Technology explainer
How Does the EU Cyber Resilience Reporting Process Work?
The EU process moves from a rapid warning to a technical notification and final report, while one national cyber-response team coordinates distribution across authorities.
The Cyber Resilience Act creates a staged process for manufacturers to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements in the European Union. The stages balance speed with the practical reality that a company rarely knows every technical detail when an incident is first discovered.
Step one: decide whether the event qualifies
A known vulnerability is not automatically reportable. The active-exploitation route requires reliable evidence that a malicious actor used the weakness without permission. A security incident must meet the Act's severity criteria, including a serious effect on the product's ability to protect the availability, authenticity, integrity or confidentiality of data or functions.
Step two: send an early warning
The first deadline is 24 hours after the manufacturer becomes aware of a qualifying event. This early warning alerts authorities quickly and may contain only the information available at that point. The obligation is based on awareness, so organizations need internal escalation routes that move evidence from engineering and security teams to the people responsible for regulatory reporting.
Step three: provide a fuller notification
Within 72 hours of awareness, the manufacturer supplies general information and an initial assessment. The exact fields depend on whether the report concerns active exploitation or a severe incident. Relevant details can include identifiers, affected products, observed impact, the nature of exploitation and available mitigation.
Step four: complete the final report
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the deadline is one month after the 72-hour notification. This stage records the fuller technical picture and the response taken as the investigation matures.
Why one platform serves many authorities
The manufacturer submits through ENISA's Single Reporting Platform and selects the designated national Computer Security Incident Response Team. The notification is normally made available to ENISA at the same time. The receiving team coordinates distribution to other relevant national teams and market-surveillance authorities, reducing the need for separate submissions across the EU.
What the process does not replace
Reporting is not the same as remediation. A company still has to investigate the event, protect affected users, prepare corrective measures and meet other applicable incident or data-protection obligations. The shared portal improves coordination, but the quality and speed of the technical response determine whether harm is actually reduced.
First appeared in
EU Gives Tech Manufacturers 24 Hours to Flag Active Cyber Exploits