CRA vulnerability and incident reporting obligations become mandatory across EU
Original title: 260911 CRA Meldepflicht Schwachstellen
As of 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and serious security incidents affecting product security under the Cyber Resilience Act. Reports are submitted EU-wide through the Single Reporting Platform (CRA-SRP) developed by ENISA, with no prior registration required. For EU-based manufacturers, reports go to the coordinating CSIRT of the member state where essential cybersecurity decisions are made; for non-EU manufacturers, jurisdiction is determined by criteria including agent location, importer location, or product availability in specific member states. BSI provides step-by-step guidance for compliance.
What changed
- Reporting obligation activates: Manufacturers must now actively report exploited vulnerabilities and serious security incidents affecting their digital products, shifting from passive to active disclosure requirements.
- Central reporting mechanism launches: The ENISA Single Reporting Platform (CRA-SRP) becomes the mandatory unified EU-wide reporting channel, eliminating the need for separate notifications to individual member states.
- Simplified submission process: Manufacturers can register and submit reports within minutes without prior platform registration, with a single submission reaching all relevant CSIRTs and ENISA simultaneously.
- Jurisdiction determined by decision-making location: For EU-based manufacturers, the coordinating CSIRT is determined by the member state where essential cybersecurity decisions are made, rather than where the company is registered.
- Non-EU manufacturers included: Non-EU manufacturers face jurisdiction determination based on CRA Article 14(7) criteria, including authorized representative location, importer location, or product availability in specific member states.
What the document requires
Manufacturers of products with digital elements must report actively exploited vulnerabilities and serious security incidents affecting product security via the CRA Single Reporting Platform.
Who is affected
Manufacturers of products with digital elements operating in or supplying products to the EU market. Specifically applies to: EU-based manufacturers with headquarters or decision-making centers in EU member states; non-EU manufacturers selling products in the EU; software and hardware vendors; technology companies; IoT device manufacturers.
Summary generated by a language model; the official text prevails. Not legal advice.