Cybersecurity blog header

Reporting exploited vulnerabilities and serious incidents affecting software and hardware is now mandatory

The CRA regulations stipulate that exploited vulnerabilities and serious incidents affecting digital products must be reported

Effective September 11, 2026, manufacturers of products containing digital components must report exploited vulnerabilities and serious incidents to public authorities and notify affected users

DORA Regulation, NIS2 Directive, AI Regulation… In recent years, the European Union has adopted a package of regulations that include cybersecurity obligations and measures to protect European society and the business ecosystem from cyber threats. One of these regulations is the Cyber Resilience Act (CRA).

What is the purpose of the CRA? To ensure the resilience and security of software and hardware sold in the European Union. How? Through measures such as continuous risk assessments and the obligation to report exploited vulnerabilities and serious incidents affecting software and hardware.

The regulation therefore targets manufacturers of products containing digital components and companies that sell them within the EU.

Unlike the NIS2 Directive, which must be transposed into Spanish law through a bill that has not yet been passed, the CRA Regulation is mandatory once it becomes applicable.

Although most of this regulation will not take effect until December 11, 2027, as of September 11, 2026, manufacturers are required to report exploited vulnerabilities and serious incidents affecting their products that contain digital components.

Next, we will explain how to report exploited vulnerabilities and serious incidents, and how to effectively manage both vulnerabilities and incidents to ensure the security and operational reliability of software and hardware.

1. When must actively exploited vulnerabilities and serious incidents affecting digital products be reported?

The CRA Regulation stipulates that manufacturers of digital products covered by the regulation must report «without undue delay» any actively exploited vulnerability present in their product to the CSIRT of the country where they have their principal place of business and to ENISA. In Spain, the CSIRT is INCIBE-CERT.

In any case, the maximum timeframe for reporting an actively exploited vulnerability is 24 hours from the moment the manufacturer becomes aware of it.

In the case of serious incidents that impact the security of products containing digital components, the notification deadline is exactly the same: 24 hours from the time the manufacturer became aware of the incident and its impact on the security of the software or hardware in question.

Therefore, the deadlines for early reporting of exploited vulnerabilities and serious incidents are very short and require manufacturers to have security policies tailored to this regulatory requirement that enable them to act efficiently and swiftly.

2. What is the process for reporting exploited vulnerabilities and serious incidents?

Basically, the relevant authorities (CSIRTs and ENISA) must be notified through a single reporting platform created by ENISA. What is the purpose of this? To facilitate the process of reporting exploited vulnerabilities and serious incidents and to streamline communication between the various CSIRTs in the European Union.

2.1. Reporting Actively Exploited Vulnerabilities

The process for reporting vulnerabilities that are already being exploited by malicious actors to carry out attacks consists of three steps:

  1. Early warning notification of the vulnerability. As noted above, this must be submitted within 24 hours of becoming aware that a vulnerability was being actively exploited. The notification must specify the EU member states in which the product is known to have been marketed.
  2. Vulnerability notification. This notification must be submitted within 72 hours at the latest, unless all the required information has already been provided in the early warning notification. What information are we referring to?
    • a. General information about the affected product.
    • b. The nature of the vulnerability.
    • c. How the vulnerability is being exploited.
    • d. Mitigation measures taken by the manufacturer.
    • e. Mitigation measures that users can take.
  3. Final report. This must be submitted within 14 days of the time a corrective measure to address the vulnerability becomes available, unless all required information has already been included in previous notifications. The minimum information that must be provided is:
    • a. A description of the vulnerability, including its severity level and its impact on the product and users.
    • b. Information about the malicious actor who exploited the vulnerability, if available.
    • c. Details about the security update developed or any other measures implemented to mitigate the vulnerability.

2.2. Reporting of Serious Incidents Affecting Product Security

The CRA Regulation establishes the obligation to report serious incidents that impact the security of hardware or software covered by the regulation. How can a manufacturer determine whether an incident meets the criteria set forth in the regulation? Essentially, when the incident is an event that:

  • Affects or could affect the ability of the software or hardware to «protect the availability, authenticity, integrity, or confidentiality of sensitive or important data or functions.»
  • Or has caused or could cause the introduction or execution of malware in the product or in the network and systems of the product’s users.

The process for reporting serious incidents also consists of three phases:

  1. Early incident alert notification. As noted above, this must be issued within 24 hours of becoming aware of the incident. The notification must include, at a minimum:
    • a. If the incident is suspected to be the result of an attack.
    • b. The EU countries where the product is known to have been marketed.
  2. Incident notification. Within 72 hours of the incident being detected, the following information must be provided, unless it was included in the early warning:
    • a. General information on the nature of the incident.
    • b. An initial analysis of the incident.
    • c. The measures taken to respond to and resolve the incident.
    • d. The measures that product users can take.
  3. Final report. Manufacturers have one month from the submission of the incident notification to provide a final report that:
    • a. Describes the incident in detail, including its severity and impact.
    • b. Specifies the type of threat that caused the incident or its cause.
    • c. Details the measures implemented to respond to the incident, including those that remain in effect.

In addition to the steps required to report exploited vulnerabilities and serious incidents, the regulation provides that the CSIRT may request interim reports from manufacturers providing updates on the status of the vulnerability or incident in question.

The goal of reporting exploited vulnerabilities and serious incidents affecting software is to protect consumers and businesses

3. Must exploited vulnerabilities and serious incidents also be reported to the individuals and organizations that use the products?

Yes. The CRA regulation requires manufacturers to report exploited vulnerabilities and serious incidents affecting their digital products to:

  • Affected users.
  • All users, where appropriate.

When should users be notified? The regulation uses the phrase «as soon as it becomes aware»; however, unlike notification to public authorities, there is no maximum timeframe for notifying citizens and businesses.

That said, the CRA Regulation also stipulates that if the manufacturer fails to notify “users of the product with digital components in a timely manner,” the CSIRT that has been notified of the vulnerability or incident may directly inform users if it considers this a necessary and proportionate measure to “prevent or mitigate the impact of the vulnerability or incident in question.”

Therefore, manufacturers have more leeway to notify users of their products about exploited vulnerabilities and serious incidents, but they cannot circumvent this legal obligation and should act diligently.

What should be communicated to users?

  • Inform them about the actively exploited vulnerability or the serious incident.
  • Provide details on the measures taken to reduce risks.
  • Outline the corrective actions that users themselves can take to mitigate the consequences of the active exploitation of the vulnerability or the incident.

How can actively exploited vulnerabilities and serious incidents be reported to users of the affected products?

  • By publishing information on the manufacturer’s website.
  • By communicating directly with users whenever possible and when cybersecurity risks are high.

4. What is the purpose of the requirement to report exploited vulnerabilities and serious incidents?

The CRA Regulation outlines some of the objectives behind the requirement to report exploited vulnerabilities and serious incidents affecting digital products:

  • To ensure that CSIRTs and ENISA have all the information they need about vulnerabilities and incidents to protect the internal market from cyberthreats.
  • To facilitate swift and effective coordination among the various CSIRTs in EU member states, given that most products are marketed throughout the common market.
  • To disclose vulnerabilities that have already been fixed to help manufacturers ensure they market secure products.
  • To enable users of products affected by vulnerabilities or incidents to take the necessary measures to minimize the consequences.

5. What are the consequences of failing to report exploited vulnerabilities and serious incidents in a timely and proper manner?

Failure to comply with the obligation to report exploited vulnerabilities and serious incidents affecting software or hardware results in the imposition of administrative fines.

To be precise, the CRA regulation provides for fines of up to 15 million euros or 2.5% of the manufacturer’s turnover in the previous year.

Obviously, the maximum fines are reserved for extremely serious cases involving large manufacturers that have affected a large number of citizens and/or businesses.

Even so, it is clear that failing to comply with the obligation to report exploited vulnerabilities and serious incidents can result in significant financial damage.

Furthermore, we must consider the erosion of consumer trust and the significant reputational damage caused by concealing the active exploitation of a vulnerability or a serious incident.

Similarly, manufacturers that have failed to report exploited vulnerabilities and serious incidents may also face legal disputes if an individual or a company has suffered an incident that could have been prevented had the necessary information been available.

Cybersecurity for digital products is critical

6. Vulnerability management and incident response are critical to protecting products and their users

How can software and hardware manufacturers report exploited vulnerabilities and serious incidents in accordance with the CRA regulation? Two key cybersecurity services are essential for protecting companies:

  • Vulnerability management. Through comprehensive vulnerability management, it is possible to:
    • Maintain an inventory of assets and continuously monitor their security.
    • Develop plans for detecting and mitigating vulnerabilities, prioritizing the most critical ones—for example, those that are already being actively exploited.
    • Reduce the time it takes to detect new vulnerabilities and remediate them.
    • Ensure compliance with cybersecurity regulations and, in particular, the obligation to report actively exploited vulnerabilities within the established timeframes and provide all requested information.
    • Provide remediation measures to users as quickly as possible.
  • Proactive incident response. An incident response team is key to identifying, containing, and eliminating malicious activity and facilitating the restoration of normal operations for a digital product. With a well-developed incident response plan:
    • The coordination of an effective response is accelerated.
    • The scope of the breach and the impact of the incident are limited.
    • Compliance with regulations regarding incident reporting is ensured by specifying who must report, to whom, within what timeframes, and what information must be included in each report.
    • It facilitates subsequent analysis to prevent recurrence.

7. Late 2027: The deadline by which the CRA Regulation must be fully complied with

The obligation to report exploited vulnerabilities and serious incidents affecting software and hardware is one of the pillars on which the CRA Regulation is based, but what are the others?

  • Establishes essential security-by-design requirements that critical and important products must meet. These categories encompass a wide range of hardware and software: routers, VPNs, operating systems, web browsers, malware detection and removal software, smart electric meters, internet-connected toys, baby monitors…
  • Establishes processes for assessing the compliance of critical and important products with the CRA regulation.
  • Requires manufacturers to conduct periodic cybersecurity risk assessments of their products.
  • Mandates the secure integration of third-party and open-source components to prevent supply chain attacks.
  • Requires that product vulnerabilities be managed throughout their lifecycle.
  • Stipulates that vulnerabilities in critical and important products must be mitigated quickly and efficiently.
  • It requires security audits of critical and important products.

In short, as of September 11, 2026, manufacturers of digital products are required to report exploited vulnerabilities and serious incidents immediately upon becoming aware of them. This new requirement makes it even more critical to implement effective vulnerability management and have a well-developed and tested incident response plan in place.

In addition, software and hardware manufacturers and distributors must begin implementing the remaining measures included in the CRA regulation to be prepared for their mandatory enforcement in just over a year.