Cyber Resilience Act Reporting Deadline Planner
Turn the moment your team became aware of a reportable CRA event into an operational timeline: 24-hour early warning, 72-hour notification, and the applicable final-report deadline.
Classify the event
Select the Article 14 reporting path you are planning.
Set the clock anchors
Use the timestamps that Article 14 actually measures from.
Readiness notes
Keep the planning context beside the countdown.
Operational timeline
What to prepare
CRA reporting obligations begin on 11 September 2026
For manufacturers covered by the Cyber Resilience Act, Article 14 reporting obligations apply from 11 September 2026. The core sequence is an early warning within 24 hours, a fuller notification within 72 hours, and a path-specific final report.
Do not reuse the 72-hour deadline as the severe-incident final-report anchor
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident affecting product security, the final report is due within one month after the Article 14(4)(b) incident notification is actually submitted. If that submission time is unknown, this planner intentionally leaves the final deadline unset.
Read the CRA reporting deadlines guide, or verify the legal text directly in Regulation (EU) 2024/2847 and the European Commission reporting guidance.