Regulation (EU) 2024/2847
CRA executive briefing: what changes on 11 September 2026
A ten-minute briefing on the Cyber Resilience Act reporting duty for decision-makers. What changes, who it lands on, and what to do in the next two weeks.
Free, no email required. Copy it, forward it, paste it into a deck.
What changes on 11 September 2026
From that date, a manufacturer who becomes aware that a vulnerability in their product is being actively exploited has a reporting duty with a clock attached. General application of the Cyber Resilience Act follows on 11 December 2027, but the reporting duty does not wait for it.
- 24 hours: early warning notification of an actively exploited vulnerability, to CSIRT designated as coordinator, and ENISA (Article 14(2)(a)).
- 72 hours: vulnerability notification (Article 14(2)(b)).
- 14 days: final report (Article 14(2)(c)).
Who it lands on
Of the 114 obligations in the Regulation as we have mapped it, 95 attach to the manufacturer. Importers and distributors carry a small number each. If you put software or a connected product on the EU market under your own name, the manufacturer role is almost certainly yours, and the exceptions are narrower than most teams assume.
Why this is an operations problem, not a legal one
The obligation is not hard to understand. It is hard to execute at 2am on a Saturday. The 24-hour clock runs from the moment you become aware, not from the moment the right person is told, not from confirmation, and not from the start of the next business day.
The failures are consistently the same three: nobody was named, so the first hours went on finding out who does this; the trigger was never defined, so the team argued about whether the clock had started while it ran; and nobody had walked the submission route, so it was learned under time pressure.
What to do in the next two weeks
None of this requires a budget line, and all of it is faster to do now than during an incident.
- Name one owner and one backup, and put both in the on-call rota rather than in a document.
- Write down what counts as active exploitation for your product, and get the on-call owner to agree to it in advance.
- Identify your coordinating CSIRT and walk the submission route far enough to know what it asks for.
- Publish a vulnerability disclosure contact that reaches a human within hours.
- Draft the early warning template once, with the fields blank.
What this briefing does not tell you
It does not state penalties. Article 64 sets them and we do not model them, so the figure belongs in the Official Journal rather than in a vendor briefing.
It covers Article 14(2), actively exploited vulnerabilities. Article 14(4) severe incidents runs on separate timings with a final report due within one month, and is not modelled here.
The obligation mapping is corpus v1.0.0, updated 2026-08-13, extracted from EUR-Lex CELEX:32024R2847, consolidated HTML, extracted 2026-08-13. Descriptions are verbatim Official Journal text; the commentary is ours and has not been counsel-reviewed. This is operational guidance, not legal advice.
Questions
- What does the CRA change for us on 11 September 2026?
- From that date the Article 14 reporting obligations apply. Becoming aware that a vulnerability in your product is being actively exploited starts a 24-hour clock ending in a report to the CSIRT designated as coordinator, and ENISA. The essential requirements do not apply until 11 December 2027.
- Do we have until December 2027?
- For the essential requirements, yes. For reporting, no. The two dates are fifteen months apart and the earlier one is the one that needs a named person and a rota rather than an engineering programme, which is why it is often the one missed.
- What should we do in the next two weeks?
- Determine whether the CRA reaches your products at all, name a reporting owner and a backup, and write down what counts as active exploitation for your product. None of the three costs money and the first 14 days of an incident are far cheaper with them in place.
- What are the penalties under the CRA?
- Article 64 sets them. We do not model penalties in our corpus, so we do not quote a figure; take the number from the Official Journal rather than from a vendor page, including this one.