Kilde › Guides › CRA › The CRA 72-hour notification: what sta…

The CRA 72-hour notification: what stage two must contain

Current to 26 August 2026 · updates land in the changelog.

Seventy-two hours after awareness, the CRA's second reporting stage falls due. Where the 24-hour early warning merely alerts, the 72-hour notification carries substance — and its required content differs by track.

Vulnerability track

For an actively exploited vulnerability, the 72-hour notification sets out general information about the product concerned, the general nature of the exploit and of the vulnerability, and the corrective or mitigating measures taken — and those available to users. This is the stage where “we are aware and investigating” must become “here is what it is and what to do about it”, at least in outline.

Incident track

For a severe incident impacting the product's security, the 72-hour notification covers the nature of the incident, an initial assessment, and any corrective or mitigating measures taken or available. The definition of what qualifies as a severe incident — data-security impact or the introduction or execution of malicious code — is covered in the triggers guide.

How the platform handles it

On the ENISA platform's published mechanics (subject to change), the 72-hour submission copies or updates the 24-hour fields, and the substantive fields — nature of the vulnerability, nature of the exploit, corrective and mitigating measures — become mandatory at this stage. After the 72-hour notification, the remaining stage is the final report, whose deadline works differently on each track.

Why preparation beats drafting on the day

Seventy-two hours is a short window to characterise an exploit, assess impact and describe mitigations while engineering is firefighting. Teams that hold pre-staged notification templates with the mandatory fields mapped — plus a decided routing (which CSIRT, which platform seats) — spend the window on facts, not on formatting.

Related guides

Quick answers

What must the CRA 72-hour notification contain for a vulnerability?
General information about the product, the general nature of the exploit and the vulnerability, and the corrective or mitigating measures taken and available to users.
What must it contain for a severe incident?
The nature of the incident, an initial assessment, and corrective or mitigating measures taken or available.
Does the 72-hour notification replace the early warning?
No — it builds on it. The staged duty is 24-hour early warning, then 72-hour notification, then a final report.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com