Kilde › Guides › CRA › The CRA 72-hour notification: what sta…
Current to 26 August 2026 · updates land in the changelog.
Seventy-two hours after awareness, the CRA's second reporting stage falls due. Where the 24-hour early warning merely alerts, the 72-hour notification carries substance — and its required content differs by track.
For an actively exploited vulnerability, the 72-hour notification sets out general information about the product concerned, the general nature of the exploit and of the vulnerability, and the corrective or mitigating measures taken — and those available to users. This is the stage where “we are aware and investigating” must become “here is what it is and what to do about it”, at least in outline.
For a severe incident impacting the product's security, the 72-hour notification covers the nature of the incident, an initial assessment, and any corrective or mitigating measures taken or available. The definition of what qualifies as a severe incident — data-security impact or the introduction or execution of malicious code — is covered in the triggers guide.
On the ENISA platform's published mechanics (subject to change), the 72-hour submission copies or updates the 24-hour fields, and the substantive fields — nature of the vulnerability, nature of the exploit, corrective and mitigating measures — become mandatory at this stage. After the 72-hour notification, the remaining stage is the final report, whose deadline works differently on each track.
Seventy-two hours is a short window to characterise an exploit, assess impact and describe mitigations while engineering is firefighting. Teams that hold pre-staged notification templates with the mandatory fields mapped — plus a decided routing (which CSIRT, which platform seats) — spend the window on facts, not on formatting.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com