The EU Cyber Resilience Act (CRA) has entered its operational reporting-obligation phase, requiring covered manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents. Manufacturers must issue an early warning within 24 hours, submit a notification including a preliminary assessment within 72 hours, and provide final follow-up reports according to timelines that depend on the event type.
ENISA launched the Single Reporting Platform (SRP) alongside the new obligations, providing a single channel that routes reports to ENISA and the relevant national CSIRT. The CRA entered into force in December 2024 and is due for full application in December 2027; implementation work still includes a planned fourth-quarter delegated act on whether the EU Common Criteria cybersecurity-certification scheme creates a presumption of CRA conformity.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
A delegated act was issued describing exceptional circumstances in which a national CSIRT may delay wider sharing of a CRA report, including when disclosure could enable exploitation or interfere with near-complete mitigation.
The EU Cyber Resilience Act (CRA) entered into force, establishing cybersecurity requirements for products with digital elements.
CRA-covered manufacturers became required to report actively exploited vulnerabilities and severe incidents, including a 24-hour early warning and 72-hour notification. ENISA publicly launched the Single Reporting Platform, which routes a single manufacturer report to ENISA and the relevant national CSIRT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.