From 11 September 2026, the first reporting obligations under the EU Cyber Resilience Act become applicable. For manufacturers of products with digital elements, this means being ready not only to identify reportable vulnerabilities and incidents, but also to act within strict deadlines.
11 September 2026 marks an important milestone in the implementation of the Cyber Resilience Act (CRA).
It does not mean that the entire CRA becomes applicable at once. The essential cybersecurity requirements for products will apply from 11 December 2027.
What changes now is the reporting obligation.
From 11 September, manufacturers must report certain actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
And with the first deadline approaching, one practical question is becoming increasingly important:
How do manufacturers actually make a CRA report?
What must manufacturers report?
The CRA reporting obligation focuses on two main situations.
Actively exploited vulnerabilities
An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited the vulnerability without the permission of the system owner.
The distinction is important: not every vulnerability or CVE needs to be reported.
A vulnerability identified through internal security testing, a penetration test, responsible disclosure or a bug bounty programme does not automatically trigger mandatory CRA reporting. There must be reliable evidence of actual malicious exploitation.
The Dutch NCSC reinforces this distinction in its CRA reporting guidance: findings from internal research or pentesting, or vulnerabilities reported through responsible disclosure or bug bounty programmes, do not require mandatory reporting unless there is evidence of exploitation.
Severe incidents affecting product security
Manufacturers must also report severe incidents that affect the security of a product with digital elements.
This includes incidents that negatively affect, or could negatively affect, the product's ability to protect the availability, authenticity, integrity or confidentiality of important data or functions.
Examples can include remote code execution affecting a product or a compromised supply chain with consequences for product security.
24 hours, 72 hours, final report
The reporting process follows a clear timeline, starting from the moment the manufacturer becomes aware of the actively exploited vulnerability or severe incident.
Within 24 hours: an early warning must be submitted. At this stage, manufacturers are not expected to know everything about the case.
Within 72 hours: a more detailed notification follows, including the information available about the nature and impact of the vulnerability or incident and the measures being taken.
A final report must then complete the reporting process in accordance with the applicable CRA deadlines.
This makes internal escalation critical. If several hours are lost simply determining who is responsible for assessing the situation, a significant part of the reporting window may already have disappeared.
How do manufacturers actually report?
At European level, notifications can be submitted through the Single Reporting Platform (SRP) operated by ENISA.
The SRP is the central reporting mechanism created for the CRA and is expected to become available on 11 September 2026.
Through the platform, the manufacturer — or an Assigned Representative acting on its behalf — can submit the notification and select the relevant CSIRT designated as coordinator.
The reporting process follows the same progressive model as the CRA deadlines: manufacturers can start with the information available for the 24-hour early warning and provide additional information through the 72-hour notification and final report.
The practical message is therefore simple:
Do not wait until the investigation is complete before starting the reporting process.
The first notification is designed to be an early warning.
What about national reporting channels? The Netherlands example
Manufacturers should also understand the reporting arrangements available through their national cybersecurity authorities.
The Netherlands provides a useful example.
During a CRA reporting webinar held by the Dutch Ministry of Economic Affairs and the National Cyber Security Centre (NCSC) on 27 August 2026, the authorities explained that manufacturers can report through three channels:
- MijnNCSC, the NCSC's secure cybersecurity portal;
- the reporting form on NCSC.nl; or
- ENISA's Single Reporting Platform.
The Dutch NCSC acts as the national reporting point and coordinator for CRA notifications.
There is also an important distinction regarding registration.
The CRA itself does not require manufacturers to register in advance before they can report. The Dutch NCSC specifically clarifies that no prior CRA registration is required.
Organisations that are also subject to other legislation, such as the Dutch Cyberbeveiligingswet, may have separate registration requirements, but these should not be confused with the CRA reporting obligation.
Manufacturers in other EU Member States should check the arrangements provided by their relevant national CSIRT, as national reporting options may differ.
What should manufacturers do now?
The 24-hour deadline leaves little room to design a reporting process once an incident is already underway.
Before a reportable situation occurs, manufacturers should make sure they:
- know who is responsible for assessing potential CRA notifications;
- define internal thresholds for actively exploited vulnerabilities and severe incidents;
- establish a clear escalation and decision-making path;
- prepare the information and templates required for the different reporting stages;
- understand how vulnerabilities affecting third-party components will be escalated by suppliers; and
- know which reporting channel and CSIRT they will use.
The Dutch NCSC also recommends maintaining visibility into the components contained in products, for example through a Software Bill of Materials (SBOM), and aligning CRA processes with other applicable reporting obligations.
CRA readiness is now operational
The 11 September deadline turns one part of CRA readiness into an immediate operational requirement.
Manufacturers need to know not only what must be reported, but who makes that decision, how quickly it must happen and where the notification must be submitted.
Clear ownership, defined escalation paths and an established reporting process can make the difference between a controlled response and a race against the 24-hour deadline.
At Brightsight, we support manufacturers in understanding and preparing for the cybersecurity and conformity requirements introduced by the Cyber Resilience Act.
From 11 September, CRA readiness also means being ready to act when a real security event occurs.


