CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know
Brief
By Matthew Brady, Senior Security Engineering Manager, Black Duck
As of September 11, 2026, Article 14 of the EU Cyber Resilience Act (CRA) is in force. Manufacturers, importers, and distributors of products with digital elements sold into the EU must notify ENISA or their national CSIRT within 24 hours of learning that a vulnerability is being actively exploited, with a mitigation report due in 72 hours and a full analysis due within two weeks.
This is the first CRA milestone, not the last: broader secure development obligations arrive in December 2027. Organisations that prepared deserve credit, but this deadline is a starting point, and several parts of the requirement are more nuanced than they appear.
