CRA knowledge base
Reporting obligations
Reporting actively exploited vulnerabilities and severe incidents to ENISA/CSIRT.
All questions in this topic
How can a manufacturer become aware of an actively exploited vulnerability or severe incident?
The CRA does not prescribe how, but the duty to notify once aware (Art. 14) – e.g. via own monitoring, reports from security researchers or users.
Source: European Commission · FAQ 5.1 Official EU FAQ (original text)
Does a manufacturer need to report zero-day vulnerabilities?
Reportable are actively exploited vulnerabilities – i.e. those with reliable evidence of actual malicious exploitation (Art. 3(42)), regardless of whether they are publicly known.
Source: European Commission · FAQ 5.2 Official EU FAQ (original text)
Do reporting obligations also apply to products placed on the market before the CRA applies?
Yes. By derogation from the general transition rule, the reporting obligations (Art. 14) also apply to products placed on the market before 11 December 2027 (Art. 69(3)).
Source: European Commission · FAQ 5.3 Official EU FAQ (original text)
If a vulnerability is in a third-party component, must all integrating manufacturers report it?
Each manufacturer notifies an actively exploited vulnerability contained in its product – including where it originates from an integrated third-party component.
Source: European Commission · FAQ 5.4 Official EU FAQ (original text)
Topic blocks
- Scope
- Interplay with other EU law
- Important & critical products
- Manufacturer obligations
- Conformity assessment & CE
- Transition period