Reviewed 17 August 2026

CRA reporting deadlines: what the 24-hour and 72-hour clocks require

Preparation guidance for a tabletop exercise. It is not legal advice and does not determine whether a real event is reportable.

The Cyber Resilience Act introduces a staged reporting flow from 11 September 2026. A manufacturer that becomes aware of an actively exploited vulnerability must submit an early warning without undue delay and, in any event, within 24 hours. A severe incident affecting the security of a product with digital elements follows a comparable 24-hour early-warning step. The official Article 14 text and Commission implementation page should control any real decision.

Within 72 hours of awareness, the notification expands. The manufacturer provides available general information about the product, the nature of the exploitation or incident, an initial assessment and measures taken or planned, including mitigation that users can apply. The flow is designed for progressive information, not a perfect incident report at hour one.

The final step differs by event type. For an actively exploited vulnerability, the final report follows after a corrective or mitigating measure is available, within the period specified in Article 14. For a severe incident, the final report follows the 72-hour notification on its separate timetable. Because the exact facts and official platform workflow matter, organisations should rehearse the data owners rather than draft one static document.

A practical clock map

StageOperational question
AwarenessWho can declare the time and event type?
24 hoursWho owns the minimum warning and routing facts?
72 hoursWhere do product, impact, measures and user advice come from?
FinalWho owns root cause/correction, evidence and approval?

The most common preparation mistake is to give the deadline to the security team while product versions, market availability, customer mitigation and legal approvals remain elsewhere. A tabletop should therefore measure handoffs, not just writing speed.