Regulation (EU) 2024/2847

Could you meet the 24-hour clock?

From 11 September 2026, a manufacturer who becomes aware that a vulnerability in their product is being actively exploited has 24 hours to file an early warning, 72 hours to notify, and 14 days to file a final report. This asks whether you could actually do that, which is a different question from whether the CRA applies to you.

Free, no account, and nothing is stored: answers stay in this tab and disappear when you close it. Each question cites the article it rests on. It is not legal advice, and it is not a certification.

Not sure the CRA reaches your product at all? Check scope first, then come back.

  1. 1

    Is there a named person, with a named backup, accountable for submitting a CRA report?

    Article 14(2), Regulation (EU) 2024/2847

  2. 2

    Can that person be reached, and act, outside working hours?

    Article 14(2)(a), Regulation (EU) 2024/2847

  3. 3

    Have you written down what counts as an "actively exploited" vulnerability in your product?

    Article 14(1), Regulation (EU) 2024/2847

  4. 4

    Would you find out that a vulnerability in your product is being exploited?

    Article 13(8), Regulation (EU) 2024/2847

  5. 5

    Do you have a coordinated vulnerability disclosure policy?

    Article 13(8) and Annex I Part II, Regulation (EU) 2024/2847

  6. 6

    Do you know exactly where the report goes, and has someone tried the route?

    Article 14(2)(a), Regulation (EU) 2024/2847

  7. 7

    Could you assemble the content of an early warning within 24 hours of becoming aware?

    Article 14(2)(a), Regulation (EU) 2024/2847

  8. 8

    Can you notify affected users about the vulnerability and any corrective measures?

    Article 14(8), Regulation (EU) 2024/2847

  9. 9

    Would you be able to show, later, what you knew and when you knew it?

    Article 14(2)(c), Regulation (EU) 2024/2847

Answer the questions above

Nothing is stored and nothing is sent. Answers stay in this tab and disappear when you close it.

The clocks this is about

Article 14(2), running from the moment you become aware of active exploitation.

  • 24 hoursEarly warning notification of an actively exploited vulnerability(Art 14(2)(a), to CSIRT designated as coordinator, and ENISA)
  • 72 hoursVulnerability notification(Art 14(2)(b), to CSIRT designated as coordinator, and ENISA)
  • 14 daysFinal report(Art 14(2)(c), to CSIRT designated as coordinator, and ENISA)

This covers Article 14(2), actively exploited vulnerabilities. Article 14(4), severe incidents, has its own clocks and a final report due within one month; it is not assessed here and Legalithm does not model it yet.

Questions

What does CRA reporting readiness actually mean?
Being able to send an early warning within 24 hours of becoming aware that a vulnerability in your product is being actively exploited, and to follow it with a fuller notification at 72 hours and a final report at 14 days. Readiness is people, a written trigger and a rota, not tooling.
When does the 24-hour clock start?
From the moment you become aware, under Article 14(2). Not from confirmation, not from triage, and not from the next business day. That is the single assumption most likely to be wrong in a plan that otherwise looks complete.
Who do I report a CRA incident to?
The CSIRT designated as coordinator, and ENISA. Both, via the single reporting platform, and the recipient does not change between the 24-hour, 72-hour and 14-day stages.
What is the most common CRA reporting gap?
No named owner and no named backup. It is free to fix, it takes one meeting, and no amount of tooling substitutes for it. This check asks about it first for that reason.