This document is under active development and has not been finalised.
Skip to content

Chapter 5: Incident Response & Disclosure

5.1 Overview

The Incident Response Framework covers the complete CRA reporting obligations. From 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe security incidents to ENISA or the competent national authority.

REPORTING OBLIGATION FROM 11.09.2026

The reporting obligations pursuant to Art. 14 CRA enter into force on 11 September 2026. From that date, actively exploited vulnerabilities must be reported within 24 hours.

5.2 Reporting Obligations Overview

EventDeadlineRecipientTemplate
Actively exploited vulnerability24h early warningENISA / CSIRTEarly Warning
Vulnerability update72h notificationENISA / CSIRTNotification
Final report14 daysENISA / CSIRTFinal Report
Severe security incident24h early warningENISA / CSIRTIncident Report
User notificationWithout delayAffected usersVulnerability Report

Chapter Structure

SectionTopicCRA Reference
5.1Incident Response Playbook – Escalation levels, phases, checklistsArt. 14, Annex I Part II
5.2Vulnerability Disclosure Policy – CVD per ISO 29147Art. 13(6)
5.3ENISA Reporting Process – Deadlines, procedure, documentationArt. 14(1)-(3)
5.4Communication Plan – Internal/external communication channelsArt. 14(8)

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT