What are the deadlines for reporting?

The reporting process starts when a manufacturer or open-source steward becomes aware of an actively exploited vulnerability or severe incident.

‘Actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner (CRA definition).

‘Incident having an impact on the security of the product with digital elements’ means an incident that negatively affects (or is capable of negatively affecting) the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions (CRA definition).

Manufacturers and, once applicable, open-source software stewards must adhere to the following reporting deadlines:

© 2026 European Union Agency for Cybersecurity (ENISA) • ENISA legal notice • "All you need to know about the CRA SRP" •
Disclaimer

Disclaimer: This FAQ is subject to the legal notice published on ENISA's website. Its content was extracted from ENISA's web page when this website was built; please check the original page for accuracy.