Compliance journey
The 24h, 72h and final report
When something is being exploited, the clock starts. Here is what you must report, and when.
The CRA introduces one of its sharpest obligations: when a manufacturer becomes aware of an actively exploited vulnerability in its product, or a severe incident affecting the security of the product, it must notify the authorities on a strict, staged timeline. These notifications go through the ENISA Single Reporting Platform (SRP) and are shared with the relevant national CSIRT and ENISA. Notably, these reporting duties apply earlier than the rest of the CRA — from 2026 — so they deserve attention now.
What triggers a report?
- An actively exploited vulnerability contained in the product — i.e. there is evidence that a malicious actor is exploiting it, without necessarily any successful compromise being required.
- A severe incident having an impact on the security of the product with digital elements — for example a compromise that affects the product's ability to protect its users.
Ordinary, non-exploited vulnerabilities that you find and fix through your normal handling process are not what this obligation is about — this is specifically for exploitation and severe incidents.
The three stages
Why the staged model?
The tight first deadline is deliberately about speed over completeness. Authorities and CSIRTs want to know quickly that something is being exploited so they can warn others and coordinate a response; the fuller picture can follow as you learn more. Trying to wait until you "have all the facts" defeats the purpose — and misses the 24-hour window.
Build the muscle before you need it
- Know who decides. Have a named, reachable owner (and backups) who can authorise a report at any hour.
- Have an internal approval step that does not become a bottleneck. Many teams want two or three responsible people to sign off before reporting — design that to happen fast.
- Template your reports. Pre-build the 24h / 72h / final structures with the fields you know you will need, so you are filling blanks, not starting from scratch.
- Keep the evidence trail. Link the report to the affected product, version, and SBOM finding.
General information, not legal advice. Exact triggers, deadlines and content are defined in Regulation (EU) 2024/2847 and ENISA's Single Reporting Platform guidance — always follow the official sources.