Cybersecurity regulation is increasingly moving from a reactive model to one that demands continuous accountability throughout the product lifecycle.
The European Union’s Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, represents a significant shift in how organizations that manufacture products with digital elements must manage cybersecurity risks.
One of the most important requirements is the mandatory reporting of actively exploited vulnerabilities.
Under Article 14 of the CRA, manufacturers must report an actively exploited vulnerability to the designated CSIRT and the European Union Agency for Cybersecurity (ENISA) through the CRA Single Reporting Platform.
The 24-Hour Clock
The CRA establishes a three-stage reporting process:
Within 24 hours — Early Warning
The manufacturer must submit an early warning without undue delay and, in any event, within 24 hours of becoming aware of the actively exploited vulnerability.
The initial notification identifies the vulnerability and, where applicable, the Member States where the affected product has been made available.
Within 72 hours — Vulnerability Notification
A more detailed notification must follow within 72 hours. This includes available information about the affected product, the general nature of the exploit and vulnerability, and corrective or mitigating measures already taken or available to users.
Within 14 days of a corrective measure becoming available — Final Report
The final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available.
It must include information such as the vulnerability’s severity and impact, information about malicious actors where available, and details of the security update or other corrective measures.
Why This Matters to GRC Leaders
The CRA transforms vulnerability management from primarily a technical activity into an enterprise governance responsibility.
Organizations need clearly defined:
- Vulnerability identification processes
- Incident escalation criteria
- Regulatory reporting procedures
- Executive notification processes
- Legal and compliance involvement
- Product security ownership
- Evidence and documentation requirements
- Patch and remediation governance
- Third-party and software dependency oversight
The biggest challenge may not be discovering the vulnerability.
It may be determining when the organization officially became aware of it.
That timestamp can effectively start the regulatory clock.
Governance Must Start Before the Vulnerability
Organizations should therefore establish a documented vulnerability-response workflow that connects:
Security Operations → Product Security → Vulnerability Management → Legal → Compliance → Risk → Executive Leadership
This should not depend on individuals remembering what to do during a crisis.
The process should be embedded into policies, procedures, playbooks and technology workflows.
A New Definition of Cybersecurity Accountability
The CRA reinforces an important principle:
Cybersecurity is no longer simply about preventing attacks. It is also about demonstrating that the organization can identify, assess, report, remediate and communicate cybersecurity risks within defined regulatory timelines.
For GRC professionals, this means vulnerability management should be treated as a regulated business process, supported by measurable controls, documented decision rights and auditable evidence.
The organizations that prepare early will be better positioned to respond when the 24-hour clock starts.
References
- European Union, Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 14, Reporting obligations of manufacturers.
- ENISA, CRA Single Reporting Platform — Frequently Asked Questions, updated September 4, 2026.



