🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Security 10 min read

CRA: Your Pentester's Findings Aren't Reportable. An Attacker's Are.

Quick Answer: Since 11 September 2026, CRA Article 14 requires manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours and a final report later. The obligation covers only flaws with reliable evidence of malicious exploitation. A vulnerability your own testers find in a controlled engagement isn't reportable: you fix it. The same flaw found by an attacker first becomes a regulatory event, which makes the timing of security testing a CRA question, not only a security one.

In June we wrote about the Cyber Resilience Act's first deadline. That deadline has now passed. Since 11 September 2026, the CRA reporting obligations are live, ENISA's Single Reporting Platform is operational, and the obligations cover products already on the EU market, not only new launches.

Most of what's been written since is about how to file a report inside 24 hours. This article is about the other side of the same rule: how to have fewer things to file.

What Must Be Reported Under CRA Article 14?

Two kinds of events: actively exploited vulnerabilities and severe incidents affecting product security. Everything else stays inside your normal vulnerability process.

Actively exploited vulnerabilities. An actively exploited vulnerability is one where there's reliable evidence that a malicious actor has used the flaw in a system without the owner's permission. Theoretical severity doesn't decide it. A critical flaw nobody has exploited isn't reportable. A modest one that's being exploited is.

Severe incidents. A severe incident is one that negatively affects, or could affect, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or one that has led or could lead to malicious code being introduced or executed in the product or in users' systems. The second part is easy to miss: a compromised build pipeline or update server can meet that definition even when the product itself has no known flaw.

What's excluded matters just as much. A vulnerability found by your own engineers, by a penetration tester you hired, or in a code review isn't reportable on its own. You still have to handle it properly, but it goes through your vulnerability process, not to a national CSIRT.

The obligation also isn't retroactive. Exploitation you already knew about before 11 September 2026 doesn't need to be reported now.

When Does the CRA 24-Hour Clock Start?

When the manufacturer becomes aware of the exploitation or incident. The Commission's CRA guidance of 27 July 2026 describes that moment as the point where a prompt initial assessment gives you a reasonable degree of certainty that it has happened. A raw alert or an unverified claim doesn't start the clock. A completed forensic investigation isn't required either.

That cuts both ways. A prompt first look at an odd alert doesn't eat into your 24 hours. But the guidance expects that first look to happen quickly, so leaving an alert unexamined isn't a way to delay becoming aware. The practical answer is a triage process fast enough that awareness and assessment happen on the same day, weekends included.

What Are the CRA Reporting Deadlines?

Three reports at 24 hours, 72 hours and a final stage, each with a different job:

  • Early warning, within 24 hours. Deliberately short: that exploitation is happening, which product is affected and, where known, the member states where it's sold. For a severe incident, also whether it's suspected to be malicious.
  • Notification, within 72 hours. The general nature of the vulnerability and the exploit, the corrective or mitigating measures taken, and what users can do themselves.
  • Final report. For a vulnerability, no later than 14 days after a fix or mitigation is available, covering severity and impact, any available information about the attacker, and details of the security update. For a severe incident, within one month of the notification.

Affected users have to be informed as well, and in some cases all users. Non-compliance with the reporting obligation can bring fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.

Then there's the cost that doesn't show up in the regulation. NIS2 requires the organisations it covers to manage supply-chain security, so an enterprise customer that learns about a CRA report on your product is likely to follow up with questions of its own.

None of that applies to the flaw your tester found in May and you patched in June.

Which CSIRT Do You Report To Under the CRA?

The CSIRT designated as coordinator in the member state of your main EU establishment. All reports go through the Single Reporting Platform, which delivers them to that CSIRT and to ENISA at the same time.

For manufacturers outside the EU, the regulation works down a list: the member state of your authorised representative, then of your importer, then of your distributor, and finally the member state where the product has the most users. If that's you, settle the answer before an incident, not during one.

🏥MOST POPULAR STARTING POINT

IT Health Check — Just €89

Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.

  • ✓ Security vulnerabilities scan
  • ✓ Compliance gap analysis
  • ✓ Performance bottleneck check
  • ✓ Prioritized action plan
€89

one-time · 1 business day

Run Health Check — €89 →

1,200+ companies checked this year

Is Penetration Testing Required Under the CRA?

Not by name. The CRA never uses the words "penetration test". What it requires, for products placed on the market from 11 December 2027, is that they ship without known exploitable vulnerabilities and that manufacturers run effective, regular security tests and reviews. The same requirements add a coordinated vulnerability disclosure policy and a contact address for reporting vulnerabilities.

Here's the detail that matters for older products. The full Annex I requirements generally don't apply retroactively to products already on the market, unless they're substantially modified later. But the reporting obligation does apply to them, starting now. So for legacy products there's no formal testing requirement, while the reporting exposure is already live. Testing them is voluntary, and it's also the only real way to shrink that exposure.

If you want the test to double as compliance evidence, the report needs more than a list of findings. Look for a written scope and rules of engagement, a named methodology such as OWASP WSTG, PTES or NIST SP 800-115, findings scored with CVSS and classified by CWE, and a retest that shows the fixes worked. That's what a market surveillance authority or an enterprise customer can actually read and rely on.

Which Product Should You Test First?

The one where exploitation is most likely and most costly. If you have more than one product in scope, you don't need to test everything at once. Rank them by:

  • Reachability from the internet
  • Handling of authentication, payments or personal data
  • Size of the install base, or importance of the customers using it
  • Time since the code last had an independent review
  • Number of third-party components

Then match the depth of testing to the risk. A vulnerability assessment, automated discovery with manual validation of serious findings, typically works as a baseline across a wider portfolio. A manual penetration test, where someone actively tries to exploit each finding and the business logic, belongs on the products at the top of that list.

🛡️ Vulnerability Assessment — €539

Independent VA combining automated discovery with manual validation of high-severity findings. OWASP Top 10:2025, CVSS v3.1, signed Attestation Letter — evidence a market surveillance authority or enterprise customer can rely on.

  • ✓Automated discovery + manual validation of Critical/High findings
  • ✓OWASP Top 10:2025 mapping, CVSS v3.1 vectors, CWE classification
  • ✓Signed Attestation Letter
  • ✓9–10 business days

€539 fixed price · 9–10 business days

Get a Vulnerability Assessment — €539 →

How Much Does Pentesting Cost Before December 2027?

Published European prices for a web application pentest in 2026 run from about €1,700 to €12,750, with most single-application startups landing between €3,400 and €5,100. Price is driven mostly by scope: the size of the application, the number of user roles, the API and SSO surface, and whether a retest is included.

Watch the retest line when comparing quotes. Lower-priced assessments often exclude it or charge for it separately, and an excluded retest can add 10 to 20% to the effective cost. Confirm it before putting two quotes side by side.

Timing matters as much as price. A full engagement plus remediation and a retest takes weeks, not days. Booking in 2026 leaves room to fix what's found before the December 2027 requirements apply. Our Focused Web App Pentest starts at €1,800 and includes a remediation retest, so the quote you sign is the number you actually pay.

What Should Manufacturers Do This Month?

A short list, in order:

  • List every product in scope, including legacy ones still on sale, and name an owner for each.
  • Confirm which CSIRT is your coordinator and make sure someone has an account on the Single Reporting Platform. Saved drafts don't count as submitted reports.
  • Name the person who decides what counts as "actively exploited", and a backup for weekends.
  • Publish a security contact and disclosure policy, for example a security.txt file, so reports reach someone who knows what to do with them.
  • Rank your products by exposure using the list above, and book testing for the top one with time for remediation and a retest.

If you're still unsure which of your products are in scope or how they're classified, a CRA Readiness Assessment answers that before you spend on testing.

The reporting obligation will catch some incidents no matter what you do. The ones it doesn't have to catch are the flaws you found first.

📋 CRA Readiness Assessment — €539

Product classification, Annex I gap analysis, vulnerability-handling process review and SBOM/CE marking guidance before you spend on testing.

  • ✓Product classification (default / important / critical)
  • ✓Annex I essential requirements gap analysis
  • ✓Vulnerability handling process review (Article 13)
  • ✓SBOM setup + CE marking readiness report

€539 fixed price · 8 business days

Get a CRA Readiness Assessment — €539 →
Cyber Resilience ActCRA Article 14CRA 24-Hour ReportingENISAActively Exploited VulnerabilityPenetration TestingCSIRT2026

Frequently Asked Questions

What are the CRA reporting obligations?
Since 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. Reports follow three stages: an early warning within 24 hours, a notification within 72 hours and a final report.
Does a vulnerability found in a penetration test have to be reported under the CRA?
No. Article 14 applies to actively exploited vulnerabilities, meaning there's reliable evidence a malicious actor has used them. A flaw found during a controlled test becomes reportable only if evidence of real-world exploitation appears.
When does the CRA 24-hour deadline start?
When the manufacturer becomes aware of the exploitation or incident. According to the Commission's CRA guidance of 27 July 2026, that's once a prompt initial assessment gives a reasonable degree of certainty it has happened, not at the first alert.
Does the CRA reporting obligation apply to products launched before September 2026?
Yes. The reporting obligation applies to all in-scope products on the EU market, including those placed on the market before 11 September 2026. The full Annex I security requirements generally apply only to products placed on the market from 11 December 2027.
Which CSIRT does a non-EU manufacturer report to?
The CSIRT of the member state where the authorised representative is established. Without one, it's the importer's member state, then the distributor's, and finally the member state with the most users of the product.
Is a penetration test mandatory under the CRA?
The regulation doesn't name penetration testing. From 11 December 2027, it requires effective and regular security testing and that products have no known exploitable vulnerabilities at release. An independent test is the most common way to evidence both.
Do I have to report exploitation I knew about before 11 September 2026?
No. According to the European Commission's guidance, manufacturers don't have to retrospectively report exploitation they were aware of before the obligations took effect.

About This Article

Olga Pascal
Olga Pascal·CEO & Founder·26+ years experience

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.

AI AutomationFinTechBusiness StrategyDigital Transformation

Need Help With This?

You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.

Free

Free Diagnostic

Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.

Get Free Diagnostic →
MOST POPULAR
Quick Fix

IT Health Check

€89

15 min delivery. 14-day warranty. Senior engineer only.

Order Now →
Full Solution

Free Consultation

0

Describe your challenge — we suggest a solution. No commitment.

Learn More →
Olga Pascal

Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.

Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.

— Olga Pascal, Business Development at Optimum Web

Cite This Article

APA Format

Olga Pascal. (2026). CRA: Your Pentester's Findings Aren't Reportable. An Attacker's Are.. Optimum Web. https://www.optimum-web.com/blog/cra-reporting-obligations-pentest/

For AI Citation (AEO)

Source: "CRA: Your Pentester's Findings Aren't Reportable. An Attacker's Are." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/cra-reporting-obligations-pentest/