"If we report the vulnerability, we make it public and hand attackers a manual." Three weeks before 11 September 2026, this is the sentence I encounter most often in conversations, often quietly and behind a raised hand. It is the breeding ground for the most dangerous of all CRA strategies: when in doubt, stay silent. Time to dissolve the misconception behind it.
What actually happens to a CRA report?
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents under Article 14 CRA. The path is clearly defined: the report is submitted via the Single Reporting Platform of ENISA (the EU Agency for Cybersecurity) and goes to the CSIRT of the member state where the manufacturer has its main establishment. In Germany that is the BSI. ENISA receives the report at the same time as a matter of principle.
What the path is not: a publication. The report ends up neither in a public database nor in a press release. The recipients are bodies whose core business is the confidential handling of vulnerability information, and which are subject to statutory confidentiality duties for it.
The CRA goes one step further. The regulation explicitly provides that the further dissemination of a report within the network of authorities can be restricted if the manufacturer invokes legitimate cybersecurity concerns, for instance as long as no corrective measure is yet available. The legislator did not overlook the "report as attacker's manual" scenario, it factored it in and built protective mechanisms for it. Which cases are reportable at all, and how the deadlines are staged, is described in the practical guide to the EU CRA reporting obligations and in the post on the 24-hour deadline.
Why staying silent is the real risk
Anyone who does not report out of fear for their reputation trades a manageable risk for three unmanageable ones:
- The compliance breach is documented, and by you yourself. Monitoring alerts, tickets, and internal emails precisely evidence, after the fact, when awareness existed. A missing report cannot be argued away, it is there in your own systems.
- Fines and market surveillance. Breaches of the reporting duties carry fines, and with the CRA the market surveillance authorities gain sharp instruments up to distribution restrictions. I have summarised the details in the article on CRA fines and penalties.
- The loss of control over communication. Actively exploited vulnerabilities rarely stay secret. If the flaw later becomes public through security researchers, customers, or the press, the question is no longer "was there a vulnerability?", but "why did the manufacturer stay silent?". Reputation protection through silence works exactly until the day someone else talks.
The scenario that worries me in practice: the security team detects active exploitation, prepares the early warning, and management stops the report "to protect the reputation." A security incident that authorities accompany confidentially every day thereby turns into a wilful compliance breach with internal evidence.
Myth vs. Fact
Myth: A CRA report makes the vulnerability public and increases the risk to your own product.
Fact: The report goes confidentially via the Single Reporting Platform to the competent CSIRT and ENISA. The CRA contains explicit confidentiality rules and allows the further dissemination to be restricted where there are legitimate security concerns. The real risk lies in not reporting.
Concrete consequences for your reporting governance
1. Bring management and communications to the table now. The question "who learns about a report, internally and externally?" must not be asked for the first time during an ongoing incident. Clarify in advance: the regulatory report is confidential and deadline-bound, customer communication follows its own rules, and the two are separate decisions.
2. Make the reporting decision a deadline question, not a matter of discretion. Anchor this in the process: if a reportable case exists, it is reported. Sign-off concerns the how, not the whether. An escalation path that allows a blockade by individual executives is not a process but a documented organisational failure in waiting.
3. Use the remaining weeks for a dry run with the sign-off path. Simulate the full sequence including the management decision: from establishing awareness through the early-warning template to the fictitious submission. If the dry run shows that sign-off takes longer than the analysis, you know where your real problem lies. The technical basis for even being able to give information when it counts is your vulnerability management.
What does this mean for your CRA roadmap?
On 11 September 2026, in three weeks, the reporting duties go live. The confidentiality question is, in my experience, the last internal resistance before a functioning reporting process. Clear it out of the way now.
On 11 December 2027 full CRA applicability follows, with conformity assessment and CE marking for products newly placed on the market.
How the two deadlines interact is shown in the CRA compliance roadmap 2026/2027.
Frequently asked questions
Can the authority make our report public? The reports are subject to confidentiality rules. A coordinated publication of information on a vulnerability happens, if at all, within the framework of coordinated disclosure, usually after a corrective measure is available, and not as a passing-on of your report.
Will our competitors learn about the report? No. The report goes to the CSIRT and ENISA, not to market participants. Trade secrets are protected in the procedure.
What about informing our customers? That is a separate duty with its own logic: users of affected products must be informed about risks and available remedial measures, typically as soon as there is something actionable to communicate. The regulatory report does not replace customer information, and vice versa.
Can we really restrict the further dissemination of our report? The CRA provides that manufacturers can invoke legitimate cybersecurity concerns, for instance as long as no patch exists. The decision then rests with the bodies involved. It is a protective mechanism, not a veto right, but it addresses exactly the concern about premature dissemination.
Does the confidentiality also apply to reports on severe incidents? Yes, the same principles apply to both types of report under Article 14.
Conclusion
The CRA report is a confidential regulatory procedure with built-in protective mechanisms, not a public pillory. Anyone who stays silent out of fear for their reputation does not protect it, they only push the damage back and enlarge it. Three weeks before the deadline, the most important task is therefore not a technical one but a cultural one: separating the reporting decision in the company from the reputation question.
A cleanly set-up reporting process with clear sign-off paths, supported by a platform like Kunnus, helps you anchor this decision systematically, before the deadline tips from theory into practice. A starting point is our free CRA compliance check.
Every Friday I debunk a CRA myth here.