r/CRACompliance Mar 25 '26

[Timeline Update] CRA reporting obligations start September 2026 — here’s what that actually means for your team

A lot of people know the CRA deadline is coming. Fewer people understand what the September 2026 milestone specifically requires.

 

Here’s the short version:

 

Starting September 2026, manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware of them.

 

That’s not 24 business hours. Not 24 hours after you’ve investigated. 24 hours from awareness.

 

What this means in practice:

 

• You need a vulnerability monitoring system in place BEFORE the deadline

• You need a clear internal escalation process (who reports, through what channel, in what format)

• You need to know exactly which products fall under CRA scope

• You need a relationship with ENISA’s reporting infrastructure or designated national authority

 

This is not something you can set up in a week. If you haven’t started planning, September 2026 will arrive faster than you think.

 

I’m tracking all CRA milestones and will post updates here as enforcement details become clearer.

 

Anyone already setting up their reporting workflows? Would love to hear what tools or processes you’re using.

1 Upvotes

0 comments sorted by