Manufacturers – prepare in advance for reporting vulnerabilities and incidents under the Cyber Resilience Act

August 28, 2026 at 11:51

Before the CRA reporting obligations start to apply, organisations should prepare internally for submitting notifications. The reporting deadlines are short, so it is important to agree on responsibilities and procedures before the first reportable case occurs. We have compiled a checklist for manufacturers and links to key guidance.

The Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe incidents within specified deadlines. The reporting obligations start to apply on 11 September 2026. All notifications must be submitted through ENISA’s centralised Single Reporting Platform (SRP).

Manufacturers should make sure that reporting responsibilities and procedures are in place now. Check the following in advance: 

  • products that fall within the scope of the CRA have been identified
  • a representative and backup representative responsible for submitting notifications have been appointed
  • the representatives know how to register on the Single Reporting Platform
  • the representatives are familiar with submitting notifications through the SRP
  • internal and external channels for receiving reports have been planned
  • the process for handling reports has been documented
  • the reporting deadlines are known
  • the information required in notifications has been reviewed
  • procedures for informing users have been planned
  • the procedure has been practised at least once

Determine which products fall within the scope of the CRA

Review your products and list those that fall within the scope of the CRA and are therefore subject to the reporting obligations. As a rule of thumb, if a device, software or other product is connected to a network or another device, it falls within the scope of the CRA.

For products within the scope of the CRA, document the product name, the person responsible for the product, the software versions being maintained and the EU Member States to which the product has been supplied. Note that products at the end of their lifecycle that no longer receive updates are also subject to the reporting obligation.

toimitusketju

Assign people responsible for submitting notifications

Appoint a representative (Assigned Representative, AR) and a backup representative to submit official notifications through the SRP. Both representatives must register on the SRP. In your organisation’s internal processes, take into account that, for the time being, notifications can only be submitted through these two representatives.

Notifications are expected to be possible through APIs from spring 2027. After this, notifications can be submitted directly from the organisation’s own system..

Reporting deadlines require an established procedure

Know the reporting deadlines and determine what information is mandatory.

For an actively exploited vulnerability or a severe incident, an early warning must be submitted within 24 hours of the manufacturer becoming aware of it. The notification must be supplemented within 72 hours.

For a vulnerability, the final report must be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report must be submitted within one month of the incident notification.

CRA notification deadlines and mandatory information are presented in a table.

ENISA has prepared guidance on reporting vulnerabilities and incidents through the SRP. The SRP will be launched on 11 September 2026, when the reporting obligations start to apply. We will also publish a link to the notification form on the website of the National Cyber Security Centre Finland (NCSC-FI).

CRA-ilmoitusten määräajat ja pakolliset tiedot esitettynä taulukkomuodossa.

CRA reporting deadlines and mandatory information

Early warning
Within 24 hours

manufacturer name
product name
type of notification (vulnerability or incident)
title
EU Member States where the product has been made available

Notification
Within 72 hours

Vulnerability

general description of the vulnerability
information on exploitation
corrective or mitigating measures
possible protective measures for users

Incident
nature of the incident
time of detection
preliminary impact assessment
corrective measures taken
possible protective measures for users

Final report

Vulnerability

Within 14 days of a corrective or mitigating measure becoming available

description of the vulnerability
severity
impact
information on actors exploiting the vulnerability
date of the corrective measure
description of the corrective or mitigating measure

 

Incident

Within one month of submitting the incident notification

detailed description of the incident
severity
impact
type of threat or likely root cause
applied and ongoing mitigating measures
applied and ongoing corrective measures

Plan in advance how to handle reports

  1. Step 1

    A report is submitted to the organisation

    • A report of suspicious activity may come from within the company, a security researcher, a subcontractor or a product user.
    • Consider whether your company has a clear point of contact and instructions telling reporters how and where to submit their reports.
    • Examples:
    • security@company.fi
    • psirt@company.fi
    • a reporting form on the website
    • security.txt
  2. Step 2

    The report is received

    • Once a report has been received, make sure that the person handling it has instructions on what to do.
    • Also instruct the company’s general points of contact, such as info@company.fi, on how to forward reports to the person responsible for handling them.
  3. Step 3

    The report is investigated

    • Carry out an initial investigation without delay to determine whether the case involves an actively exploited vulnerability or a severe incident having an impact on security.
  4. Step 4

    Report the vulnerability or incident

    • Once the manufacturer has reasonable certainty that an actively exploited vulnerability exists or an incident having an impact on the security of the product has occurred, submit an early warning within 24 hours.

Be prepared to inform users too

Under the Regulation, the manufacturer must inform affected users of the product and, where appropriate, all users without undue delay about a vulnerability or incident and, where necessary, about any corrective or mitigating measures that users can take. If users’ contact details are not available, publishing a notice on the website may, for example, be appropriate.

When preparing for the reporting obligations, you can use ENISA’s guidance on the Single Reporting Platform and materials on the Cyber Resilience Act published by the European Commission and the NCSC-FI at Traficom.

More information

European Commission’s CRA Guidance Ulkoinen verkkopalvelu.ENISA’s SRP pages Ulkoinen verkkopalvelu. ENISA’s SRP pages NCSC-FI’s CRA pages Ulkoinen verkkopalvelu.

The NCSC-FI’s CRA pages also include a link to a form you can use to submit further questions about the CRA.