Kilde › Guides › CRA › The CRA 24-hour early warning: what go…

The CRA 24-hour early warning: what goes in it, and when the clock starts

Current to 26 August 2026 · updates land in the changelog.

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements, or of a severe incident having an impact on the product's security, has 24 hours to file an early warning. That is the first stage of the Cyber Resilience Act's staged reporting duty under Article 14 — early warning within 24 hours, a fuller notification within 72 hours, then a final report.

When the clock starts

The trigger is awareness. For the vulnerability track that means awareness of an actively exploited vulnerability — a defined term, narrower than knowing about a vulnerability that could be exploited. For the incident track it means awareness of a severe incident having an impact on the security of the product, also a defined term (Article 14(5)). Which track you are on decides what the later stages must contain, so the triage call is part of the first 24 hours.

What the early warning contains

The early warning is deliberately thin — it exists to alert, not to analyse. On the vulnerability track it should indicate the Member States on whose market the product is made available, where that information is available. On the incident track it additionally states whether the incident is suspected to be caused by unlawful or malicious acts, and the Member States affected.

On the ENISA reporting platform's published field matrix (as at our verification date, and marked by ENISA as subject to change), the 24-hour submission asks for: notification type (vulnerability or incident), the reporting level, the reporter, the manufacturer's name, the product, a title, and — for incidents — the suspected-unlawful-or-malicious flag.

Who receives it

Two recipients, simultaneously: the CSIRT designated as coordinator in the Member State of the manufacturer's main establishment — the place where cybersecurity decisions for the product are predominantly taken — and ENISA, via the single reporting platform of Article 16. Which CSIRT a non-EU manufacturer routes to follows the cascade in Article 14(7).

The part most teams miss

The duty is not limited to products shipped after the CRA fully applies: by Article 69(3), the reporting obligation covers the whole in-scope installed base — products placed on the market before 11 December 2027 included. A product last updated years ago can still put you on a 24-hour clock in September 2026.

Related guides

Quick answers

When does the CRA 24-hour reporting duty start?
11 September 2026. From that date manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident impacting a product's security.
Who must the 24-hour early warning go to?
Simultaneously to the CSIRT designated as coordinator of the Member State of the manufacturer's main establishment and to ENISA, via the single reporting platform.
Is the 24-hour warning a full incident report?
No. It is an alert with minimal content — Member States concerned and, for incidents, the suspected-malicious flag. The substantive detail lands in the 72-hour notification and the final report.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com