Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

EU CRA 24-hour reporting: is your detection-to-disclosure workflow ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: The EU Cyber Resilience Act’s September 2026 reporting obligation turns vulnerability disclosure into a 24-hour operational workflow, with early warning to ENISA and CSIRTs, full notification in 72 hours, and final reporting within 14 days, according to Cycode. The real problem is not paperwork but the detection, ownership, and evidence chain needed to file on time.

NHIMG editorial — based on content published by Cycode: Are You Prepared for 24-Hour EU CRA Vulnerability Reporting in September? Accelerate Your Readiness with Cycode

By the numbers:

  • Cycode says manufacturers must submit an early warning to ENISA and the relevant CSIRT within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
  • Cycode says a full notification is due within 72 hours of awareness, with a final report required within 14 days of a corrective measure or one month for severe incidents.
  • Cycode says the EU Cyber Resilience Act can impose maximum fines of up to €15 million or 2.5% of global turnover, whichever is higher, for serious breaches.

Questions worth separating out

Q: What fails when organisations do not have a CRA reporting workflow in place?

A: The failure mode is not simply late paperwork.

Q: Why does the EU Cyber Resilience Act force teams to rethink vulnerability management timing?

A: Because the CRA measures response from awareness, not from final forensic certainty.

Q: How do security teams know if disclosure review controls are working?

A: They should look for rejection of inconsistent submissions, escalation of ambiguous cases, and independent verification of the reporting organisation before publication.

Practitioner guidance

  • Define a named reporting chain Assign the primary reporter, backup reporter, decision-maker, and legal approver for CRA notifications, then test whether the chain still works when the first choice is unavailable.
  • Measure your detection-to-disclosure time Run timed exercises from first credible exploitation signal to filed notification, and record where time is lost across triage, ownership lookup, and sign-off.
  • Build product-level scope mapping Map repositories, dependencies, containers, AI components, and customer impact back to each in-scope product so notification scoping does not depend on manual reconstruction.

What's in the full article

Cycode's full article covers the operational detail this post intentionally leaves for the source:

  • A four-month readiness plan broken into inventory, detection, workflow, and drill phases
  • Specific examples of what belongs in the 24-hour, 72-hour, and final report packets
  • Cycode's CRA dashboard and Context Intelligence Graph workflow for mapping findings to products
  • Practical self-assessment questions for security, product, and legal stakeholders

👉 Read Cycode's readiness guide for EU CRA vulnerability reporting →

EU CRA 24-hour reporting: is your detection-to-disclosure workflow ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Detection-to-disclosure is becoming a first-class governance control. The CRA’s 24-hour obligation means organisations are no longer judged only on whether they patched, but on how quickly they can move from awareness to authorised disclosure. That shifts attention from static compliance artefacts to operational decision speed, evidence integrity, and ownership clarity. For identity and security teams, the practical consequence is that reporting workflow design now belongs in the control model, not just the runbook.

A question worth separating out:

Q: Who is accountable when a CRA reporting deadline is missed?

A: Accountability usually falls across product security, engineering leadership, and the manufacturer that places the product on the EU market. The regulation shifts responsibility away from the end user and onto the party shipping the software or device. That means governance must define who detects, who validates, who approves, and who signs the notification.

👉 Read our full editorial: EU CRA 24-hour vulnerability reporting exposes detection-to-disclosure gaps



   
ReplyQuote
Share: