Which Vulnerabilities Count? Reporting and Exploitability Under the Cyber Resilience Act
On 11 September 2026, the Cyber Resilience Act's reporting obligation went live. If you become aware that a vulnerability in a product you sell into the EU is being actively exploited, you have 24 hours to file an early warning with ENISA and your national CSIRT, 72 hours for the details, and 14 days for a final report once a fix is available. It applies to products already on the market, not only to what you ship next year.
The second date is 11 December 2027, when the rest of the regulation applies: the Annex I essential requirements, conformity assessment and CE marking, SBOMs, and support periods measured in years. No harmonized standard has been published in the Official Journal yet, and no CRA notified bodies have been designated, so the conformity route many teams are waiting on is not open. The obligations arrive on schedule regardless.
Both dates come down to the same question. Which of the vulnerabilities in what you ship are actually exploitable, and can you prove it? The Commission's July 2026 guidance sharpened that question considerably. A vulnerability in a third-party component is reportable only where it is exploitable in your product, and a vulnerability counts as known once your own testing finds it, including AI-assisted analysis.
In this webinar, we'll through both deadlines and what they ask of engineering and security teams. We cover:
- What the 24, 72 and 14-day reporting clock requires, and when the clock actually starts
- Why "exploitable in your product" became a regulatory determination rather than a triage preference
- What December 2027 adds: product classification, Annex I, SBOM depth, and the support-period long tail
- How to build the evidence now, without waiting for harmonized standards




