# What changed on 11 September 2026
Act (CRA) began requiring manufacturers who place products with digital elements on the EU market to report actively exploited vulnerabilities and severe security incidents on tight timelines. The duty applies regardless of where the manufacturer is based, subject to the regulation's exemptions.
# The reporting timeline
- Initial report: within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
- Follow-up: a more detailed notification within 72 hours.
# Practical effects for manufacturers
Manufacturers can no longer delay mapping affected products after a vulnerability appears. The CRA requires a maintained, accurate view of a product's components and related products so manufacturers can identify what to report within the 24- and 72-hour windows. The act anticipates that software bills of materials (SBOMs) and continued traceability will be essential when further CRA provisions take effect.
Darren Anstee, CTO for security at Netscout, said: "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt." He added that faster sharing helps organisations put defences and mitigating controls in place when risk is heightened.
Eran Kinsbruner, vice president of product marketing at Checkmarx, said: "Secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list." He noted that modern applications combine proprietary code, open-source packages, third-party components and AI models and services, all of which need to be understood.
# User notifications and accountability
Manufacturers must inform affected users where appropriate about actively exploited vulnerabilities or severe incidents, and users must be told about available corrections or mitigations without undue delay. The CRA classifies these reporting duties as core responsibilities. Noncompliance can trigger the regulation's top-tier fines: up to €15 million or 2.5% of annual turnover, whichever is higher.
# Where this fits in the wider CRA rollout
Most remaining CRA provisions become applicable on 11 December 2027. At that point manufacturers must demonstrate security by design and default, which includes removing default passwords, delivering security updates as a requirement, and completing applicable conformity assessments before placing products on the EU market and affixing a CE mark. SBOMs and ongoing component traceability are expected to be mandatory parts of compliance.
# What manufacturers should do now
- Ensure incident response and vulnerability-handling processes can produce an initial report within 24 hours and a 72-hour follow-up.
- Maintain current inventories or SBOM-like records and update them through a product's lifecycle so affected components and dependencies can be identified quickly.
- Identify the coordinating CSIRT under the CRA and register with ENISA's Single Reporting Platform.
- Prepare user-notification procedures that communicate corrections and mitigations without undue delay.
# Bottom line
The CRA's reporting clock shifts urgency into manufacturers' day-to-day operations: rapid internal discovery and prepared, traceable inventories of software and components are now prerequisites to meet the new reporting deadlines.