The EU Cyber Resilience Act's 24-hour rule is a legal requirement, in force since 11 September 2026, for manufacturers of "products with digital elements" sold in the EU to report actively exploited vulnerabilities and severe security incidents within 24 hours of becoming aware of them, via ENISA's Single Reporting Platform.
Below is what it means in practice...
The CRA itself is a broader regulation setting baseline cybersecurity requirements for any connected hardware or software sold into the EU. Most of it doesn't apply until 11 December 2027, but the reporting obligation under Article 14 was fast-tracked a full year ahead of everything else. If you make a connected product for the EU market and someone starts actively exploiting a weakness in it, you now have a legal clock running from the moment you find out, not from when you've worked out what happened or fixed it.
If you build connected medical devices, defence technology, or AI-enabled systems, this isn't a compliance footnote; it's a new operational requirement that needs a process behind it.
Two categories of event carry this obligation:
Vulnerabilities you've found yourself that haven't been exploited don't trigger this obligation; voluntary reporting of those isn't supported on the platform yet.
Miss the 24-hour window, and you're already non-compliant, regardless of how fast you resolve the underlying issue.
ENISA's Single Reporting Platform (SRP) went live the same day and is the single route in. A few practical points:
The CRA doesn't carve out exceptions for regulated sectors; if anything, products in digital health, defence and AI are more likely to sit in the Act's higher-risk product classes, which brings additional conformity assessment obligations on top of the reporting duty. If you're already managing NHS DSPT, Cyber Essentials, or DCC requirements, this is another clock running in parallel, not a replacement for any of them.
The practical first step isn't reading the regulation cover to cover; it's making sure you have a named Assigned Representative, an EU Login account ready, and an internal process that can surface "we think this is being exploited" within hours, not days.
What is the EU Cyber Resilience Act?
A regulation setting mandatory cybersecurity requirements for products with digital elements sold in the EU, with most obligations applying from 11 December 2027.
When did the CRA's 24-hour reporting rule start?
11 September 2026, a year ahead of the rest of the Act.
What has to be reported under Article 14 of the CRA?
Actively exploited vulnerabilities and severe incidents affecting a product's security, reported through ENISA's Single Reporting Platform.
How do I report a vulnerability under the CRA?
Through ENISA's Single Reporting Platform, using a named Assigned Representative with an EU Login account and MFA enabled.
What happens if I miss the 24-hour deadline?
You're non-compliant from that point, regardless of how quickly the underlying vulnerability or incident is later resolved.