CRA Enforcement Express Unit
Get Audit-Ready for CRA Vulnerability Reporting Deadline
On 11 September 2026, the CRA reporting clock starts. Can your team file within 24 hours?
Most of the Cyber Resilience Act arrives in 2027. One part does not. From 11 September 2026, if you make a product with digital elements available on the EU market, you must report an actively exploited vulnerability or a severe incident to ENISA within 24 hours — and that duty reaches products already on the market. This express kit gets you ready before the clock starts.
Built for software and hardware manufacturers, and the CTOs and security leads who’ll be holding the pager when a report is due. Fast to deploy — an assessment, a strategy session, and a ready-to-use execution pack.





What Changes on 11 September 2026?
The Cyber Resilience Act (CRA) introduces mandatory, strict-liability cybersecurity rules for software and hardware products placed on the EU market. Article 11 takes effect first, imposing immediate notification duties on software vendors:
- The 24-hour clock: You must formally notify the European Union Agency for Cybersecurity (ENISA) and designated national CSIRTs within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
- Mandatory Coordinated Vulnerability Disclosure (CVD): You are legally required to maintain a public, structured channel (such as an RFC 9116
security.txtfile) allowing security researchers to report flaws. - Enterprise procurement screening: European buyers are actively freezing vendor contracts that cannot produce a documented CRA incident response workflow and signed legal proof of CRA readiness.
How It Works: Two Parts
Part 1: Find your gaps
You complete two structured self-assessments and walk the findings through a 30-minute strategy session:
- Vulnerability Management Gap Audit: Line-by-line evaluation of your update mechanism, patch-distribution channels and vulnerability-intake channels against the CRA’s vulnerability-handling requirements (Annex I Part II), the manufacturer’s diligence and support-period duties (Article 13), and the reporting duty (Article 14).
- SBOM Review: An evaluation of your open-source and third-party component tracking, built around one hard question: if a critical vulnerability dropped in a component today, could you identify the affected products fast enough to meet the reporting clock?
- 30-Minute CTO Strategy Session: A direct debrief with an EU tech legal architect to review your findings, sequence the fixes, and confirm how the execution pack closes each gap.
Part 2: Deploy the execution pack
Five ready-to-use technical and legal assets:
Developer Security and Patching Ticket Pack: Nine Markdown tickets ready to import into Jira or GitHub, covering SBOM generation, patch-distribution SLAs, secure update distribution and the Article 14 reporting hook — each mapped to a specific CRA obligation.
ENISA 24-Hour & 72-Hour Incident Response SOP: A step-by-step procedure defining roles, triage triggers and statutory escalation paths for notifying ENISA and the national CSIRT within 24 hours (early warning) and 72 hours (full notification), through ENISA’s Single Reporting Platform.
Pre-Formatted ENISA & CSIRT Intake Forms: Fill-in-the-blank early-warning, notification and final-report templates, with a standing-information block you complete once so your team fills only the event-specific fields while the clock runs.
CVD Policy & security.txt Pack: Ready-to-publish coordinated vulnerability disclosure policy text (with safe-harbour clause) and a repository-ready RFC 9116 security.txt file, satisfying the CRA’s disclosure-policy and reporting-contact requirements (Annex I Part II, points 5–6).
Why This Is the Right Basis, Not a Generic Checklist
The CRA’s vulnerability-handling and SBOM obligations live in Annex I Part II; the manufacturer’s diligence and support-period duties in Article 13; the reporting cadence in Article 14.
Every asset in this kit is built to those provisions, with the relevant legal text quoted in each so your engineers and your lawyer can see exactly what’s being satisfied. Nothing here is grounded in the wrong article, that’s the difference between a kit that survives scrutiny and one that doesn’t.
The September CRA Deadline, Plainly
11 September 2026 is not the full CRA. It’s the reporting obligation — the 24-hour early warning, the 72-hour notification, the final report — landing 15 months ahead of everything else, and applying to products you’ve already shipped.
A team that has rehearsed the procedure files calmly. A team that hasn’t spends the first of its 24 hours working out who’s even allowed to click submit. This kit is the difference between those two teams.
Who This Is For
- Software and hardware manufacturers placing connected products on the EU market.
- CTOs and heads of engineering who own incident response.
- Security leads standing up a coordinated vulnerability disclosure programme.
- Companies whose products are already shipped and in the field — the reporting duty reaches you too.
- Teams who’d rather rehearse the 24-hour procedure now than improvise it during a live exploit.
What’s Included in the Price
Includes twelve months of updates as ENISA’s Single Reporting Platform, the Commission guidance and the harmonised standards develop.
A specialist firm building an incident-response procedure, CVD framework and reporting readiness from scratch will typically run €6,000–15,000. The kit is the same readiness at a fraction of the cost, with a strategy session included so you leave knowing what to do first.
If you need more input from our team, let’s discuss – go ahead and book a scoping call.
What this pack is not (Important)
This is not legal advice, and it’s not a certificate of compliance. It’s an assessment-and-execution kit that your security team and a qualified lawyer should adapt to your platform before you rely on it. The assessments are self-assessments; the strategy session reviews your findings, it doesn’t independently verify your systems.
Submission is always made through ENISA’s official Single Reporting Platform, whose own fields govern. The intake forms prepare your content but don’t replace the submission.
FAQ about CRA Vulnerability Reporting
Does the CRA 11 September 2026 deadline apply to non-EU/UK companies?
Yes. The Cyber Resilience Act applies to any product with digital elements placed on the EU market, regardless of where the developer or vendor is headquartered. Post-Brexit UK firms and US scaleups selling software into the EU must comply with Article 11 reporting duties.
What happens if an actively exploited vulnerability is not reported to ENISA within 24 hours?
Non-compliance with CRA reporting obligations carries statutory administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher—in addition to potential market withdrawal orders for your software.
What is the difference between a 24-hour Early Warning and a 72-hour Notification?
Within 24 Hours: You must submit an “Early Warning” notification to ENISA indicating whether the vulnerability is suspected to be caused by malicious action or has cross-border impact.
Within 72 Hours: You must follow up with a detailed “Vulnerability Notification” containing initial assessment data, severity ratings, and available mitigation steps.
Is an SBOM (Software Bill of Materials) mandatory under the CRA?
Yes. Article 10 of the CRA requires vendors to identify and document vulnerabilities in third-party and open-source components. Our assessment verifies your component inventory workflows and supplies developer tickets to automate SBOM tracking.
Can we attach the Signed CRA Attestation Letter to enterprise sales contracts?
Yes. The Attestation Letter signed by European Compliance Suite explicitly states that your platform maintains an audited Coordinated Vulnerability Disclosure (CVD) policy, ENISA 24-hour notification procedures, and patch management protocols aligned with CRA Article 11.
