← All CRA guides

The 24-hour reporting obligation

From 11 Sept 2026: actively exploited vulnerabilities must be reported to ENISA fast.

What applies from September 2026?

If a vulnerability in your product is actively exploited (or a severe security incident occurs), you must submit an early warning to ENISA and the responsible national CSIRT within 24 hours, including for products already shipped and in the field.

The deadline cascade

Early warning within 24 hours, full notification within 72 hours, final report within 14 days of a fix (or one month after an incident). KONFORMA detects actively exploited vulnerabilities automatically (via CISA KEV) and prepares a pre-filled draft.

Who submits the report?

You do, as the manufacturer, always. KONFORMA prepares the draft but never submits anything on your behalf; sign-off and responsibility stay with you.

Put it into practice, instead of just reading about it.

KONFORMA walks you from the software inventory through monitoring to the Declaration of Conformity, self-service, per release, starting free.