Reporting clock
Both the CRA and the Swedish Cybersecurity Act run their reporting deadlines from the moment you become aware, not from when you finish investigating. Put that moment in and get the actual dates, in your own timezone, in a form you can paste into a ticket.
What this does not tell you
It calculates dates. It does not decide whether you have a reportable event, and that is the harder question. Under the CRA the trigger is an actively exploited vulnerability, meaning reliable evidence of real-world exploitation rather than a proof of concept or a high severity score, or a severe incident affecting the security of the product. Under the Cybersecurity Act it is a significant incident, judged on operational disruption and impact.
It also does not tell you where to file. For the CRA that is the coordinator CSIRT for your member state plus ENISA, through the Single Reporting Platform. For NIS2 in Sweden it is your sector supervisory authority, with registrations handled by NCSC since 1 July 2026.