
Who is in scope, and how penalties and exemptions work
Scope is broad: networked hardware and software sold in the EU are covered, and non-EU companies that distribute in member states must comply. The CRA fast-track does not require companies to report known vulnerabilities that are not yet actively exploited; it focuses on exploitation and incidents that materially affect availability, integrity, authenticity or confidentiality.
Penalties are explicit and tiered: the maximum administrative sanction for failing to report serious incidents is 15 million euros or, if larger, 2.5% of total worldwide annual turnover. That mirrors the dual-cap threshold model used in other EU rules.
Microenterprises (fewer than 10 employees and under 2 million euros turnover) and small enterprises (fewer than 50 people and under 10 million euros turnover) are protected from fines for missing the 24-hour window, and conformity assessments will be carried out proportionately for micro-, small- and medium-sized firms. Larger vendors receive no such exemption.
Operational impact: detection, disclosure and reputational trade-offs
The CRA shifts legal pressure onto detection and incident-response processes. Organisations with mature IR teams and clear playbooks will find the 24- and 72-hour deadlines operationally demanding but procedurally manageable; those without automated detection and rapid triage will struggle to assemble a credible initial notice in time.
Dr. Aram Hovsepyan, CEO and founder of Codific and a founding board member of OWASP EU, says rapid reporting is realistic for many large organisations because "Based on quantitative data from the OWASP SAMM Benchmarking project, we know that organizations are actually pretty good at those, and especially when it comes to incident response." That view underscores how the CRA leverages existing IR capability in bigger firms while exposing capability gaps elsewhere.
A predictable challenge will be the tension between compliance and reputation management: companies often prioritise containment and messaging over regulatory reporting when an incident breaks. Under the CRA, those choices can carry a direct financial cost, and manufacturers will need clear internal rules that balance customer notifications, legal disclosure and public communication.
| Item | Who it applies to | Reporting deadline | Penalty |
|---|---|---|---|
| Fast-tracked CRA reporting | Vendors selling connected products in EU | Initial: 24 hours; fuller: 72 hours; formal/final: weeks/month | Up to 15 million euros or 2.5% global turnover |
| Micro/small enterprises | Micro: <10 employees & <2M€ turnover; Small: <50 & <10M€ | Same windows, but protected from 24-hour fines | Conformity assessments proportionate |
How this could play out
The case for
- Faster disclosure can reduce exploit dwell time and speed coordinated mitigations, limiting overall impact.
- A single ENISA reporting channel standardises filings across member states, easing cross-border incident coordination.
- Organisations with mature IR practices can fold CRA deadlines into existing playbooks and avoid fines.
The case against
- Reputational concerns may still delay public disclosure and complicate compliance despite the legal deadline.
- Article 16(2) provisions that permit dissemination delays could produce uneven transparency and enforcement.
- Smaller vendors may lack the detection tooling to meet initial notices even if they are protected from fines, raising systemic risk.
What to be careful about
- Companies that misclassify or under-report an actively exploited vulnerability risk fines reaching 15 million euros or 2.5% of global turnover.
- Ambiguity over what constitutes a "reasonable indication" of exploitation could produce inconsistent enforcement across jurisdictions.
- Delaying public dissemination under Article 16(2) may reduce the speed of community mitigations and increase exposure for end users.
- Non-EU vendors that sell into the EU may underestimate cross-border obligations and miss reporting deadlines.
The bottom line
The Cyber Resilience Act’s fast-tracked reporting obligations force vendors to operationalise rapid detection and disclosure. For many large organisations the new 24-hour initial notice and 72-hour follow-up will slot into existing incident-response routines; for smaller and less mature vendors the deadlines expose capability gaps and potential regulatory risk. The immediate task for product teams is mapping detection-to-reporting playbooks to ENISA’s Single Reporting Platform and verifying internal thresholds for what counts as an "actively exploited" vulnerability. With maximum fines of 15 million euros or 2.5% of global turnover on the table, organisations that sell connected products in the EU must treat the CRA’s reporting timetable as an urgent compliance and engineering priority.
What to watch
- 11 September 2026 — the CRA fast-tracked reporting requirement takes effect; watch for ENISA’s Single Reporting Platform to receive its first notices.
- December 2027 — the CRA’s remaining obligations move into strict enforcement; vendors must finish broader compliance work before this date.
Frequently asked questions
Who must report under the CRA fast-track?
Any organisation that distributes connected hardware or software in EU member states must report; the rule covers vendors regardless of where they are legally based, though certain already-regulated technologies and open source software are out of scope.
What deadlines and penalties apply?
Vendors must submit an initial flag to ENISA within 24 hours and a fuller notice within 72 hours; a formal security report follows within weeks of a fix and a full report within one month. Penalties for failing to report can reach 15 million euros or 2.5% of worldwide annual revenue.
Are small vendors treated differently?
Yes. Microenterprises (fewer than 10 employees and under 2 million euros turnover) and small enterprises (fewer than 50 people and under 10 million euros turnover) may not be fined for missing the 24-hour window, and conformity assessments are to be proportionate for smaller firms.
Related reading
This article is information, not financial advice. Anyone acting on it should do their own checks.