Do I need to report actively exploited vulnerabilities or severe incidents for products placed on the market before the entry into force of the CRA?

Please refer to the European Commission’s “FAQs on the CRA Implementation”, in particular subsection 5.3 on the reporting obligations under Art. 14, which will apply from 11 September 2026 to all products with digital elements falling within the scope of the CRA, including products that were placed on the market before 11 December 2027.

© 2026 European Union Agency for Cybersecurity (ENISA)ENISA legal notice"All you need to know about the CRA SRP"
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.