CRA 24-hour incident clock
Work out the Cyber Resilience Act reporting deadlines from the moment you became aware: 24-hour early warning, 72-hour notification and the final report. The reporting duty has applied since 11 September 2026; the guide for small vendors explains it.
Runs entirely in your browser
Enter the time you became aware to see the deadlines.
A helper, not legal advice: the regulation (EU) 2024/2847, Article 14, and ENISA's guidance prevail. Hours are counted as elapsed time and months as calendar months in UTC; the formal counting rules may allow slightly more time, so plan to the times shown and report earlier when you can. Nothing is sent anywhere.
How to use the CRA incident clock
- Choose what happened: an actively exploited vulnerability in your product, or a severe incident that affects its security.
- Enter the moment you became aware, or press the button to use the current time. Check whether the time you typed is in your own time zone or in UTC.
- Read the deadlines in your time zone and in UTC. When a fix is available (vulnerability) or you have filed the 72-hour notification (incident), enter that time to fix the date of the final report.
- Print the checklist or save the page, and file each report through ENISA's Single Reporting Platform before its deadline.
The three reports
Since 11 September 2026, the Cyber Resilience Act (Regulation (EU) 2024/2847, Article 14) requires manufacturers of products with digital elements to report actively exploited vulnerabilities in their products and severe incidents that affect their security. Each event leads to three reports, all filed through the same ENISA platform: a short early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report. The final report is due 14 days after a corrective or mitigating measure is available for an exploited vulnerability, and one month after the notification for a severe incident.
The first two clocks run on elapsed time from awareness, so they do not stop at night or at weekends. The third depends on something you control or learn later, which is why the page asks for the time a fix became available or the time you filed the notification. Until you enter it, the final report is shown as open for a vulnerability, and as the latest possible date for an incident.
Preparing before the clock starts
Most of the 24 hours is lost on setup: who decides that exploitation is real, who has an account on the reporting platform, and which product versions and EU countries are affected. Settle these in advance. A component list for each product, a monitored contact (see the security.txt generator) and a written disclosure policy make the first report much easier.
Tips
- Print the checklist for the on-call person, or save the page as PDF, so that nobody has to read the regulation at 3 a.m.
- Share the UTC time with colleagues in other countries; the local times shown are for the computer you are using.
- Need to compare other time zones? Try the time zone converter.
Questions
When does the 24-hour clock start?
When you become aware, which the commentary summarised in our guide describes as the point at which an initial assessment gives you reasonable certainty that exploitation is happening. It is not the end of your investigation, and not when a customer first writes. When in doubt, use the earlier moment.
What are the deadlines?
For an actively exploited vulnerability: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available. For a severe incident: the same first two, then a final report within one month after the 72-hour notification.
Where do I file the reports?
Through ENISA's Single Reporting Platform. One submission reaches ENISA and the CSIRT designated as coordinator, normally the one in the country of your main EU establishment. Manufacturers outside the EU report through their EU authorised representative. Register before you need it.
Does a weekend or holiday extend the deadline?
Do not count on it. The deadlines run in hours from awareness, so plan as if every hour counts, and keep an on-call rule for who files. This page shows the times as exact moments for that reason.
Is anything stored or sent?
No. The page works out the times in your browser. If you tick the box to remember the times, they are kept in this browser's local storage on this device only, and the button next to it deletes them.
Does this tell me whether I must report?
No. It only does the date arithmetic. Whether an event is an actively exploited vulnerability or a severe incident, and whether your product is covered, is for you and your advisers to decide against the regulation and ENISA's guidance.