EU Cyber Resilience Act Reporting Starts 11 September: A 24-Hour Readiness Checklist

The first Cyber Resilience Act reporting duties begin on 11 September 2026. Manufacturers need a working decision and notification process now.

By dotSuper Research DeskPublished Sep 10, 2026Reviewed Sep 10, 20268 min read
EU Cyber Resilience Act Reporting Starts 11 September: A 24-Hour Readiness Checklist
Image: dotSuper original visual
Daily briefingPrimary regulatory guidance from the European Commission, ENISA, and Ireland’s NCSCUpdated Sep 10, 2026

/ THE SHORT ANSWER

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the EU Single Reporting Platform. The first early warning can be due within 24 hours, so ownership, triage, evidence preservation, and reporting access must already be operational.

Key takeaways
  • 01Reporting duties begin on 11 September 2026.
  • 02An early warning can be required within 24 hours and a fuller notification within 72 hours.
  • 03The reporting trigger depends on active exploitation or a severe product-security incident.
  • 04Teams need a documented cross-functional decision process before an incident occurs.

/ dotSuper point of view

The immediate CRA requirement is an incident-reporting operating process, not a last-minute paperwork exercise or a blanket vulnerability-scanning deadline.

What starts on 11 September

The European Commission states that manufacturers must begin reporting actively exploited vulnerabilities and severe incidents affecting products with digital elements on 11 September 2026. Reporting runs through the Single Reporting Platform established by ENISA.

The obligation arrives before the CRA’s broader product requirements apply in December 2027. Companies should therefore avoid treating the September date as the deadline for every technical control in the regulation.

  • Early warning within 24 hours of awareness
  • Full notification within 72 hours
  • Final report after corrective action for an exploited vulnerability
  • Final report within one month for a severe incident

Build the reporting decision path

A credible signal can arrive through vulnerability disclosure, customer support, threat intelligence, a supplier, or an internal security alert. The organization needs one intake path and a named group able to determine whether the legal trigger is met.

Document when awareness begins, what evidence was available, who made the decision, and why the event was or was not reportable. That record supports consistent decisions under time pressure.

  • Identify the legal manufacturer for each EU product
  • Map products and versions to owners
  • Create a 24-hour legal and security escalation route
  • Pre-authorize access to the reporting platform

Prepare the evidence package

The first notice can be brief, but speed cannot come from guessing. Preserve affected versions, exploitation indicators, timelines, observed impact, mitigations, and contact details in a structured incident record.

Connect product security, incident response, engineering, legal, communications, and customer support. Each team should know what evidence it owns and who can approve an external notification.

  • Product name, version, and EU market footprint
  • Known exploitation or incident evidence
  • Impact and affected users or systems
  • Containment, remediation, and disclosure status

What this page cannot conclude

  • 01This article is operational guidance, not legal advice.
  • 02Whether an event is reportable depends on the facts, product role, and applicable law.
  • 03Organizations should use the latest Commission, ENISA, and national CSIRT guidance.

Sources

  1. 01Cyber Resilience Act reporting obligationsEuropean Commission · accessed Sep 10, 2026
  2. 02Single Reporting PlatformENISA · accessed Sep 10, 2026
  3. 03Cyber Resilience Act reporting obligationsNational Cyber Security Centre Ireland · accessed Sep 10, 2026

Our editorial standard · Found an error? Send a correction with its source.

/ CITE OR SHARE THIS GUIDE

Make the evidence easy to verify.

When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.

Suggested citation

dotSuper Research Desk. (September 10, 2026). EU Cyber Resilience Act Reporting Starts 11 September: A 24-Hour Readiness Checklist. dotSuper. https://dotsuper.net/feeds/daily-briefing/2026-09-10-eu-cyber-resilience-act-reporting-deadline

Share on LinkedIn
MAP THE DATA BEFORE PATCHING THE SCREENEU Cyber Resilience Act Reporting Starts 11 September: A 24-Hour Readiness Checklist

/ APPLY THE THINKING

Map your CRA reporting workflow

dotSuper can help your team map the workflow, identify exposure points, define ownership and scope the smallest useful remediation sprint.

Question for the working sessionWhat must manufacturers do when Cyber Resilience Act reporting starts?

/ Topic-led working session · EU Cyber Resilience Act Reporting Starts 11 September: A 24-Hour Readiness Checklist

Turn this question\ninto a useful first move.

Bring how this question currently shows up in your business: “What must manufacturers do when Cyber Resilience Act reporting starts?” We’ll test the page’s evidence against your context and define the smallest useful next move.

Live availability from ceo@dotsuper.net Your time zone · Local time
  1. 01Bring the contextWhere this issue shows up in the work.
  2. 02Test the relevanceUse the evidence against your reality.
  3. 03Choose the next moveOne accountable action, clearly owned.
Live availability
  1. Date
  2. Time
  3. Booked

Syncing live times