CRA 24h Clock · Sample Watch bulletin · September 2026
CRA24 Watch, 2026-09
Article 14 starts on 11 September 2026. The platform you must file through was still not publicly reachable when this bulletin was compiled.
Compiled 2026-09-03. Every claim below cites a primary source and the date it was read. Where something could not be verified it says [ei verifioitu] rather than being left out.
The clock
- 2026-09-11, 8 days away. Article 14 reporting obligations apply. Article 71(2). Applies to products already on the market, not only new ones.
- 2027-12-11, 464 days away. The rest of the CRA applies, including the SBOM and vulnerability handling requirements. Article 71 general date. Annex I Part II.
Reporting deadlines, all running from the moment you become aware:
- 24 hours from becoming aware. Early warning to the coordinating CSIRT and ENISA. Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
- 72 hours from becoming aware. Full notification: product information, nature of the exploitation, corrective or mitigating measures. Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
- no later than 14 days after a corrective measure is available. Final report, actively exploited vulnerability. Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
- within one month. Final report, severe incident. Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
What changed this month
ENISA updated three Single Reporting Platform guidance pages in August 2026
ENISA published dated guidance for Assigned Representatives: "CRA SRP - AR User registration" and "CRA SRP - AR Notification submission and update", both updated 3 August 2026, and "CRA SRP - AR Interface functions", updated 14 August 2026. These are the operational screens you will actually use, and they landed five weeks before the obligation applies.
Why it matters. If your reporting runbook was written before August, it predates the only official description of the submission interface. Re-read the runbook against the AR pages before 11 September.
Source: ENISA, Single Reporting Platform (SRP) (https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp), read 2026-09-02
There is no reporting API at launch
ENISA's SRP FAQ states: "Organisations might automate reporting workflows and integrate reporting requirements into their systems and databases, however no Application Programming Interfaces will be provided at this stage."
Why it matters. Everything up to submission can be automated, but the final filing is a human in a browser. That is a staffing question, not an engineering one: inside a 24 hour window you need a named person who can log in, plus a named backup.
Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02
Registration runs through EU Login and can be done before you have anything to report
ENISA's SRP FAQ states: "Assigned Representatives (ARs) of manufacturers or open-source stewards must have an EU Login account and use it to register on the SRP." A Primary AR registers by selecting the relevant CSIRT designated as coordinator.
Why it matters. An EU Login account is the one prerequisite that does not depend on the platform being live. Create it for the primary filer and at least one deputy now. The 24 hour clock does not pause for account creation.
Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02
A non-validated Assigned Representative may file up to 20 notifications
ENISA's SRP FAQ states: "Non-validated ARs will be able to submit up to 20 notifications for one manufacturer before validation becomes mandatory."
Why it matters. You are not blocked from filing while validation is pending, but the allowance is finite. Treat validation as a task with a deadline rather than something that happens on its own. Note that at least one widely shared secondary summary gave this number as 10; the figure above is read from ENISA's own FAQ.
Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02
The delegated act on CSIRT dissemination delays is in force
Commission Delegated Regulation (EU) 2026/881, adopted 11 December 2025, sets the conditions under which a CSIRT may delay disseminating a notification on cybersecurity grounds.
Why it matters. Your report can be held back from onward distribution without that being a fault in your filing. Do not treat silence after submission as evidence that the report failed.
Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
Article 14 covers products already on the market
The Commission states: "As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements." The duty is framed by product status, not by placing date.
Why it matters. The common reading that only products shipped after September are in scope is wrong. Your evidence log has to cover the product lines you still support, including old ones.
Source: Euroopan komissio, CRA Reporting obligations (https://digital-strategy.ec.europa.eu/en/policies/cra-reporting), read 2026-09-02
Open, contested, or not yet published
The public URL of the Single Reporting Platform
Status: ei verifioitu.
What we checked: ENISA's SRP page states that "As of 11 September 2026 onwards, the SRP will be used by CSIRTs and manufacturers for mandatory reporting" and that the platform is under development. No public submission URL was present on that page when this bulletin was compiled.
What to do: Watch the ENISA SRP page. Do not build a runbook step around a URL that does not exist yet; build it around the EU Login account, which does.
Source: ENISA, Single Reporting Platform (SRP) (https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp), read 2026-09-02
Two ENISA pages disagree on when voluntary reporting opens
Status: ristiriita ensisijaisten lahteiden valilla.
What we checked: The ENISA SRP page says the platform "could be used by any natural/legal persons for voluntary reporting" as of 11 September 2026 onwards. The ENISA SRP FAQ says voluntary reporting "will be enabled in the next phase of the CRA SRP". Both pages were read on the same day.
What to do: Do not plan a low stakes practice filing through the voluntary channel on day one. Assume your first filing may have to be a real one, and rehearse against your own evidence log instead.
Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02
The published list of national CSIRTs designated as coordinators
Status: ei verifioitu.
What we checked: Registration requires selecting the CSIRT designated as coordinator for your Member State of main establishment. We did not locate a published, consolidated list of those designations from a primary source.
What to do: Determine your Member State of main establishment now and record the reasoning. That determination is yours to make and does not depend on the list being published.
Source: ENISA, SRP Frequently Asked Questions (https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions), read 2026-09-02
What "becoming aware" means for an open source steward
Status: ohjeistus kesken.
What we checked: Section 9 of the Commission's implementing guidance, published 2026-07-27, addresses becoming aware, but frames it around a manufacturer and their product. The open question for stewards is being tracked publicly at orcwg/orcwg#261.
What to do: Whichever reading prevails, the two facts an authority asks for first are the same: a timestamped moment of awareness and a record of who made the actively exploited call. Both are what your evidence log records.
Source: Euroopan komissio, CRA implementing guidance (julkaistu 2026-07-27) (https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation), read 2026-09-02
Tool and template changes
Measured from the repository history for this month, not written by hand:
- f525e39 fix(cra24): korttiselitteen ja peruutuksen lupaukset vastaamaan todellisuutta
- 8e4dddb feat(cra24): kassapinta, maksun jalkeinen sivu ja yksi kanoninen spec
Your monthly evidence chain run
Your evidence log is only worth something if its chain is intact and you can show that it was intact before the incident, not after it.
CRA_CLOCK_LOG=<your path> node cra-clock.mjs verify
CRA_CLOCK_LOG=<your path> node cra-clock.mjs status
CRA_CLOCK_LOG=<your path> node cra-clock.mjs aware --product "<name>" --vuln <id> --source <url> --decided-by "<name>"
CRA_CLOCK_LOG=<your path> node cra-clock.mjs deadlines --aware <ISO timestamp>
Run the first command once a month and keep the output. It costs a minute and it is the difference between an evidence log and a text file.
Sources tracked
- ENISA, Single Reporting Platform (SRP): https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp
- ENISA, SRP Frequently Asked Questions: https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions
- ENISA, CRA SRP Factsheet v1.0 (heinakuu 2026): https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA_CRA_SRP_Factsheet_v1.0_0.pdf
- Euroopan komissio, CRA Reporting obligations: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
- Euroopan komissio, CRA implementing guidance (julkaistu 2026-07-27): https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
This bulletin is a regulatory tracking summary. It is not legal advice, and no response time or on-call service is promised or implied.