What Is the EU Cyber Resilience Act (CRA)'s 24-Hour Vulnerability Disclosure Rule?
The EU Cyber Resilience Act's 24-hour rule is a legal requirement, in force since 11 September 2026, for manufacturers of "products with digital elements" sold in the EU to report actively exploited vulnerabilities and severe security incidents within 24 hours of becoming aware of them, via ENISA's Single Reporting Platform.
Below is what it means in practice...
The CRA itself is a broader regulation setting baseline cybersecurity requirements for any connected hardware or software sold into the EU. Most of it doesn't apply until 11 December 2027, but the reporting obligation under Article 14 was fast-tracked a full year ahead of everything else. If you make a connected product for the EU market and someone starts actively exploiting a weakness in it, you now have a legal clock running from the moment you find out, not from when you've worked out what happened or fixed it.
If you build connected medical devices, defence technology, or AI-enabled systems, this isn't a compliance footnote; it's a new operational requirement that needs a process behind it.
What actually triggers a report
Two categories of event carry this obligation:
- Actively exploited vulnerabilities — where there's reliable evidence a malicious actor has already exploited a weakness in your product
- Severe incidents — under Article 14(5), an incident counts as severe if it negatively affects (or could affect) the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or if it has led (or could lead) to malicious code being introduced or executed in the product or in a user's system
Vulnerabilities you've found yourself that haven't been exploited don't trigger this obligation; voluntary reporting of those isn't supported on the platform yet.
The three CRA reporting deadlines
- 24 hours — an early warning, from the moment you become aware
- 72 hours — a fuller notification, with more detail on the exploit and any mitigations
- 14 days (vulnerabilities) or 1 month (incidents) a final report, once a fix is available
Miss the 24-hour window, and you're already non-compliant, regardless of how fast you resolve the underlying issue.
How to report under the CRA
ENISA's Single Reporting Platform (SRP) went live the same day and is the single route in. A few practical points:
- You report once, through the SRP, it routes to the CSIRT covering your main establishment, and notifies ENISA in parallel
- Reporting is done by a named "Assigned Representative" (AR), who needs an EU Login account with MFA enabled
- A Primary AR can invite up to 20 Secondary ARs, and can start submitting notifications while their AR–manufacturer association is still being verified, so verification delays aren't an excuse to miss the 24-hour deadline
- The obligation covers products already on the market before December 2027, not just new releases, though you don't need to retrospectively report exploitation you were already aware of before 11 September 2026
- Open-source software stewards get a longer runway, with their obligations following in December 2027
Why this matters more in health tech, defence and AI
The CRA doesn't carve out exceptions for regulated sectors; if anything, products in digital health, defence and AI are more likely to sit in the Act's higher-risk product classes, which brings additional conformity assessment obligations on top of the reporting duty. If you're already managing NHS DSPT, Cyber Essentials, or DCC requirements, this is another clock running in parallel, not a replacement for any of them.
The practical first step isn't reading the regulation cover to cover; it's making sure you have a named Assigned Representative, an EU Login account ready, and an internal process that can surface "we think this is being exploited" within hours, not days.
FAQs
What is the EU Cyber Resilience Act?
A regulation setting mandatory cybersecurity requirements for products with digital elements sold in the EU, with most obligations applying from 11 December 2027.
When did the CRA's 24-hour reporting rule start?
11 September 2026, a year ahead of the rest of the Act.
What has to be reported under Article 14 of the CRA?
Actively exploited vulnerabilities and severe incidents affecting a product's security, reported through ENISA's Single Reporting Platform.
How do I report a vulnerability under the CRA?
Through ENISA's Single Reporting Platform, using a named Assigned Representative with an EU Login account and MFA enabled.
What happens if I miss the 24-hour deadline?
You're non-compliant from that point, regardless of how quickly the underlying vulnerability or incident is later resolved.