EU Regulation 2024/2847 - Articles 13 & 14

    CRA Reporting
    Obligations

    From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through a structured three-stage notification chain.

    Legacy product trap

    The September 2026 reporting obligations apply to products already on the market - not just new products. Your existing portfolio needs CRA-compliant processes in place before this date.

    The Three-Stage Notification Chain

    CRA Articles 13 and 14 establish a mandatory reporting chain. All three notifications are submitted via the EU single reporting platform operated by ENISA.

    0h
    Detection

    Vulnerability / Incident Detected

    Manufacturer becomes aware of an actively exploited vulnerability in their product, or becomes aware of a severe incident impacting product security or users.

    • Vulnerability reported by security researcher or customer
    • ENISA or national CSIRT notification of active exploitation
    • Internal monitoring detects active exploitation in the wild
    • Severe security incident detected affecting product integrity or user data
    24h
    Early Warning

    Early Warning - Article 14(1)

    Submit initial notification to ENISA via the EU single reporting platform. This is a 'heads up' notification - full details not required at this stage.

    • Notify ENISA that an actively exploited vulnerability or severe incident has occurred
    • Provide: product identification, nature of the vulnerability/incident, initial impact assessment
    • Indicate whether you suspect malicious involvement
    • Notification triggers distribution to relevant national authorities and CSIRTs
    72h
    Intermediate

    Intermediate Notification - Article 14(2)

    Updated notification with more complete information on the vulnerability, exploitation status, and initial remediation steps taken.

    • Updated information on the vulnerability including CVE identifier if assigned
    • Affected product versions and configurations
    • Severity assessment and exploitation scope
    • Initial remediation measures applied or planned
    • Whether coordinated disclosure is in progress
    14 days
    Final Report

    Final Report - Article 14(3)

    Comprehensive final report describing the vulnerability, exploitation details, full remediation, and measures to prevent recurrence.

    • Complete technical description of the vulnerability
    • Root cause analysis
    • All affected product versions with specific identifiers
    • Full remediation steps taken including security update details
    • Measures implemented to prevent similar vulnerabilities
    • Whether a security advisory has been published

    What Triggers CRA Reporting?

    Not every vulnerability requires notification. The CRA defines two specific trigger conditions under Article 14.

    Trigger 1: Actively Exploited Vulnerability

    A vulnerability in the product that is being actively exploited in the wild - not merely known to exist. Active exploitation means there is evidence of real-world use of the vulnerability to attack systems.

    - Evidence of exploitation in threat intelligence feeds

    - ENISA or national CSIRT notification of active use

    - Customer or researcher reports of exploitation

    - Internal detection of exploitation attempts

    Trigger 2: Severe Security Incident

    An incident with a significant impact on the product's ability to provide its intended function, on the security of users, or on the security of data processed by the product.

    - Breach of product integrity or confidentiality

    - Significant impact on availability of the product

    - Unauthorised access to user data

    - Supply chain compromise affecting the product

    The ENISA Single Reporting Platform

    All three notifications are submitted to ENISA via the EU single reporting platform. ENISA then routes the information to:

    • - National cybersecurity authorities (NCAs) in relevant member states
    • - Computer Security Incident Response Teams (CSIRTs) for technical coordination
    • - Market surveillance authorities for product compliance oversight

    The Legacy Product Obligation

    The most significant compliance risk for many organisations is that the September 2026 reporting obligations apply to products already on the market - not just new products released after that date.

    What "already on the market" means

    If you placed a product with digital elements on the EU market before September 2026 and it is still available to customers (through continued sale, active support, or connected services), the reporting obligations apply. This includes SaaS products, embedded software in hardware, mobile applications, and connected devices.

    What this requires in practice

    By 11 September 2026, manufacturers must have: a vulnerability monitoring process capable of detecting active exploitation, a coordinated vulnerability disclosure (CVD) policy that security researchers can use to report vulnerabilities, and an incident response process that can execute the 24hr → 72hr → 14-day notification chain.

    Need to build your reporting process?

    ContinueOps provides the runbooks, audit trail, and tooling to execute the CRA notification chain.

    See how we help →