CRA knowledge base

Reporting obligations

Reporting actively exploited vulnerabilities and severe incidents to ENISA/CSIRT.

← Back to the FAQ overview

All questions in this topic

How can a manufacturer become aware of an actively exploited vulnerability or severe incident?

The CRA does not prescribe how, but the duty to notify once aware (Art. 14) – e.g. via own monitoring, reports from security researchers or users.

Source: European Commission · FAQ 5.1 Official EU FAQ (original text)

Does a manufacturer need to report zero-day vulnerabilities?

Reportable are actively exploited vulnerabilities – i.e. those with reliable evidence of actual malicious exploitation (Art. 3(42)), regardless of whether they are publicly known.

Source: European Commission · FAQ 5.2 Official EU FAQ (original text)

Do reporting obligations also apply to products placed on the market before the CRA applies?

Yes. By derogation from the general transition rule, the reporting obligations (Art. 14) also apply to products placed on the market before 11 December 2027 (Art. 69(3)).

Source: European Commission · FAQ 5.3 Official EU FAQ (original text)

If a vulnerability is in a third-party component, must all integrating manufacturers report it?

Each manufacturer notifies an actively exploited vulnerability contained in its product – including where it originates from an integrated third-party component.

Source: European Commission · FAQ 5.4 Official EU FAQ (original text)

Topic blocks

Summarised and translated from the European Commission’s “FAQs on the Cyber Resilience Act” (v1.2, 16 January 2026), licensed under CC BY 4.0. Simplified by Lehner & Szecsey – the original text prevails. Official EU FAQ (original text).