Product safety
CRA Reporting Starts on 11 September: What China Importers Need from Digital-Product Manufacturers
ENISA updated its FAQ for the CRA Single Reporting Platform on 4 September 2026. The platform is scheduled to begin mandatory reporting on 11 September 2026 for actively exploited vulnerabilities and serious security incidents.

What changes on 11 September 2026?
The CRA Single Reporting Platform is scheduled to become operational for mandatory reports on 11 September 2026. ENISA updated its FAQ for the platform on 4 September 2026 and described the launch date, the reporting types initially available and the applicable deadlines.
CRA means the Cyber Resilience Act. In this context, the Cyber Resilience Act is the EU regulation associated with requirements for products with digital elements and related security processes. For China importers, the immediate issue is not automatically that they must file a report for every imported product. The practical issue is whether the importer has reliable manufacturer evidence before placing the product on the EU market and can demonstrate that the required checks were carried out.
Only mandatory reports are planned for the platform at launch. Voluntary reporting is not expected to be available at that point. This distinction matters for internal planning: an importer should not treat the platform as a general voluntary notification channel when a manufacturer or another responsible party has to handle a reportable event.
Which events must manufacturers report?
Manufacturers must report actively exploited vulnerabilities and serious security incidents affecting products with digital elements. The reporting duty therefore concerns specific security events rather than the mere fact that a product was sourced from China.
An actively exploited vulnerability is a security weakness that is being actively exploited. A serious security incident is a security event affecting a product with digital elements that falls within the CRA reporting category described by the supplied facts. The research material does not provide an additional decision tree for classifying every incident. You should therefore avoid treating an unverified internal threshold as a complete legal test.
Reports are submitted through a single platform. The European Commission confirms that reporting obligations begin on 11 September 2026 and that reports are made through one platform. ENISA’s updated FAQ states that the initial service is intended for mandatory reporting types.
What are the reporting deadlines?
The early warning must be submitted within no more than 24 hours. The complete initial report must follow within no more than 72 hours.
For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective measure becomes available. For a serious security incident, the final report is due within one month.
| Reporting step | Deadline | Importer consequence |
|---|---|---|
| Early warning | No more than 24 hours | The manufacturer needs a process that escalates relevant information immediately. |
| Complete initial report | No more than 72 hours | The first complete report cannot be planned only after the entire root-cause analysis is finished. |
| Final report for an actively exploited vulnerability | No later than 14 days after a corrective measure becomes available | The date on which the corrective measure became available must be traceable. |
| Final report for a serious security incident | Within one month | The manufacturer needs a process for further investigation and closure. |
The deadlines do not answer every operational question. You should agree with the Chinese manufacturer on when it treats an event as reportable, who starts the internal clock and how the importer will be informed. The supplied sources establish the deadlines but do not provide a separate contractual template for importer–manufacturer communications.
Is the China importer the reporting manufacturer?
China importers are often not the reporting manufacturer party. This is a cautious classification because the applicable role depends on the specific product and distribution situation, and the supplied facts do not provide a complete role assessment for every transaction.
The importer still has a concrete verification and evidence task. Before placing the product on the market, you must check, among other things, the manufacturer’s conformity assessment, technical documentation, CE marking, EU declaration of conformity and understandable user information.
“Placing on the market” is used here for the point before the digital product is made available on the EU market. The importer should therefore request the documents during sourcing and product approval, not only after the goods arrive or after a security incident occurs. The check belongs in the purchasing and release process.
You should also distinguish between checking the manufacturer’s documents and filing a security report. The supplied facts confirm the listed checks and the reporting deadlines for manufacturers. They do not establish that every importer must automatically submit every report itself.
Which documents should the manufacturer provide?
The manufacturer should provide the documents and information needed for the importer to check the listed CRA requirements. The research material identifies five central document groups.
- Evidence of the conformity assessment: Ask how the manufacturer carried out the conformity assessment and which records support it.
- Technical documentation: Request the technical documentation before placing the product on the market and check that it relates to the exact product.
- CE marking: Check that the product bears the required CE marking.
- EU declaration of conformity: Request the manufacturer’s EU declaration of conformity and archive its link to the product.
- Understandable user information: Check that the user information is available in an understandable form.
For this article, the CE marking is not merely a graphic on a package or product. It is one of the items the importer must check as part of the compliance review. The CE marking does not replace the EU declaration of conformity or the technical documentation.
An EU declaration of conformity is the manufacturer’s declaration concerning the product’s conformity. The importer should therefore not rely only on a photograph of a CE mark on the packaging. A complete declaration should be stored in the product file.
Which manufacturer security processes should you check?
You should request a traceable manufacturer process for vulnerabilities and security incidents. The research material confirms the reporting events and deadlines but does not prescribe one single process template, so the review should focus on evidence of the manufacturer’s actual procedures.
Ask the manufacturer to document at least the following points:
- Who receives and assesses security events.
- How actively exploited vulnerabilities are detected and escalated internally.
- How a serious security incident is recorded.
- Who prepares the early warning within no more than 24 hours.
- Who is responsible for the complete initial report within no more than 72 hours.
- How the date of an available corrective measure is recorded.
- How the final report for an actively exploited vulnerability is prepared within the 14-day deadline.
- How the final report for a serious security incident is prepared within one month.
- How and when the importer is informed about a report, corrective measure and final report.
This list is a practical import-control tool, not an additional statutory checklist derived from facts that were not supplied. It helps you distinguish a general assurance from a documented security process.
Which evidence should you request before ordering?
You should request the CRA-related evidence before committing to the product and not only after shipment. Early collection reduces the risk of placing goods on the EU market without documents that can be clearly linked to the product.
Practical document checklist
- Request the EU declaration of conformity for the exact product model.
- Request the technical documentation for the same model and product variant.
- Link the CE marking on the product to the available product documentation.
- Request understandable user information.
- Ask the manufacturer to describe its process for actively exploited vulnerabilities.
- Ask the manufacturer to describe its process for serious security incidents.
- Record the responsible communication contacts and escalation routes.
- Store the received files with the product model, version and date received.
- Check before placing the product on the market that the evidence is complete and clearly linked.
- Record unresolved points and release the product only after evaluating them.
The checklist does not prove that the product is compliant by itself. It creates a documented basis for showing that the manufacturer evidence identified in the supplied requirements was actually reviewed.
How long must an importer retain the EU declaration of conformity?
An importer must retain the EU declaration of conformity for at least ten years after the product is placed on the market or for the duration of the support period, whichever is longer. The retention period is therefore not automatically limited to ten years.
For each product, record the date it was placed on the market and the applicable support period. If the support period exceeds ten years, the longer period applies according to the supplied facts. If no longer period applies, the ten-year minimum remains relevant.
The archive should link the declaration to the specific product, model and manufacturer. An unnamed attachment without a product reference makes it harder to demonstrate that the correct declaration was retained.
What does the platform launch mean for supplier communication?
You should treat 11 September 2026 as a fixed date for a supplier check. The platform is scheduled to be operational for mandatory reporting on that date, so the Chinese manufacturer should identify an available security contact and an internal escalation route before the launch.
A request asking whether the supplier is simply “CRA compliant” is not sufficient for an operational review. A general answer does not show which documents exist, who assesses security events or how the 24- and 72-hour deadlines are handled.
A more useful request can ask for the following evidence:
- EU declaration of conformity for the specific product.
- Technical documentation linked to the product version.
- Evidence of the CE marking.
- Understandable user information.
- Description of the reporting process for actively exploited vulnerabilities.
- Description of the reporting process for serious security incidents.
- A named contact for time-critical information.
- A process for informing the importer about corrective measures and final reports.
This request does not replace a case-specific legal assessment. It does show whether the manufacturer responds with concrete documents and processes or only with a general statement.
What is established and what remains uncertain?
The updated ENISA FAQ dated 4 September 2026 is an established part of the supplied record. The scheduled platform launch on 11 September 2026, the initially mandatory-only reporting, the two event types and the stated deadlines are also established by the supplied sources.
The requirement for an EU importer to check the manufacturer’s conformity assessment, technical documentation, CE marking, EU declaration of conformity and understandable user information is also established in the supplied material. The retention rule for at least ten years or the longer support period is likewise established.
The exact legal classification of every import transaction remains open on the supplied facts. Not every importer necessarily has the same role, and the sources do not support a blanket statement that every importer must personally submit every report.
The detailed technical fields and workflows available for each case after the platform launch also remain open on the supplied facts. The supported statement is limited to the platform being intended to operate for mandatory reports and to reports being made through a single platform.
What should you do now?
You should add a documented CRA review to your product-release process before placing digital products on the EU market. The following steps connect the established requirements with a practical import control:
- List the digital products and the responsible Chinese manufacturer for each product.
- Request the five central evidence groups: conformity assessment, technical documentation, CE marking, EU declaration of conformity and user information.
- Link every document to the exact model and product version.
- Ask the manufacturer to describe its processes for actively exploited vulnerabilities and serious security incidents.
- Record the contacts for time-critical information.
- Check how the early warning within no more than 24 hours and the complete initial report within no more than 72 hours are prepared.
- Document how corrective measures and final reports are tracked.
- Record the date the product is placed on the market and the support period.
- Retain the EU declaration of conformity for at least ten years or the longer support period.
- Record missing evidence and unresolved case-specific questions in writing before release.
The central operational issue is evidence before market placement. A CE mark without a linked declaration, technical documentation and understandable user information does not constitute a complete importer file under the requirements used for this article.
Sources
This article is based on ENISA’s FAQ for the CRA Single Reporting Platform, updated on 4 September 2026, the European Commission’s CRA reporting information dated 31 July 2026 and Article 19 of Regulation (EU) 2024/2847, the Cyber Resilience Act.
Sources
Research checked on 2026-09-07. The following original sources support the factual claims:
- ENISA – All you need to know about the CRA Single Reporting Platform – Frequently Asked Questions (2026-09-04): ENISA nennt den 11. September 2026 als Starttermin der Plattform, beschreibt die zunächst ausschließlich verpflichtenden Meldungen sowie die beiden meldepflichtigen Ereignistypen und die 24-, 72- und 14-Tage- beziehungsweise Monatsfristen.
- European Commission, Directorate-General for Communications Networks, Content and Technology – Cyber Resilience Act – Reporting obligations (2026-07-31): Die Kommission bestätigt den Beginn der Meldepflichten am 11. September 2026, die Meldung über eine einzige Plattform und die Fristen von 24 Stunden, 72 Stunden, 14 Tagen und einem Monat.
- EUR-Lex / European Union – Regulation (EU) 2024/2847 – Cyber Resilience Act (2024-11-20): Artikel 19 verpflichtet Importeure zur Prüfung von Konformitätsbewertung, technischer Dokumentation, CE-Kennzeichnung, EU-Konformitätserklärung und Nutzerinformationen sowie zur Aufbewahrung der Konformitätserklärung für mindestens zehn Jahre oder für den längeren Supportzeitraum.
Reading aid
Glossary terms in this article
These terms occur in the article. Hover over a highlighted term or open its entry for the full explanation.
- EU Declaration of Conformity
- The EU Declaration of Conformity is the manufacturer’s confirmation that a product meets the applicable EU requirements.
- Technical documentation
- Technical documentation collects the evidence, drawings, test reports and risk assessments for a product.
FAQ
When must CRA reports be submitted through the platform?
The CRA Single Reporting Platform is scheduled to be operational on 11 September 2026. According to the supplied information, only mandatory reports are planned at launch; voluntary reports will not yet be available.
Which events must be reported?
Manufacturers must report actively exploited vulnerabilities and serious security incidents affecting products with digital elements. The early warning deadline is no more than 24 hours, followed by a complete initial report within no more than 72 hours.
Does every China importer have to file the CRA report itself?
China importers are often not the reporting manufacturer party. The exact role depends on the case. Regardless of that role, importers must check the relevant manufacturer evidence and be able to demonstrate the checks before placing the product on the market.
Which CRA documents should the manufacturer provide?
Request the conformity assessment, technical documentation, CE marking, EU declaration of conformity and understandable user information. The documents should be clearly linked to the exact product and, where relevant, its version.
How long must an importer retain the EU declaration of conformity?
The declaration must be retained for at least ten years after the product is placed on the market. If the support period is longer, the longer period applies according to the supplied facts.
What should an importer do before 11 September 2026?
List the manufacturers and product versions, request the five central evidence groups, identify security contacts and document the processes for the 24-hour, 72-hour, 14-day and one-month deadlines.