CRA Vulnerability Reporting is Now Operational
Since 11 September 2026, an important part of the EU Cyber Resilience Act (CRA) has become operational. Manufacturers of products with digital elements are now required to report:
- actively exploited vulnerabilities; and
- severe incidents affecting the security of their products.
These are no longer future requirements. The CRA reporting obligations are now applicable, more than a year before the main CRA product-security requirements become applicable on 11 December 2027.
For manufacturers of industrial automation, railway, embedded and other OT products, this marks an important transition: CRA readiness has moved from preparation to operation.
Strict reporting deadlines
The CRA establishes a staged reporting process.
Manufacturers must submit an early warning within 24 hours after becoming aware of an actively exploited vulnerability or severe incident. A more complete notification must follow within 72 hours.
For an actively exploited vulnerability, the final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month of the 72-hour notification.
Mandatory notifications are submitted through the CRA Single Reporting Platform (SRP) operated by the European Union Agency for Cybersecurity, ENISA.
The reporting obligations apply to products with digital elements falling within the scope of the CRA, including relevant products that were already made available on the EU market before 11 December 2027.
A documented process is no longer enough
Many manufacturers already have vulnerability-management procedures, security policies, ticketing systems or Product Security Incident Response Team (PSIRT) processes.
The CRA adds another dimension: the organisation must be capable of executing the process within legally defined time limits.
An operational reporting process should therefore be able to:
- detect and assess potential vulnerabilities and security incidents;
- establish and record when the manufacturer became aware of the event;
- determine whether the CRA reporting criteria are fulfilled;
- escalate the case to authorised decision-makers;
- prepare and submit the required notifications within the applicable deadlines;
- coordinate corrective and mitigating measures;
- track the subsequent final report; and
- retain consistent and auditable evidence of the complete process.
One particularly important element is the awareness timestamp. The 24-hour reporting period begins when the manufacturer becomes aware of the reportable event. Organisations therefore need a defined mechanism for establishing, recording and preserving this point in time.
IEC 62443 provides a foundation — but it is not the complete answer
For industrial and OT manufacturers, IEC 62443 provides an important basis for secure product development and vulnerability management.
IEC 62443-4-1, for example, addresses secure development lifecycle processes, including security issue management, vulnerability handling and security updates.
However, implementing or obtaining certification against IEC 62443 does not by itself demonstrate fulfilment of all CRA reporting obligations.
CRA readiness additionally requires organisations to determine whether events meet the applicable reporting criteria, meet statutory deadlines and maintain consistency between information held across different sources such as:
- PSIRT and vulnerability records;
- issue and defect tracking systems;
- product and version information;
- SBOM and component information;
- customer communications;
- security advisories;
- corrective actions; and
- information submitted through the CRA Single Reporting Platform.
Clear organisational responsibility is equally important. Reporting authority, escalation paths and backup arrangements should be established so that regulatory reporting does not depend on the availability of one individual.
How innotec can support CRA readiness
For manufacturers, CRA implementation is not only a legal interpretation exercise. It requires regulatory requirements to be translated into practical engineering and organisational processes.
At innotec, cybersecurity consulting combines regulatory and standards expertise with an engineering-oriented approach, particularly for embedded, industrial, railway and safety-related systems.
Support can include, depending on the organisation and product:
- CRA gap analysis and readiness assessment;
- analysis of existing vulnerability-management and PSIRT processes;
- alignment of CRA activities with existing IEC 62443 processes;
- development or review of vulnerability-handling and reporting workflows;
- definition of responsibilities, escalation paths and reporting interfaces;
- review of cybersecurity evidence and traceability;
- cybersecurity risk assessment and security-by-design activities;
- preparation for cybersecurity and conformity assessments;
- CRA reporting exercises and process walkthroughs; and
- tailored training and workshops for engineering, cybersecurity and management teams.
The objective is not to create another isolated compliance process. Where possible, CRA activities should build upon existing product-development, cybersecurity, quality and safety processes while adding the elements needed to satisfy the new regulatory obligations.
From CRA preparation to CRA operation
In summary, the start of mandatory vulnerability and incident reporting on 11 September 2026 represents an important milestone in CRA implementation.
For manufacturers, the relevant question has therefore changed.
It is no longer simply:
“Do we have a vulnerability-handling procedure?”
It is increasingly:
“Can our organisation identify a reportable event, make the necessary decisions, submit the required information within 24 and 72 hours, and demonstrate afterwards exactly what happened?”
That is the difference between having a documented process and having an operational CRA reporting capability.
For organisations assessing their current CRA readiness, innotec can support the transition from regulatory requirements to practical, traceable and operational cybersecurity processes.
Further information on the reporting obligations is available from the European Commission’s CRA reporting guidance and the ENISA CRA Single Reporting Platform resources.
