SecurityNews & Analysis

EU CRA September 11 Deadline: What Developers Must Do Now

EU Cyber Resilience Act compliance deadline illustration with EU flag, digital padlock, and 24-hour warning timer

Ten days. That is how long you have before the EU Cyber Resilience Act’s mandatory vulnerability reporting obligation goes live on September 11, 2026. Article 14 requires any company placing software products on the EU market to report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware of them. Miss that window and you are looking at fines up to €15 million or 2.5% of global annual turnover. Here is exactly what you need to do before the clock runs out.

The Three-Stage Reporting Chain

The moment you become aware of an actively exploited vulnerability or a severe incident affecting one of your products, the clock starts. There is no grace period. The CRA defines “actively exploited” as confirmed attack activity in the wild — not theoretical risk. A “severe incident” covers anything that compromises a product’s ability to protect sensitive data or results in malicious code executing in a user’s system.

From that moment, you have three obligations:

  • 24 hours: Submit an early warning to ENISA and your national CSIRT via the Single Reporting Platform (SRP). It does not need to be a full report — it needs to confirm you know about the issue and classify it. But it must go out within 24 hours.
  • 72 hours: File a detailed notification with technical specifics, an initial impact assessment, and a description of any corrective measures in progress.
  • 14 days after a patch is available: Submit a final report including root cause analysis, a full account of corrective measures implemented, and preventive actions added to your process.

To put this in perspective: GDPR breach notification gives you 72 hours for the initial report. Article 14 requires an early warning in half that time. If your incident response runbook does not already include this chain, it is dangerously out of date. The full reporting requirements are documented at cyberresilienceact.eu.

Register on the ENISA SRP Before September 11

The ENISA Single Reporting Platform is the mandatory submission channel for all Article 14 reports. It is a single-submission system — you file once, and ENISA routes the notification to the correct national CSIRT for your reference country (the EU member state where your company is established or where your EU representative operates).

The platform opens on September 11. If you have not registered before that date, you cannot file a report when you need to. Registration requires an EU Login account. Steps to take this week:

  • Monitor the ENISA SRP page for the registration launch announcement
  • Identify the individuals at your organization authorized to file CRA reports
  • Document credentials in a secure shared location — not on one person’s device
  • Know your reference country in the EU
  • Run a test submission when the platform opens, before a real incident forces you to learn the interface under pressure

If you need help before go-live, ENISA’s helpdesk is at cra-srp-helpdesk@enisa.europa.eu.

More Organizations Are in Scope Than They Think

Two assumptions are dangerously wrong. First: “We are a US company, this does not apply to us.” Article 14 applies to any manufacturer whose products are placed on the EU market, regardless of where the company is headquartered. If you sell software in Europe, you are in scope.

Second: “We ship open source, so we are exempt.” Only truly non-commercial open source — volunteer projects with no revenue model — gets a clear exemption. The moment your company commercially distributes or monetizes software built on open source, you are a manufacturer under the CRA. Organizations classified as “open source stewards” — foundations or companies providing systematic support to commercial OSS — carry lighter obligations but are not exempt.

A third scope issue catches teams off guard: legacy products and end-of-life dependencies. If your product is still installed in a customer’s environment, you are responsible for reporting actively exploited vulnerabilities in it — even if you shipped it years ago, even if it contains a component that has since reached end-of-life. EOL dependencies with known exploits are no longer a quiet technical debt issue. They are a compliance liability.

What Happens If You Miss a Deadline

Non-compliance with Article 14 reporting obligations carries fines of up to €15 million or 2.5% of global annual turnover, whichever is higher. Submitting false or misleading information brings separate penalties: up to €5 million or 1% of global turnover. Market surveillance authorities can also issue product withdrawal orders and, in serious cases, mandate recalls. The European Commission’s official CRA reporting guidance lays out the full enforcement framework.

What You Do Not Need to Do by September 11

Full CRA compliance — CE marking, conformity assessments, SBOM submission — is not required until December 11, 2027. The only obligation going live on September 11 is Article 14 reporting. That is still a significant operational requirement, but it is not the full weight of the regulation. Use the next 15 months to build the SBOM infrastructure and vulnerability management processes that will underpin the rest of your compliance program.

What to Do This Week

  • Audit which of your products are sold or distributed in the EU market, including legacy versions still in customer use
  • Check your dependencies for known EOL components with active CVEs
  • Register on the ENISA SRP as soon as the platform opens this week
  • Add the 24h/72h/14-day reporting chain to your incident response runbook
  • Designate who at your organization is authorized to file Article 14 reports
  • Identify your reference country in the EU

The regulation is not new. The enforcement is. September 11 is the line between preparation and penalty.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:Security