From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through a structured three-stage notification chain.
Legacy product trap
The September 2026 reporting obligations apply to products already on the market - not just new products. Your existing portfolio needs CRA-compliant processes in place before this date.
CRA Articles 13 and 14 establish a mandatory reporting chain. All three notifications are submitted via the EU single reporting platform operated by ENISA.
Manufacturer becomes aware of an actively exploited vulnerability in their product, or becomes aware of a severe incident impacting product security or users.
Submit initial notification to ENISA via the EU single reporting platform. This is a 'heads up' notification - full details not required at this stage.
Updated notification with more complete information on the vulnerability, exploitation status, and initial remediation steps taken.
Comprehensive final report describing the vulnerability, exploitation details, full remediation, and measures to prevent recurrence.
Not every vulnerability requires notification. The CRA defines two specific trigger conditions under Article 14.
A vulnerability in the product that is being actively exploited in the wild - not merely known to exist. Active exploitation means there is evidence of real-world use of the vulnerability to attack systems.
- Evidence of exploitation in threat intelligence feeds
- ENISA or national CSIRT notification of active use
- Customer or researcher reports of exploitation
- Internal detection of exploitation attempts
An incident with a significant impact on the product's ability to provide its intended function, on the security of users, or on the security of data processed by the product.
- Breach of product integrity or confidentiality
- Significant impact on availability of the product
- Unauthorised access to user data
- Supply chain compromise affecting the product
All three notifications are submitted to ENISA via the EU single reporting platform. ENISA then routes the information to:
The most significant compliance risk for many organisations is that the September 2026 reporting obligations apply to products already on the market - not just new products released after that date.
If you placed a product with digital elements on the EU market before September 2026 and it is still available to customers (through continued sale, active support, or connected services), the reporting obligations apply. This includes SaaS products, embedded software in hardware, mobile applications, and connected devices.
By 11 September 2026, manufacturers must have: a vulnerability monitoring process capable of detecting active exploitation, a coordinated vulnerability disclosure (CVD) policy that security researchers can use to report vulnerabilities, and an incident response process that can execute the 24hr → 72hr → 14-day notification chain.
Need to build your reporting process?
ContinueOps provides the runbooks, audit trail, and tooling to execute the CRA notification chain.