CRA Reporting Obligations from September 2026 – What Applies Now
September 11, 2026 was a hard deadline for many manufacturers of connected products: since that date, the reporting obligations of the Cyber Resilience Act (CRA) apply in full. Anyone offering products with digital elements on the EU market – from embedded software to IoT devices to industrial control systems – must report actively exploited vulnerabilities and serious security incidents to the European agency ENISA within strict deadlines.
This affects more than a niche group: the CRA addresses nearly all manufacturers and importers of hardware and software products with a network connection. For many companies this represents a fundamentally new compliance dimension – alongside the already familiar patch management, structured vulnerability reporting now takes centre stage.
What the CRA Requires of Manufacturers: Reporting Obligations in Detail
Article 11 of the CRA defines the reporting obligations precisely. Manufacturers must:
- Submit an initial notification within 24 hours as soon as they become aware of an actively exploited vulnerability or a serious security incident.
- Submit a complete follow-up notification within 72 hours, with detailed information on the vulnerability, the affected products and the measures initiated.
- Submit a final report within 14 days at the latest, documenting the facts, the root cause analysis and the remedial measures taken.
Specifically subject to reporting are: actively circulating exploits, incidents that can significantly impair user security, and – depending on national implementations – certain near-miss incidents. ENISA acts as the central point of contact and forwards notifications to the responsible national authorities, i.e. the BSI in Germany.
The deadlines are ambitious. Anyone without a mature internal process will make mistakes under time pressure – with potentially significant consequences.
ENISA Single Reporting Point (SRP): How Registration Works
ENISA provides the technical infrastructure for notifications via the Single Reporting Platform (SRP). Registration proceeds in several steps:
- Account creation on the ENISA portal – providing company data, contact persons and product categories. An EU Login is required for registration. This must be set up separately (see https://trusted-digital-identity.europa.eu/index_en).
- Identity verification – ENISA checks the information; this step can take several business days.
- Complete organisation profile – registering product classes, preferred reporting formats (CSAF, JSON or structured web form) as well as emergency contacts.
- Submit test notification – ENISA recommends a test submission before going live, in order to identify format errors and configuration issues early.
Important pitfalls: Verification can take longer than expected and, in an emergency, becomes an unusable extension of the process. In addition, reporting formats such as CSAF are not without technical hurdles; a spontaneous submission without preparation is hardly reliably possible! For example, without support such as the TrustSource EUVD-ID lookup, it is barely feasible to perform the transformation from GHSAs to EUVD-IDs required for the notification.
Further technical details on the SRP can be found directly at ENISA and at the BSI.
When Early Registration Is Worthwhile – and When It Is Mandatory
Early registration is generally worthwhile for all companies that:
- manufacture products of Class I or II under the CRA annex (elevated risk potential, e.g. firewalls, operating systems, industrial automation components),
- operate in regulated sectors (energy, health, critical infrastructure),
- already run active vulnerability disclosure programmes, or
- act as PSIRT service providers for several manufacturers.
This last point deserves particular attention: external PSIRTs or managed security providers – such as EACG – can register with the SRP as reporters on behalf of third parties. This allows notifications to be submitted on behalf of several manufacturers while maintaining central oversight of all ongoing cases.
In the event of missing or late notification, severe sanctions apply: fines of up to 15 million euros or 2.5% of global annual turnover – whichever is higher.
Coordinated Vulnerability Disclosure (CVD): The Foundation of a Legally Compliant Notification
Before a notification can be sent to ENISA, an internal Coordinated Vulnerability Disclosure (CVD) process must be in place. CVD describes the structured approach by which manufacturers disclose vulnerabilities in a coordinated manner – involving the finder, relevant CERTs and, if applicable, other affected parties.
The roles involved in the CVD process are:
- Finder/Reporter: The person or organisation that discovers and reports the vulnerability.
- Manufacturer/Vendor: Responsible for analysis, patching and coordination of the disclosure.
- Coordinator: Often a CERT or PSIRT, mediating between finder and manufacturer.
- ENISA/BSI: Recipient of the regulatory notification.
Without a functioning CVD process, a CRA-compliant notification is barely conceivable: the information required by ENISA – vulnerability classification, CVSS score, affected product versions, countermeasures – only emerges during a structured disclosure process. Anyone improvising here risks incomplete notifications and thus compliance gaps.
More on the connection between CSAF and structured vulnerability management can be found in this in-depth article on the TrustSource blog.
How TrustSource CVD Specifically Supports the Reporting Process
TrustSource CVD is designed to close precisely this gap: between internal vulnerability management and regulatory-compliant notification. Internal reports are handled analogously to external reports within the same process. Key features at a glance:
Automated Deadline Monitoring
As soon as a vulnerability is classified as actively exploited, TrustSource CVD automatically starts the clock. The system transparently shows when the 24-hour initial notification, the 72-hour follow-up notification and the 14-day final report are due – with configurable escalation notifications for PSIRT and product owners.
Structured Capture of Vulnerability Data
TrustSource CVD guides the handling teams through a structured capture process based on the Vultron protocol of the Carnegie Mellon CERT: CVSS assessment, product assignment, specification of affected versions, description of countermeasures. The entries are structured so that they can be used directly for the ENISA notification.
Automatically Generated Notification Summary
Since a fully automated API connection to the ENISA SRP is not yet available, TrustSource CVD generates a pre-filled notification summary – all relevant fields, prepared in the structure of the ENISA notification form. The PSIRT team can transfer this directly into the web portal, without having to laboriously gather information. As soon as automated transmission becomes technically possible, this functionality will be extended accordingly.
Audit Trail for Evidence Obligations
Every action in the disclosure process – receipt of the notification, status changes, communication with the finder, submitted notifications – is logged in an audit-proof manner. In the event of a regulatory audit, the entire course of the process can be fully evidenced.
Conclusion and Next Steps: Act Now, Don’t Wait for the First Incident
The notification itself is not complicated. But anyone who starts with EU Login registration in an emergency will find themselves breaking a sweat. The necessary processes, systems and registrations require some lead time. Three key insights for your planning:
- Registration has lead time: Setting up a verified account with the ENISA SRP takes some time. Start now.
- CVD is not optional, but a prerequisite: Without a structured disclosure process, the CRA reporting deadlines cannot in practice be met. TrustSource CVD provides a ready-to-use framework here. If you feel uncomfortable with the task or still see challenges in your organisation, a managed service provider such as EACG can help you establish the necessary decisions and steps.
- Process maturity protects against fines: The sanctions for violations are substantial. Companies that invest in processes and tools today avoid compliance risks tomorrow.
Next steps for your team:
- Check whether your products fall under the CRA and which risk class they belong to.
- Start the registration with the ENISA SRP – ideally still this quarter.
- Evaluate TrustSource CVD as the technical foundation of your PSIRT process (visit us at it-sa 2026, booth 9-218).
The deadline applies to everyone. The difference lies in who is prepared.