Does the reporting obligation also cover products placed on the market before 2026?
Yes. From 11 September 2026, the Article 14 obligation applies product-based — including products already on the market. The remaining CRA obligations, such as CE marking, apply from 11 December 2027.
When does the 24-hour deadline start?
Upon awareness (“becoming aware”): as soon as your company learns of the active exploitation or the severe incident. Not upon remediation, and not after internal sign-off — which is why awareness triggers and the reporting process must be defined and documented in advance.
What exactly does “actively exploited” mean?
There is reliable evidence that an attacker exploited the vulnerability without the system owner's consent, or attempted to — whether the attack succeeded is irrelevant (Art. 3(42) CRA). A credible external report, for instance from a CSIRT or a customer, can start the clock.
Do I have to report if no damage has occurred yet?
For severe incidents, potential is enough: even if the incident is merely capable of affecting the product's ability to protect data and functions, or could enable execution of malicious code, it is reportable (Art. 14(5)). When in doubt: report — a notification is not an admission of fault.
Is there an API for automated reporting?
Not at launch. According to the ENISA FAQ, the SRP will initially operate without an API — reports are entered manually in the web form. That makes prepared text modules, a field mapping to your internal data and rehearsed procedures all the more important.
Which CSIRT is competent for us?
In principle, the CSIRT of the member state of your main establishment — where the essential cybersecurity decisions for your products are taken (Art. 14(7)). Without an EU establishment, the cascade runs via authorised representative, importer and distributor. In Germany, the BSI is the central point of contact; ENISA publishes the official CSIRT list.
What are the penalties for violating the reporting obligation?
Fines of up to €15 million or 2.5% of worldwide annual turnover — whichever is higher — plus market surveillance measures up to and including recalls. And if you fail to inform impacted users yourself, the CSIRT can do it for you — without your tone of voice.