Cyber Resilience Act: all tools and articles

Something happened. When did you become aware?

What happened
  1. 24h

    Early warning

    the date you became aware has not been recorded.

  2. 72h

    Vulnerability notification

    the date you became aware has not been recorded.

  3. 14days

    Final report

    no deadline until a corrective measure is available.

Your CRA reporting deadlines

From 11 September 2026, becoming aware of an actively exploited vulnerability in a product you place on the EU market starts a 24-hour clock. This works out all three deadlines, including the one most write-ups get wrong.

The three clocks do not share a starting point

The 24-hour and 72-hour deadlines both run from the moment you became aware. The final report does not. For a vulnerability it runs 14 days from a corrective or mitigating measure being available, a date that may not exist yet: a documented workaround starts it, not only a fix. For an incident it runs one month from the 72-hour notification, so it does not exist until that notification is filed. Where there is no date, this page says which anchor is missing rather than printing a number.

Starts the 24-hour and 72-hour clocks.

  1. Early warning

    Art. 14(2)(a)

    the date you became aware has not been recorded.

    24 hours from awareness

  2. Vulnerability notification

    Art. 14(2)(b)

    the date you became aware has not been recorded.

    72 hours from awareness

  3. Final report

    Art. 14(2)(c)

    no deadline until a corrective measure is available.

    14 days after a corrective or mitigating measure is available

Enter the moment you became aware to start the clocks.

Who this applies to

Manufacturers of products with digital elements placed on the EU market, and open-source software stewards. There is no size threshold and no SME exemption anywhere in the CRA, and under Article 69(3) the reporting duty reaches products that were already on the market before the Regulation's full application in December 2027.

Recital 12 puts cloud service models, including software as a service, outside the CRA and inside NIS2, so a great many software companies are out of scope entirely. That determination depends on what you actually place on the market, and it is yours to make and record. We will not make it for you on a marketing page.

Is your product in scope? Six questions, a written determination

The duty applies. Five things to have in place today

None of these takes long. All of them are impossible to do well in the first hour of an incident, which is when a company without them discovers it needed them.

  1. 1Decide whether you are in scope, and write the decision down. Software you install or download, mobile and desktop apps, libraries and devices are in. Pure software as a service is out. Remote processing a product cannot function without is back in. A recorded determination is what you show if anyone asks why you did or did not report.
  2. 2Find your CSIRT. Notifications go to the CSIRT designated as coordinator in the member state of your main establishment. If your main establishment is outside the EU, Article 14 picks the member state of your authorised representative, then your largest importer, then your largest distributor, then where most of your users are. The coordinators are listed below.
  3. 3Give the person who will report an EU Login with two-factor authentication. ENISA's single reporting platform requires a personal EU Login account with multi-factor authentication switched on. It is a ten-minute task on a quiet day and a very long one at hour twenty-three.
  4. 4Name that person, and a deputy. The 24-hour clock does not pause for annual leave.
  5. 5Agree what "became aware" means for you. That moment starts the clock, and a team that has not decided whether a customer email, a scanner alert or a confirmed exploit is the trigger will argue about it while the hours run.

Where reports go

To the CSIRT designated as coordinator for your main establishment, and to ENISA, both through ENISA's single reporting platform, which opened on 11 September 2026, the day the obligation started, runs in English only, has no API, and requires a personal EU Login with multi-factor authentication. Nothing on this page files anything; it tells you when you would have to. The platform is at portal.cra-srp.enisa.europa.eu

The table is the list of CSIRTs designated as coordinators as ENISA published it on 10 September 2026, the day before the platform opened, read on 12 September 2026; the link is the first contact page ENISA gives for each state. In most states it is the national CSIRT the state appointed to the EU CSIRTs Network. It is a different body in Croatia (NCSC-HR), Czechia (NÚKIB). ENISA says a notification filed to the wrong coordinator may be invalidated and has to be filed again, so the row for your main establishment is the one to write into your incident procedure. ENISA's list.

CSIRTs designated as coordinators under the Cyber Resilience Act, by EU member state
Member stateCSIRT designated as coordinatorContact page
AustriaCERT.at · Computer Emergency Response Team Austriawww.cert.at
BelgiumCCB · Centre for Cybersecurity Belgiumccb.belgium.be
BulgariaCERT Bulgaria · CERT Bulgariawww.govcert.bg
CroatiaNCSC-HR · National Cyber Security Centre of Croatiancsc.hr
CyprusCSIRT-CY · National CSIRT-CYwww.csirt.cy
CzechiaNÚKIB · National Cyber and Information Security Agencynukib.gov.cz
DenmarkFE DDIS · Danish Defence Intelligence Service, formerly CFCSwww.fe-ddis.dk
EstoniaCERT-EE · CERT Estoniawww.ria.ee
FinlandNCSC-FI · National Cyber Security Centre Finlandwww.kyberturvallisuuskeskus.fi
FranceCERT-FR · CERT-FRwww.cert.ssi.gouv.fr
GermanyCERT-Bund · CERT-Bund at the BSIwww.bsi.bund.de
GreeceEL-CSIRT · National Cyber Security Authority CSIRTcyber.gov.gr
HungaryNCSC Hungary · National Cyber Security Center of Hungaryncsc.gov.hu
IrelandCSIRT-IE · National Cyber Security Centre Irelandwww.ncsc.gov.ie
ItalyCSIRT Italia · Computer Security Incident Response Team Italiawww.acn.gov.it
LatviaCERT.LV · Information Technologies Security Incident Response Institutioncert.lv
LithuaniaCERT-LT · National CERT of Lithuaniawww.nksc.lt
LuxembourgCIRCL · Computer Incident Response Center Luxembourgwww.circl.lu
MaltaMT-CSIRT · MT-CSIRTwww.mita.gov.mt
NetherlandsNCSC-NL · Nationaal Cyber Security Centrumwww.ncsc.nl
PolandCERT Polska · CERT Polskacert.pl
PortugalCERT.PT · CERT.PT at the CNCSwww.cncs.gov.pt
RomaniaDNSC · Romanian National Cyber Security Directoratewww.dnsc.ro
SlovakiaSK-CERT · SK-CERTwww.sk-cert.sk
SloveniaSI-CERT · Slovenian Computer Emergency Response Teamwww.cert.si
SpainINCIBE-CERT · INCIBE-CERTwww.incibe.es
SwedenCERT-SE · CERT-SEcert.se

Who enforces it, member state by member state

Fines are imposed nationally, by the market surveillance authority each member state designates under Article 52 and registers with the Commission. On 11 September 2026, 7 of 27 had registered one. The rest are shown as not registered: that is what the Commission's register held on that date, not a statement that the state has no plan. Names are verbatim as registered.

Cyber Resilience Act authorities registered with the Commission, by member state
Member stateMarket surveillance authority (Art. 52)Notifying authority (Art. 36)
Austrianot registerednot registered
BelgiumBelgian Institute for Postal services and TelecommunicationsCCB – Centre for Cybersecurity Belgium
Bulgarianot registerednot registered
Croatianot registeredInformation Systems Security Bureau
CyprusOffice of the Commissioner of Communications - Digital Security Authority (DSA)Digital Security Authority - National Cybersecurity Certification Authority
Czechianot registerednot registered
Denmarknot registerednot registered
Estonianot registeredConsumer Protection and Technical Regulatory Authority
FinlandFinnish Transport and Communications Agency (Traficom)not registered
FranceAgence Nationale des FréquencesAgence nationale de la sécurité des systèmes d’information
GermanyBundesamt für Sicherheit in der Informationstechnik (BSI)Bundesamt für Sicherheit in der Informationstechnik - Referat S 14 – Befugniserteilung und Aufsicht über Konformitätsbewertungsstellen
Greecenot registerednot registered
Hungarynot registeredSupervisory Authority for Regulatory Affairs
Irelandnot registerednot registered
Italynot registerednot registered
LatviaConsumer Rights Protection Centre (Patērētāju tiesību aizsardzības centrs)not registered
Lithuanianot registeredMinistry of National Defence of the Republic of Lithuania
Luxembourgnot registerednot registered
Maltanot registeredMalta Digital Innovation Authority
Netherlandsnot registeredMinistry of Economic Affairs – Dutch Authority for Digital Infrastructure
Polandnot registeredMinistry of Digital Affairs - Cybersecurity Department
Portugalnot registerednot registered
Romanianot registerednot registered
SlovakiaNational Security AuthoritySlovak Office of Standards, Metrology and Testing
Slovenianot registerednot registered
Spainnot registerednot registered
Swedennot registeredSWEDAC - Swedish Board for Accreditation and Conformity Assessment

Knowing the deadline is the easy part

At hour zero you have 24 hours and no time to work out which CSIRT is yours, who signs the notification, or where last quarter's vulnerability handling records are. StandardOS keeps the scope determination, the CSIRT routing, the named owner and deputy, and the evidence trail, so the clock starts against a page that is already filled in.

By December 2027 you also need the technical file

Article 13(12) requires technical documentation for every product with digital elements before it is placed on the market, kept for at least ten years or the support period, whichever is longer, with the contents Annex VII lists. Buy it for one product and it is drafted into your organization at checkout.

The technical file, €5,000 one-time

If you resell rather than build, Articles 19 to 21 still reach you

An importer verifies that the manufacturer did its part before the product is placed on the market. A distributor verifies the CE marking and the manufacturer's and importer's compliance. Put your own brand on a product and Article 21 makes you its manufacturer.

Importer and distributor duties, €2,500

What a missed report is actually worth

Article 14 sits in the CRA's top penalty tier, alongside the Annex I security requirements: up to EUR 15 000 000 or 2.5% of worldwide annual turnover. There are three tiers, national authorities do the enforcing, and the Regulation names small manufacturers twice.

The three penalty tiers, and who applies them

The questions this page raises, answered at length

The arithmetic here is the same function the product runs, not a copy written for this page, including the calendar-month clamp, so a notification on 31 January is answered on 28 February rather than rolling into March. This is not legal advice, and Article 14 is short enough to read yourself: Regulation (EU) 2024/2847.