<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci" -->

---
title: Guide to the EU CRA Sept 11 Deadline for Manufacturers
description: Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the EU CRA Single...
canonical: https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Guide to the EU CRA Sept 11 Deadline for Manufacturers | daily.dev
og:description: Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the EU CRA Single...
og:url: https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci
og:image: https://api.daily.dev/og/posts/Ovx8KPqCi.png
og:image:alt: Guide to the EU CRA Sept 11 Deadline for Manufacturers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Guide to the EU CRA Sept 11 Deadline for Manufacturers

**[OpenSSF](https://daily.dev/sources/openssf)** · 10 min read · 0 upvotes · 0 comments

## Summary

Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the EU CRA Single Reporting Platform starting September 11, 2026, with early warnings due within 24 hours and full notifications within 72 hours. This deadline does not create reporting obligations for open source maintainers or stewards, whose CRA obligations under Article 24 begin December 11, 2027. However, manufacturers will increasingly contact upstream open source projects when reported vulnerabilities trace to open source components, per Article 13(6), which will require manufacturers to share fixes with maintainers. Maintainers are advised to add a SECURITY.md file, keep security contacts current, and understand their steward's role. Stewards should establish points of contact, escalation paths, and use the LF/OpenSSF CRA Stewards Playbook to prepare ahead of their 2027 deadline.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://openssf.org/blog/2026/09/11/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers>

## Questions this post answers

### What are manufacturers required to do under the EU Cyber Resilience Act starting September 11, 2026?

Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform (SRP). An early warning is due within 24 hours of becoming aware of the event, a full notification within 72 hours, and a final report within 14 days after a fix becomes available (or one month after the 72-hour notification for severe incidents). Voluntary reporting under Article 15 is not yet available in the SRP at launch.

_Teams tracking CRA compliance deadlines can follow regulatory and open source security updates on daily.dev._

### Do open source maintainers have CRA reporting obligations on September 11, 2026?

No, individual open source maintainers and stewards do not have CRA reporting obligations on this date. Manufacturer reporting requirements take effect September 11, 2026, while steward obligations under Article 24 of the CRA do not begin until December 11, 2027. Maintainers may still be contacted by manufacturers when a reported vulnerability traces to their component, so having a security contact and disclosure process ready is recommended.

_Maintainers navigating evolving open source security regulations can find related coverage on daily.dev._

## Similar posts on daily.dev

- [CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know](https://daily.dev/posts/cra-reporting-is-live-what-manufacturers-vendors-and-distributors-need-to-know-lgzvcskld) · IT Security Guru · 0 upvotes · 0 comments
- [CRA’s First Connected-Products Deadline Is in Less Than 100 Days](https://daily.dev/posts/cra-s-first-connected-products-deadline-is-in-less-than-100-days-7zrubiyyy) · Embedded.com · 0 upvotes · 0 comments
- [What the EU CRA actually asks of your engineering team](https://daily.dev/posts/what-the-eu-cra-actually-asks-of-your-engineering-team-syimwsx88) · Kilo Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#compliance](https://daily.dev/tags/compliance)

[View this post on daily.dev](https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Guide to the EU CRA Sept 11 Deadline for Manufacturers","url":"https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci"},"datePublished":"2026-09-11T16:07:48.064Z","dateModified":"2026-09-15T16:15:13.896Z","description":"Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the EU CRA Single...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4e037d97cd91e3eed29aff9dc8d85948?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4e037d97cd91e3eed29aff9dc8d85948?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"OpenSSF","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"OpenSSF","logo":"https://media.daily.dev/image/upload/s--l6RJ5uPj--/f_auto,q_auto/v1774959959/logos/openssf?_a=BAMAMiWQ0","url":"https://daily.dev/sources/openssf"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,compliance","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"OpenSSF","item":"https://daily.dev/sources/openssf"},{"@type":"ListItem","position":3,"name":"Guide to the EU CRA Sept 11 Deadline for Manufacturers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/guide-to-the-eu-cra-sept-11-deadline-for-manufacturers-ovx8kpqci#faq","mainEntity":[{"@type":"Question","name":"What are manufacturers required to do under the EU Cyber Resilience Act starting September 11, 2026?","acceptedAnswer":{"@type":"Answer","text":"Manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform (SRP). An early warning is due within 24 hours of becoming aware of the event, a full notification within 72 hours, and a final report within 14 days after a fix becomes available (or one month after the 72-hour notification for severe incidents). Voluntary reporting under Article 15 is not yet available in the SRP at launch. Teams tracking CRA compliance deadlines can follow regulatory and open source security updates on daily.dev."}},{"@type":"Question","name":"Do open source maintainers have CRA reporting obligations on September 11, 2026?","acceptedAnswer":{"@type":"Answer","text":"No, individual open source maintainers and stewards do not have CRA reporting obligations on this date. Manufacturer reporting requirements take effect September 11, 2026, while steward obligations under Article 24 of the CRA do not begin until December 11, 2027. Maintainers may still be contacted by manufacturers when a reported vulnerability traces to their component, so having a security contact and disclosure process ready is recommended. Maintainers navigating evolving open source security regulations can find related coverage on daily.dev."}}]}
```

