Cyber Resilience Act · Reporting starts 11 September 2026

You get 24 hours.
Does your on-call engineer know that?

Everyone is preparing for the Cyber Resilience Act's 2027 requirements. The reporting duty starts earlier: from 11 September 2026, an actively exploited vulnerability in your product must reach ENISA and your national CSIRT within 24 hours of you becoming aware of it.

days
hours
minutes

until Article 14 reporting obligations apply

Get report-ready — €99 Free: generate your intake channel

Built on Regulation (EU) 2024/2847 and the Commission's CRA reporting guidance. An operations toolkit, not legal advice.

24 hours is not a policy problem. It's an operations problem.

The clock starts when you become aware — which may be a Saturday night, from a stranger's email. If the person who reads that email doesn't know a duty exists, the deadline is already gone.

≤ 24h — early warning

An actively exploited vulnerability, or a severe incident affecting your product's security, gets a minimal first notification. Partial information is expected — silence is not.

≤ 72h — full notification

Nature of the vulnerability or incident, affected versions, mitigations available, indicators of compromise where you have them.

≤ 14 days / 1 month — final report

After a corrective measure is available (vulnerabilities), or within a month (severe incidents): root cause, fix, remediation status.

Who this hits: manufacturers of products with digital elements made available in the EU — software included, wherever your company is based. One submission on the ENISA Single Reporting Platform reaches your CSIRT and ENISA together.

Free: the intake channel that starts your clock on time

Your 24 hours run from awareness. Hearing it from a researcher on Tuesday beats reading it on social media on Friday. Generate a valid security.txt (RFC 9116) and a coordinated disclosure policy in one minute. No signup, nothing leaves your browser — a coordinated disclosure policy is also mandatory in the CRA's 2027 phase, so this is a free head start.

Without https:// — used to build the canonical URL.

Must reach a human fast — an alias to your on-call, not a weekly ticket queue.

/.well-known/security.txt

Serve security.txt at https://yourdomain/.well-known/security.txt as text/plain. The Expires field is mandatory under RFC 9116 — we set it 12 months out, so put a calendar reminder to refresh it.

The Report-Ready Kit — the other 23 hours and 50 minutes

The generator opens the channel. The Kit is what happens when a report arrives: is this even reportable, who decides, what exactly gets filed, and what proves you did it on time.

Built to install this afternoon, not to book a call

Consultancies sell CRA readiness as a custom engagement with a quote on request. This is the opposite: a fixed price, downloaded now, run by your own team the same day.

One fixed price

€99, whole company, all products. No scoping call, no rate card on request, no "contact sales" — you see the price before you decide.

Self-serve, same day

Download, read, and wire the intake channel and runbook yourself. Time-to-ready is an afternoon, not a multi-week engagement.

Built for small teams

Written for the software house without a compliance department — the segment consultancies price out. Plain operations, not a framework to learn.

Questions you should be asking

Isn't the CRA a 2027 problem?

Its essential requirements, CE marking and conformity assessment are — 11 December 2027. The reporting obligations under Article 14 start on 11 September 2026, more than a year earlier. That gap is the whole reason this kit exists.

We're pure SaaS. Are we in scope?

Probably not for the CRA — cloud services largely sit under NIS2 instead. The trap is remote data processing that is part of a product you ship: the backend your app or device needs to work comes into scope with the product. The kit's scope check walks this properly, and tells you when the answer is "no".

What counts as "actively exploited"?

Evidence of real-world exploitation — observed attacks, exploitation confirmed in the wild, a credible report of in-the-wild abuse. Not a CVE with no known exploitation, not a pentest finding, not a theoretical proof of concept. Awareness of exploitation starts the clock, not awareness of the bug.

What if we're not sure whether to report?

File the early warning. It is deliberately minimal, it is not an admission of fault, and the duty is triggered by awareness. Regulators penalise silence, not caution — the runbook makes this the default so nobody has to make a judgement call at 2am.

Is this legal advice?

No. It's an operations toolkit built on the regulation and the Commission's reporting guidance. For classification edge cases, ask counsel — with this in hand you'll be asking a €300 question instead of commissioning a project.

Sooner on the calendar

2 August 2026: your chatbot must say it's an AI

EU AI Act Article 50 lands first: AI interactions disclosed in the interface, AI-generated content labelled. Free widget, same one-afternoon approach.

See AI Disclosure →