EU Cyber Resilience ActCRA / Article 14applies 11 Sep 2026

Finland: the CRA 24-hour reporting duty starts on 11 September 2026. Can you report on time?

Under the EU Cyber Resilience Act (CRA; Regulation (EU) 2024/2847), from 11 September 2026 a manufacturer must report an actively exploited vulnerability or a severe incident to Traficom's National Cyber Security Centre (NCSC-FI) and ENISA via ENISA's Single Reporting Platform (SRP). The deadline starts at awareness, not confirmation, and the duty also covers products already on the market, including products no longer manufactured. Penalties can reach EUR 15 million or 2.5% of worldwide turnover.

Reporting deadlines

24 hoursEarly warning, once there is reliable evidence that a vulnerability in your product is being exploited.
72 hoursThe actual vulnerability and incident notification.
14 daysFinal report no later than 14 days after a corrective or mitigating measure is available (for a severe incident: one month after the 72-hour notification).

Check your situation for free, in the browser

The tools run entirely in your browser. Nothing you enter is sent anywhere.

🔎 Take the 3-minute readiness check →
See whether you are in scope, which duties bind you, and whether you could actually report in 24 hours.

⏱️ Compute deadlines and draft notifications →
Enter the awareness moment and get 24h/72h/14-day dates, notification drafts, and a CSAF 2.0 file.

In Finland: prepare in advance

According to Traficom NCSC-FI guidance, a manufacturer should already:

Paid reporting kit and setup

The paid setup service is paused. The tools on this site are free and open source (MIT). Questions: open an issue.