Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live
The EU Cyber Resilience Act's reporting obligations bind from 11 September 2026, requiring manufacturers of "products with digital elements" placed on the EU market to report actively exploited vulnerabilities and severe incidents through ENISA's centralised Single Reporting Platform (SRP) (NCSC-FI / Traficom, 2026-08-28). On 2026-08-28, with two weeks left before the obligation binds, NCSC-FI published a manufacturer checklist supplying the concrete notification clock: an early warning within 24 hours of the manufacturer becoming aware of an actively exploited vulnerability or severe incident, supplemented within 72 hours; for a vulnerability, a final report within 14 days after a corrective or mitigating measure becomes available; for a severe incident, a final report within one month of the incident notification (NCSC-FI / Traficom, 2026-08-28). The SRP itself only becomes live on 2026-09-11 — the same date the reporting duty starts to apply (ENISA, 2026-08-14). NCSC-FI's checklist directs manufacturers to identify in-scope products now — noting that products past end-of-life and no longer receiving updates remain subject to the reporting obligation — appoint a primary and backup "Assigned Representative" (AR) authorised to submit SRP notifications, document an internal report-intake and triage process, and rehearse it at least once before the first reportable case (NCSC-FI / Traficom, 2026-08-28). API-based submission is not expected until spring 2027; until then, only the two named Assigned Representatives per manufacturer can file, which is a concrete operational bottleneck for any organisation planning its incident-response workflow around the deadline (NCSC-FI / Traficom, 2026-08-28).
For an actively exploited vulnerability or a severe incident, an early warning must be submitted within 24 hours of the manufacturer becoming aware of it. The notification must be supplemented within 72 hours.
For a vulnerability, the final report must be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report must be submitted within one month of the incident notification.
Notifications are expected to be possible through APIs from spring 2027. After this, notifications can be submitted directly from the organisation's own system.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.