CRA vulnerability and incident reporting obligations now apply
Manufacturers must now notify actively exploited vulnerabilities and severe incidents affecting the security of their products, at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. An early warning is due within 24 hours and a notification within 72 hours; a final report follows.
Affects Manufacturers of products with digital elements on the EU market, including products placed on the market before 11 December 2027 (Article 69(3)).