← Back to news 05.07.2026

Cyber Resilience Act: why the 24-hour reporting duty forces preparation

From 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours, followed by a full notification in 72 hours and a final report in 14 days. The deadlines are not a formality but a test of whether the groundwork is done. What the Cyber Resilience Act really demands and why the real work happens beforehand.

The Cyber Resilience Act is settled law, but the date still ahead for many manufacturers is 11 September 2026. From then on the reporting duties apply: anyone placing a product with digital elements on the market must report actively exploited vulnerabilities and severe incidents. Not eventually, but on a clock that leaves almost no room.

Three deadlines, one narrow window

The reporting chain is staged: an early warning within 24 hours, a full notification within 72 hours, a final report no later than 14 days after a fix is available. The recipients are CSIRT and ENISA via a single platform. Anyone who has lived through a real incident knows: 24 hours pass quickly when you only start searching then.

The deadline is the real test

The point is not the form. 24 hours are enough only if the groundwork is done: within hours you must know which product in which version is affected, which component carries the flaw, who decides and through which channel it is reported. Whoever asks these questions only during the incident has already lost the early warning.

What has to exist beforehand

Three things decide the 24 hours, regardless of the tool: a current picture of your own products and their components, ongoing transparency about known vulnerabilities in them, and a rehearsed reporting process with clear roles. Plus the conformity side, which is not created during the incident: the essential requirements from Annex I, the technical documentation and the declaration of conformity belong before placing on the market, not after.

How isidaten maps this

That is exactly what the CRA module in isidaten is for. It maps the control catalog from Annex I, split into essential cybersecurity requirements and vulnerability-handling requirements, and keeps product profiles, technical documentation and the declaration of conformity in one place. The reporting chain knows the CRA deadlines of 24, 72 and 14. The most important part: the CRA requirements map onto evidence that already arises in other modules, such as vulnerability and asset management. So conformity does not start from zero.

11 September is not a date to postpone. If you want to know how your products stand against the CRA requirements, talk to us.

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.