Mandatory CRA Reporting Takes Full Effect in September 2026
There are only about one month left until the mandatory implementation of the reporting obligations in CRA. Many foreign trade factories and cross-border sellers still have not established the corresponding procedures. Unlike the full rollout of the act by the end of 2027, these reporting obligations are mandatory regulation implemented separately in advance. Regulators across EU member states, Amazon, and customs authorities will simultaneously start routine spot checks. Without a vulnerability response system, products risk immediate delisting, fines and cargo detention.
Core Mandatory Compliance Requirements
1. Time Boundary
When a device exposes a high-risk vulnerability that can be remotely invaded, steal privacy, tamper with firmware and so on, a vulnerability alert must be submitted to ENISA's EU-wide SRP platform within 24 hours. Late submission constitutes non-compliance.
2. Remediation Obligations
After the vulnerability is reported, interim mitigation measures must be delivered within 72 hours; full root-cause remediation, security patch rollout and submission of a final detailed report shall be completed within 14 or 30 days.
3. Documentation Obligations
Full documentation covering vulnerability intake, reporting, remediation and post-review must be archived and retained for a minimum of 10 years for regulator inspection upon request.
4. Scope of Application
All Internet-connected smart devices sold to the EU: such as cameras, smart home devices, wearable devices, industrial gateways, charging piles, Bluetooth/Wi-Fi devices and other terminals are all covered (except for exempted products).
Heavy Fines for Violations
Failure to report on time, concealing vulnerabilities, or submitting false reports are considered severe violations. Penalties are set at the higher of 15 million euros or 2.5% of the enterprise's global annual revenue.
Reminder from Toby Testing
The September enforcement deadline will not be postponed. This is the last window for preparation. Reporting obligations is the first hard compliance hurder under the CRA. Early preparation safeguards your EU market access.
Services that Toby Testing Provides
- Break down the full reporting timeline (24 / 72h / 14 or 30 days) and assessment criteria;
- Walk through SRP platform registration, field filling, and platform integration;
- Conduct scenario-based simulation drills to equip teams to submit reports correctly, rapidly and competently. Guide enterprises on building internal SRP reporting governance systems.
Toby Testing holds A2LA accreditation and EN 18031 qualification, delivering authoritative cybersecurity testing and technical support aligned with standard requirements to facilitate market access into the EU. Please contact us for cybersecurity inquires.
About Toby Testing
Toby Testing is a third-party testing company with CMA and ISO 17025 accreditations from CNAS and A2LA. Operating two laboratories in Shenzhen, China, Toby specializes in electronic and electrical (E&E) product safety, EMC, wireless, chemical, and physical testing and certification. With advanced facilities and expert staff, Toby delivers global market access solutions, enabling clients to expand into international markets.