BG Image

A Step-by-Step Guide to CRA Vulnerability and Incident Reporting

Starting 11 September 2026, manufacturers and open-source software stewards must report actively exploited vulnerabilities and severe security incidents under the EU Cyber Resilience Act. A failure to report may lead to fines of up to €15 million or 2.5% of worldwide turnover.

The reporting deadlines are short and strict, so you need to understand the process before an incident happens. We put together a practical CRA Reporting Cheat Sheet that turns CRA Article 14 requirements into a step-by-step workflow you can use during preparation and response.

Use this Cheat Sheet to assess
  • Whether you and your product is in scope
  • Which events are considered reportable
  • Which CSIRT you should report to
  • How to register and submit a report through the ENISA SRP
  • What is the reporting timeline
  • What information must be submitted within 24 hours, 72 hours, and in the final report

Get Your Free Copy


What customers say about our support

Konstantin Bulenkov

Konstantin Bulenkov

Head of JetBrains Runtime

We rely on the Liberica team's experience and expertise to provide timely updates for our customers; together, we keep JetBrains Runtime secure and performant.