Reviewed 31 August 2026
CRA reporting deadlines: what the 24-hour and 72-hour clocks require
Preparation guidance for a tabletop exercise. It is not legal advice and does not determine whether a real event is reportable.
Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools
The Cyber Resilience Act introduces a staged reporting flow from 11 September 2026. A manufacturer that becomes aware of an actively exploited vulnerability must submit an early warning without undue delay and, in any event, within 24 hours. A severe incident affecting the security of a product with digital elements follows its own comparable 24-hour early-warning pathway. The official Article 14 text and Commission implementation page should control any real decision.
Within 72 hours of awareness, the notification expands. For an actively exploited vulnerability, the manufacturer provides available general information about the product, the exploit and the vulnerability, plus corrective or mitigating measures. For a severe incident, the notification provides available information about the nature of the incident, an initial assessment and measures taken or available to users. The flow is designed for progressive information, not a perfect report at hour one.
The final step differs materially by event type. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, it is due within one month after submission of the 72-hour incident notification. A deadline calculator can therefore calculate the fixed awareness-based milestones, but it must not invent a vulnerability final-report date before the corrective-measure trigger exists.
A practical clock map
| Stage | Operational question |
|---|---|
| Awareness | Who can establish and record the time and event pathway? |
| 24 hours | Who owns the minimum warning and routing facts? |
| 72 hours | Where do the product/event facts, initial assessment and mitigation data come from? |
| Final — vulnerability | Who records when a corrective or mitigating measure became available and owns the 14-day report? |
| Final — severe incident | Who owns the report due within one month after the 72-hour incident notification? |
The most common preparation mistake is to give the deadline to the security team while product versions, market availability, customer mitigation and legal approvals remain elsewhere. A tabletop should therefore measure handoffs, not just writing speed.
Frequently asked questions
- When does the 24-hour clock start under the Cyber Resilience Act?
- It starts at awareness. In a tabletop, the practical question is who in your organisation is allowed to establish and record the awareness time and event type, because the 24-hour and 72-hour stages are measured from that moment.
- What has to be in the 24-hour early warning?
- The early warning is deliberately short: it identifies the relevant event pathway and, where applicable, the Member States where the product has been made available. For a severe incident it also states at least whether unlawful or malicious acts are suspected. More detail follows in the 72-hour notification.
- What changes at 72 hours?
- The notification expands to available product and event information, an initial assessment and corrective or mitigating measures taken or planned, including measures users can take themselves. The exact fields differ between the vulnerability and severe-incident pathways.
- Is the final report the same for incidents and vulnerabilities?
- No. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month after the 72-hour incident notification.
- Do these dates apply to us yet?
- CRA reporting obligations start on 11 September 2026, with general application on 11 December 2027. Use the official Article 14 text and current Commission reporting guidance for any real event.