Kilde › Guides › CRA › The CRA 24-hour early warning: what go…
Current to 26 August 2026 · updates land in the changelog.
From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements, or of a severe incident having an impact on the product's security, has 24 hours to file an early warning. That is the first stage of the Cyber Resilience Act's staged reporting duty under Article 14 — early warning within 24 hours, a fuller notification within 72 hours, then a final report.
The trigger is awareness. For the vulnerability track that means awareness of an actively exploited vulnerability — a defined term, narrower than knowing about a vulnerability that could be exploited. For the incident track it means awareness of a severe incident having an impact on the security of the product, also a defined term (Article 14(5)). Which track you are on decides what the later stages must contain, so the triage call is part of the first 24 hours.
The early warning is deliberately thin — it exists to alert, not to analyse. On the vulnerability track it should indicate the Member States on whose market the product is made available, where that information is available. On the incident track it additionally states whether the incident is suspected to be caused by unlawful or malicious acts, and the Member States affected.
On the ENISA reporting platform's published field matrix (as at our verification date, and marked by ENISA as subject to change), the 24-hour submission asks for: notification type (vulnerability or incident), the reporting level, the reporter, the manufacturer's name, the product, a title, and — for incidents — the suspected-unlawful-or-malicious flag.
Two recipients, simultaneously: the CSIRT designated as coordinator in the Member State of the manufacturer's main establishment — the place where cybersecurity decisions for the product are predominantly taken — and ENISA, via the single reporting platform of Article 16. Which CSIRT a non-EU manufacturer routes to follows the cascade in Article 14(7).
The duty is not limited to products shipped after the CRA fully applies: by Article 69(3), the reporting obligation covers the whole in-scope installed base — products placed on the market before 11 December 2027 included. A product last updated years ago can still put you on a 24-hour clock in September 2026.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com