Recently, the European Commission officially released the document (C(2026) 778 final), announcing that the RED cybersecurity authorization regulation ((EU) 2022/30) will be abolished as of December 11, 2027, and the Network Resilience Act (CRA) will take over completely. Among them, the core obligations such as vulnerability reporting will be mandatory and implemented first in September 2026. For enterprises exporting to the EU, this is a mandatory requirement regardless of product type, and the violators may face a maximum fine of 2.5% of their global turnover.
This article will deeply analyze the core rules, reporting deadlines, and practical procedures for vulnerability management and disclosure under the CRA framework, helping you quickly implement compliance.
I. Vulnerability Reporting Requirements
The CRA has set strict compliance requirements for the entire product lifecycle. The core regulations regarding vulnerability reporting are as follows:
● Report vulnerabilities and incidents to the national CSIRT as soon as they are discovered and actively exploited by attackers.
● Information distribution across borders is carried out through the EU's unified platform, synchronizing risks with other member states to prevent the spread of vulnerabilities across Europe.
● Coordinate vulnerability disclosure to guide enterprises to follow the "collaborative vulnerability disclosure" process to avoid the public release of information causing greater harm.
● Connect with market supervision to synchronize risk information with regulatory agencies to support compliance checks and penalties.
II. Which Vulnerabilities Must Be Reported? Which Ones Don't Need to Be Reported?
According to CRA Article 14, Paragraph 1, once a manufacturer becomes aware of a vulnerability that has been actually exploited in the product, they must report it through the unified reporting platform of ENISA (European Network and Information Security Agency). The following situations must be mandatory to report:
● Vulnerabilities with public POCs/attack tools that have been maliciously exploited.
● Vulnerabilities disclosed by the technical community and with evidence of being attacked by hackers.
● 0-day vulnerabilities discovered by the manufacturer and confirmed to have been exploited.
● Vulnerabilities discovered in security investigations that have led to serious security incidents.
Unexploited vulnerabilities do not require reporting. The following situations do not need to be reported (routine self-check and repair are sufficient):
● Vulnerabilities discovered through scanning but without actual exploitation conditions.
● Ordinary/low-risk vulnerabilities in the SRC (Vulnerability Reward Scheme) program.
● Internal research and potential vulnerabilities that have not been exploited.
● Business logic defects (without remote exploitation possibility).
III. Reporting Process and Deadline
All outbound enterprises need to establish a security incident response team (PSIRT) and a vulnerability receiving channel, and require enterprises to report exploited vulnerabilities / serious incidents after discovery:
● Within 24 hours: Submit an early warning to ENISA;
● Within 72 hours: Submit a detailed report (including mitigation measures);
● Within 14 days: Submit a final repair report.
IV. The "24-hour Life-Saving Line": How Can Enterprises Quickly Complete Vulnerability Reporting?
According to CRA Article 14, Article 16, the core mechanism of vulnerability reporting is: Through the "CRA Unified Reporting Platform" (CRA Single Reporting Platform, abbreviated as CRA-SRP) built by ENISA, one report is submitted, and the system will automatically send the notification to the corresponding national CSIRT and ENISA. This platform is expected to be launched in September 2026.
Before this, enterprises need to establish the corresponding reporting mechanism:
1. Confirm your EU authorized representative and the corresponding national CSIRT will be automatically matched by the reporting platform.
2. Review whether the product is within the scope of CRA, including networked hardware, software, IoT, and smart devices.
3. Build a vulnerability monitoring and reporting process to ensure that the warning can be triggered within 24 hours.
4. The official launch of the unified platform's main entry point will be announced by ENISA before September 2026.
If the above preparations are not completed on time, once a vulnerability is exploited and the enterprise fails to report it within 24 hours after September 2026, it may trigger a huge fine of up to 150 million euros or 2.5% of global turnover (whichever is higher).
Regarding the CRA Act:
The Cyber Resilience Act (Cyber Resilience Act, abbreviated as CRA, regulation number (EU) 2024/2847) is a mandatory cybersecurity regulation officially effective in the EU on December 10, 2024. It aims to set a unified security standard for all "products with digital elements (PDEs)" entering the EU market. Its core logic is to shift the security responsibility from consumers to manufacturers: requiring that products have "cyber resilience" throughout their entire lifecycle from design, development to retirement, to prevent security vulnerabilities at the source and completely change the past industry status quo of "emphasizing functionality, neglecting security".
The coverage of CRA is very extensive. As long as the product contains software and hardware and can be directly or indirectly connected to the network, regardless of whether the enterprise headquarters is in the EU, it must comply.
● Hardware products: smart phones, laptops, smart home devices, smart watches, connected toys, microprocessors, firewalls, smart meter gateways, etc.
● Software products: operating systems, mobile apps, accounting software, computer games, background services, library files, etc.
● Embedded and IoT devices: embedded components such as MCU/CPU/SoC/ECU/Tbox, and connected industrial equipment, etc.
● Exceptional exemptions: the following products are not subject to CRA - industries covered by specific regulations (medical devices, automotive and vehicle components, aviation equipment, navigation equipment, defense and national security products), non-commercial open-source software, pure SaaS products (but need to be managed under the NIS2 directive).
E-You Recommendation:
With less than half a year until September 2026, if your product falls under the jurisdiction of CRA, please start the internal assessment and preparation work immediately. We will also continuously update key information such as the latest CRA policies, the official unified reporting entry for vulnerabilities, and compliance guidelines for high-risk products.
E-You Testing Group is a professional third-party testing institution with CNAS and CMA qualifications, with strong technical strength and rich testing experience. We can provide professional qualification assessment and compliance support services based on CRA requirements, helping enterprises efficiently complete compliance planning. Welcome to consult E-You and have in-depth discussions and exchanges~