# The EU Cyber Resilience Act's first reporting deadline is here

- Author: Michael Mikus (https://mikus.io/about/)
- Published: 2026-09-11
- Type: Link
- Link: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- Web page: https://mikus.io/signals/2026-09-11-cra-first-reporting-deadline/

As of today, the CRA's first reporting obligation is live. If a vulnerability in a product you shipped is being actively exploited, the clock is now measured in hours, not weeks.

Once you become aware, the timeline is an early warning within 24 hours, a full notification within 72 hours, and a final report 14 days after a fix is available (one month after the 72-hour mark for a severe incident). Notifications go through ENISA's Single Reporting Platform, which delivers them to the national CSIRT acting as coordinator and to ENISA at the same time.

Hitting those windows is not a paperwork problem. It means knowing which firmware versions include the affected component, and which of your deployed devices last reported running them. For most fleets, that is not a question you can answer by hand in a day.
