Reviewed 17 August 2026
CRA reporting deadlines: what the 24-hour and 72-hour clocks require
Preparation guidance for a tabletop exercise. It is not legal advice and does not determine whether a real event is reportable.
Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools
The Cyber Resilience Act introduces a staged reporting flow from 11 September 2026. A manufacturer that becomes aware of an actively exploited vulnerability must submit an early warning without undue delay and, in any event, within 24 hours. A severe incident affecting the security of a product with digital elements follows a comparable 24-hour early-warning step. The official Article 14 text and Commission implementation page should control any real decision.
Within 72 hours of awareness, the notification expands. The manufacturer provides available general information about the product, the nature of the exploitation or incident, an initial assessment and measures taken or planned, including mitigation that users can apply. The flow is designed for progressive information, not a perfect incident report at hour one.
The final step differs by event type. For an actively exploited vulnerability, the final report follows after a corrective or mitigating measure is available, within the period specified in Article 14. For a severe incident, the final report follows the 72-hour notification on its separate timetable. Because the exact facts and official platform workflow matter, organisations should rehearse the data owners rather than draft one static document.
A practical clock map
| Stage | Operational question |
|---|---|
| Awareness | Who can declare the time and event type? |
| 24 hours | Who owns the minimum warning and routing facts? |
| 72 hours | Where do product, impact, measures and user advice come from? |
| Final | Who owns root cause/correction, evidence and approval? |
The most common preparation mistake is to give the deadline to the security team while product versions, market availability, customer mitigation and legal approvals remain elsewhere. A tabletop should therefore measure handoffs, not just writing speed.
Frequently asked questions
- When does the 24-hour clock start under the Cyber Resilience Act?
- It starts at awareness. In a tabletop, the practical question is who in your organisation is allowed to declare the awareness time and the event type, because everything downstream is measured from that moment.
- What has to be in the 24-hour early warning?
- The early warning is deliberately short: the event type, that it is an actively exploited vulnerability or a severe incident, and where the product is available. Detail is expected to follow in the 72-hour notification, not at hour one.
- What changes at 72 hours?
- The notification expands to product identification, the nature of the exploitation or incident, an initial assessment of impact and severity, and the measures taken or planned, including mitigation users can apply themselves.
- Is the final report the same for incidents and vulnerabilities?
- No. For an actively exploited vulnerability the final report follows once a corrective or mitigating measure is available; for a severe incident it follows the 72-hour notification on its own timetable. Confirm the exact periods in the official Article 14 text.
- Do these dates apply to us yet?
- CRA reporting obligations start on 11 September 2026, with general application on 11 December 2027. That is why rehearsing now is cheap and rehearsing later is not.