The First CRA Deadline Is Looming: What to Watch For?

The CRA’s first deadline is about reporting incidents and vulnerabilities
(photo by Ignas Kukenys, CC BY 2.0)

The European Union (EU) enacted the Cyber Resilience Act (CRA) in 2024. Its full enforcement will start in December 2027. Before that deadline, however, there is another, earlier deadline: the CRA’s vulnerability and incident reporting obligations will go live on 11 September 2026. Therefore, it is a good time for a small status check on things to watch for.

What is the earlier deadline about? It is about the mandatory reporting of severe incidents and actively exploited vulnerabilities to European public authorities.

Although the CRA’s Article 14(5) tries to clarify what severe incidents are, the article’s wording is so broad that interpretations by vendors are the first thing to watch for. Nevertheless, severe incidents are – as the qualifying adjective hints – something more than “conventional” incidents whose reporting is voluntary. One interpretation is that they are a step in an escalation ladder toward full-fledged cyber security crises rather than mere incidents.

An actively exploited vulnerability is “a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner“, to quote the CRA’s Article 3(42). This definition has two parts. The first is the notion of reliable evidence. To exclude the question about whose evidence, it will again be interesting to see how vendors and public authorities will interpret evidence about exploitation and reliability of it. However, the second part of the definition emphasizes that only unauthorized actions are covered, meaning that penetration testing is excluded. As further clarified in the recently released guidance, a countdown toward the reporting deadlines, which are rather strict, will only start running once a vendor has become aware of active exploitation.

In addition to interpretations, it will be interesting and relevant to observe how the EU’s reformed incident and vulnerability reporting, coordination, and disclosure framework will perform. Today, in mid-2026, vulnerability coordination and disclosure are in a state of flux due to artificial intelligence tools and frontier large language models (LLMs) in particular. While keeping the everlasting hype in mind, frontier LLMs have accelerated the discovery of new vulnerabilities. At the same time, false positives, slop, and outright spam are causing severe problems for vulnerability disclosure. Given these points, in hindsight, the concept of actively exploited vulnerabilities, which resembles a similar concept used in the United States, seems as a strategically wise choice from the European policy-makers. Indeed: the growth rate of actively exploited vulnerabilities has not been rapid despite the overall growth rate of all vulnerabilities disclosed and reported.

Regarding governance and public administration, it is relevant to keep an eye on the functioning of the new single reporting platform for incidents and actively exploited vulnerabilities. It may also remedy some of the potential problems that have been speculated; false positives, over-reporting, under-reporting, and reporting quality have all been perceived as potential problems in this regard.

Analogously, the functioning of the new European Union Vulnerability Database, which was established with the NIS2 directive and which is already online, should be watched for. To put aside questions about meta-data quality and provenance, which are still among the grand challenges in software security, the coordination and reporting by the public authorities of the member states as well as the EU-level coordination and reporting are both something to keep track of. Early probes indicate that only a few European authorities have contributed thus far.