Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA reporting deadlines and information

Last updated:

Stage Actively exploited vulnerability Severe incident
Early warning without undue delay and within 24 hours of awareness without undue delay and within 24 hours of awareness
Notification without undue delay and within 72 hours of awareness without undue delay and within 72 hours of awareness
Final report no later than 14 days after a corrective or mitigating measure becomes available within one month after the 72-hour notification

Prepare

Assign a process owner and backups, check who has assigned JISKB access, and rehearse an out-of-hours scenario. Select the correct entry point through the SK-CERT route page: a CRA-related vulnerability is directed to CVD, while the incident route differs according to JISKB access. ENISA’s SRP FAQ also describes the current information set. Follow the fields and instructions in the selected channel.