Report a product security incident or vulnerability as a manufacturer

As a manufacturer, you must report an actively exploited vulnerability or a severe incident having an impact on the security of your product.

When you must report

The Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe incidents having an impact on the security of a product.

The reporting obligation applies both to new products and to products already on the EU market.

The reporting obligation applies from 11 September 2026. 

What is an actively exploited vulnerability? 

An actively exploited vulnerability is a vulnerability where a malicious actor has exploited a weakness in a product with digital elements. The reporting obligation applies to products that the manufacturer has made available on the market.

Mandatory reporting does not apply where a vulnerability is identified without malicious intent. This can include good-faith testing or research, such as bug bounty programmes.  

What is a severe incident having an impact on product security? 

A severe incident having an impact on product security is an incident that affects the product’s: 

  • availability 
  • authenticity 
  • integrity or 
  • confidentiality

An incident may occur, for example, in the manufacturer’s development, production or maintenance process.

One example of a severe incident is a situation where an attacker has succeeded in inserting malware into the manufacturer’s update distribution channel. 
 

How to report a vulnerability or severe incident

  1. Step 1

    Submit an early warning notification within 24 hours

    Submit an early warning notification within 24 hours of becoming aware of an actively exploited vulnerability or severe incident. 

    Submit the notification through the Single Reporting Platform (SRP) of the European Union Agency for Cybersecurity (ENISA).

    Required information in the early warning notification 

    Include: 

    • the EU Member States in whose territory you know the product has been made available 
    • when reporting a severe incident, whether you suspect that the incident was caused by unlawful or malicious acts 
  2. Step 2

    Submit a vulnerability or incident notification within 72 hours

    Submit a vulnerability notification or incident notification within 72 hours of becoming aware of the event. 

    Submit the notification through the Single Reporting Platform. 

    Required information in a vulnerability notification 

    Include: 

    • general information about the product and the general nature of the vulnerability and its exploitation 
    • any corrective or mitigating measures taken 
    • corrective or mitigating measures that users can take 
    • how sensitive you consider the information in the notification to be 

    Required information in an incident notification 

    Include: 

    • general information about the nature of the incident and an initial assessment of the incident 
    • any corrective or mitigating measures taken 
    • corrective or mitigating measures that users can take 
    • how sensitive you consider the information in the notification to be 
  3. Step 3

    Submit the final report by the deadline

    Submit the final report on a vulnerability no later than 14 days after a corrective or mitigating measure becomes available. 

    Submit the final report on a severe incident within one month after submitting the incident notification. 

    Submit the final report through the Single Reporting Platform. 

    Required information in a final report on a vulnerability 

    Include: 

    • a description of the vulnerability, including its severity and impact 
    • where available, information about any malicious actor that has exploited or is exploiting the vulnerability 
    • details about the security update or other corrective measures made available to remedy the vulnerability 

    Required information in a final report on a severe incident 

    Include: 

    • a detailed description of the incident, including its severity and impact 
    • the type of threat or the likely root cause of the incident 
    • applied and ongoing mitigation measures 

What happens after you submit a notification?

A notification submitted through the Single Reporting Platform is sent to the CSIRT designated as coordinator. As a rule, this is the CSIRT in the country where you submit the notification.

The information in the notification is also disseminated to CSIRTs in the countries where the product has been made available.

When can you request a delay in disseminating a notification?

When submitting a notification, you can ask the CSIRT designated as coordinator to delay its dissemination if any of the following conditions are met:

  • A malicious actor has actively exploited the reported vulnerability and, according to the information available, the vulnerability has been exploited only in the Member State of the CSIRT designated as coordinator to which you reported the vulnerability.
  • Immediate further dissemination of information about the reported vulnerability would be likely to result in the disclosure of information contrary to the essential interests of that Member State.
  • Further dissemination of the reported vulnerability would pose an imminent high cybersecurity risk.

In these situations, the CSIRT assesses the circumstances and makes a decision based on the information available.

The CSIRT may also decide to delay dissemination without a separate request if any of the conditions above are met.

See also

Read about the Cyber Resilience Act requirements for products with digital elements and for economic operators that place them on the EU market.

Page was last updated