EU Cyber Resilience ActCRA / Article 14applies 11 Sep 2026
Finland: the CRA 24-hour reporting duty starts on 11 September 2026. Can you report on time?
Under the EU Cyber Resilience Act (CRA; Regulation (EU) 2024/2847), from 11 September 2026 a manufacturer must report an actively exploited vulnerability or a severe incident to Traficom's National Cyber Security Centre (NCSC-FI) and ENISA via ENISA's Single Reporting Platform (SRP). The deadline starts at awareness, not confirmation, and the duty also covers products already on the market, including products no longer manufactured. Penalties can reach EUR 15 million or 2.5% of worldwide turnover.
Reporting deadlines
| 24 hours | Early warning, once there is reliable evidence that a vulnerability in your product is being exploited. |
|---|---|
| 72 hours | The actual vulnerability and incident notification. |
| 14 days | Final report no later than 14 days after a corrective or mitigating measure is available (for a severe incident: one month after the 72-hour notification). |
Check your situation for free, in the browser
The tools run entirely in your browser. Nothing you enter is sent anywhere.
🔎 Take the 3-minute readiness check →
See whether you are in scope, which duties bind you, and whether you could actually report in 24 hours.
⏱️ Compute deadlines and draft notifications →
Enter the awareness moment and get 24h/72h/14-day dates, notification drafts, and a CSAF 2.0 file.
In Finland: prepare in advance
According to Traficom NCSC-FI guidance, a manufacturer should already:
- Establish whether you are a manufacturer and for which products.
- Name a representative and a deputy who will file official notifications, and register them on ENISA's reporting platform (SRP). For now, notifications go only through those two people.
- Agree who makes the reporting decision at the weekend too. The 24-hour clock does not pause for registration or on-call coverage.
Paid reporting kit and setup
The paid setup service is paused. The tools on this site are free and open source (MIT). Questions: open an issue.