Skip to content
EU Rules Finder
English (Language)

CRA reporting register: deadlines and Single Reporting Platform fields

Article 14 of the Cyber Resilience Act gives you hours, not days. Keep one entry per vulnerability or incident here: the page counts each deadline from the moment you became aware, shows which fields ENISA's Single Reporting Platform asks for at each step, and drafts the notice to your users.

Checked against the sources on 11 October 2026

Your register

Only a file downloaded from this page. It is read in your browser and not uploaded.

Nothing you enter leaves your browser and nothing is stored. Download the register file to keep your work, and open it here again later.

Which CSIRT receives your reports

Choose the first line that applies to you (Article 14(7)), then the Member State it points to.

ENISA: if the wrong CSIRT is selected, the notification may be invalidated and has to be resubmitted to the right one. Settle this before you need to report.

No entries yet. Add a vulnerability or an incident, or open a register file.

What this page does

  • counts the early warning (24 hours) and the notification (72 hours) from the moment you became aware, in your local time and in UTC;
  • counts the final report: 14 days after a corrective or mitigating measure is available for a vulnerability, one month after you submit the notification for an incident;
  • lists the platform's fields with ENISA's numbers, the step that requires each one and its character limit, and copies a step's answers for pasting;
  • shows which CSIRT you report to under Article 14(7), also when you have no establishment in the EU;
  • drafts the notice to users that Article 14(8) asks for, from what you have already filled in.

The platform's own counter currently shows the 72-hour deadline as 48 hours after you submit the early warning, and it has no counter for the final report on a vulnerability (ENISA's questions and answers, 3 October 2026). ENISA says the counters are only aids and the legal deadline stays. This page counts from the moment you became aware, as Article 14 does.

What you report, and what you do not

You report an actively exploited vulnerability in your product: one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission (Article 3(42)). According to the Commission's questions and answers, a vulnerability found in testing or reported by a researcher in good faith, with no evidence of malicious exploitation, is not one. You also report a severe incident having an impact on the security of your product (Article 14(5)). One notification covers one vulnerability or incident, even if you have several branches in the EU.

Fines

Article 64(2) sets fines of up to EUR 15 million or, for an undertaking, up to 2.5% of its worldwide annual turnover, whichever is higher, for not complying with Article 14. Under Article 64(10)(a) those fines do not apply to microenterprises and small enterprises for missing the 24-hour deadline of the early warning; no other deadline is covered. Article 14 has applied since 11 September 2026. Article 64 is not among the provisions that apply early, so it applies from 11 December 2027 (Article 71(2)).

The rules themselves are on the CRA reporting page; whether the Act covers your product at all is on the Cyber Resilience Act page.

This page sends nothing to ENISA: you submit on the Single Reporting Platform yourself. Nothing you enter leaves your browser and nothing is stored, so download the register file to keep your work. ENISA's field list and guidance may change, and the Commission's guidance is not binding. This is not legal advice.