---
title: "Report to ENISA in 24 hours: a machine builder guide | Edge SDN"
description: "CRA reporting is in force. What counts as actively exploited, the 24-hour, 72-hour and 14-day deadlines, who gets the report and how a machine builder gets ready."
url: https://www.edge-sdn.com/use-cases/report-to-enisa-in-24-hours/
last_updated: 2026-09-19
---

Cyber Resilience Act · Machine builder · Software builder

# Report to ENISA in 24 hours: what a machine builder must do since 11 September 2026

By Aldo Campi, co-founder and CEO of Stoorm5 · Published 19 September 2026 · Last updated 19 September 2026

What are the CRA reporting obligations and deadlines for manufacturers?

Since 11 September 2026, Article 14 of the Cyber Resilience Act obliges manufacturers to report actively exploited vulnerabilities and severe incidents. The steps are an early warning within 24 hours, a notification within 72 hours and a final report within 14 days of a fix. The duty also covers products already on the market, and affected users must be informed.

Where are you against 20 January 2027? [Take the Check 2027](https://www.edge-sdn.com/check-2027/): seven questions, three minutes.

## Key facts

- Article 14 of the CRA applies from 11 September 2026. The regulation applies in full from 11 December 2027. [\[Regulation (EU) 2024/2847, Article 71\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- Early warning within 24 hours, notification within 72 hours, final report no later than 14 days after a corrective or mitigating measure is available. For severe incidents the final report is due within one month. [\[Regulation (EU) 2024/2847, Article 14\]](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting)
- The reporting duty applies to all products with digital elements, including those placed on the market before 11 December 2027. [\[Regulation (EU) 2024/2847, Article 69(3)\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)
- Breaches of Article 14 can be fined up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher. Micro and small enterprises cannot be fined for missing the 24-hour deadline, but the duty still applies to them. [\[Regulation (EU) 2024/2847, Article 64(2) and 64(10)\]](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)

## The situation

A machine builder with 80 employees sells in Germany, France and Italy. It has no security operations centre and no product security team. The person who knows the machine software best is the lead PLC programmer.

On a Friday afternoon a supplier writes that a vulnerability in their remote access gateway is being used in real attacks. The builder has used that gateway in its machines for years.

The 24 hours start when the builder is aware that the exploited vulnerability is in its product. Without a component list, the builder cannot even answer that question.

## What the law asks

The Cyber Resilience Act sets three steps for an **actively exploited vulnerability** in your product:

| Step                       | Deadline                                                      | Content                                                                                                                                 |
| -------------------------- | ------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Early warning              | 24 hours after you become aware                               | That the vulnerability exists and, where known, in which Member States the product is available                                         |
| Vulnerability notification | 72 hours after you become aware                               | General information on the product, the nature of the exploit and the vulnerability, the measures taken and the measures users can take |
| Final report               | 14 days after a corrective or mitigating measure is available | Description, severity and impact, information on the malicious actor where available, details of the security update or measure         |

For a **severe incident** that affects the security of the product, the first two deadlines are the same and the final report is due within one month of the notification.

You send the reports through the single reporting platform, to your national CSIRT coordinator and to ENISA at the same time. You must also inform the affected users.

## Why this is hard for a machine builder

The deadline is not the hard part. The hard part is that in 24 hours you must already know:

- **Which products are affected.** That means a component list for every machine you delivered, with versions.
- **Who the users are.** That means a current contact for every customer of every machine.
- **What they should do.** That means knowing if the component can be reached on their machine, and which mitigation works.

A builder that starts to collect this information when the email arrives will miss the first deadline and probably the second.

## The steps to get ready

### 1. Name two people

Decide who receives security reports from suppliers and customers, and who sends the report to the platform. Name a deputy for holidays. Check on the ENISA website how to get access to the single reporting platform, and do it before you need it.

### 2. Open a channel for incoming reports

Publish a security contact and a simple vulnerability disclosure policy. Researchers and suppliers must know where to write. The CRA asks for a coordinated vulnerability disclosure policy in any case.

### 3. Build the component list for what is already in the field

Start with the models that have remote access, because they are the most likely to be concerned. Record the components and versions per delivered machine.

### 4. Keep customer contacts with the machine record

The notice to users is part of the duty. A contact list in the sales CRM, sorted by account manager, will not help you on a Friday evening.

### 5. Prepare the templates

Write the early warning, the notification and the customer notice once, with empty fields. In the real case you fill the fields.

## How Shield Lifecycle helps

[Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/) holds the component list, the attack surface and the customer of every delivered machine. When a vulnerability arrives, it tells you which machines contain the component and on which of them it can be reached. It drafts the notice to each affected customer with the technical report and the patch procedure attached, and it keeps a record of what was sent and when.

It does not send the report to ENISA for you. The duty and the account on the platform are the manufacturer’s. It gives you the facts you need to write that report in hours and not in weeks.

## Frequently asked questions

### Do I have to report every CVE that affects my machine?

No. The duty concerns actively exploited vulnerabilities. That means there is reliable evidence that a malicious actor has used them. It also concerns severe incidents that affect the security of your product. But you can only know that one of these concerns you if you know what is inside your machines.

### Does this apply to machines we sold before the CRA?

Yes for reporting. Article 69(3) extends the Article 14 duties to products placed on the market before 11 December 2027. The product requirements, such as the SBOM, apply to older products only if they are substantially modified after that date.

### Who do I report to?

To the CSIRT designated as coordinator in the Member State of your main establishment and to ENISA, at the same time, through the single reporting platform.

### Do I have to tell my customers?

Yes. After becoming aware, the manufacturer must inform the impacted users of the vulnerability or incident and, where needed, of the risk mitigation and corrective measures they can take.

Product

### Shield Lifecycle

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Related use case

### Same model, two machines, one exposed: find which shipped machines a new CVE hits

[Read](https://www.edge-sdn.com/use-cases/find-which-machines-a-new-cve-exposes/)

Related use case

### Prepare for point 1.1.9: what your machine must know about its own software from 20 January 2027

[Read](https://www.edge-sdn.com/use-cases/machinery-regulation-point-1-1-9/)

This article is a summary for practitioners and not legal advice. Always check the official text for your case.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
