Free online session · Regulation (EU) 2024/2847
CRA reporting starts 11 September
What manufacturers must do in the first 24 and 72 hours
Thursday, 3 September 2026 · 15:00 Berlin · 16:00 Athens · 14:00 London · 60 minutes
What changes on 11 September
From that date, becoming aware that a vulnerability in your product is being actively exploited starts a 24-hour clock, with a fuller notification at 72 hours. A severe incident affecting the security of the product is a separate duty with its own timings. The clock runs from when you became aware, not from when you got round to looking, which is the detail most readiness plans get wrong.
This is a working session, not a product pitch. You should leave able to say who in your organisation decides that awareness has occurred, and what the next two deadlines would be.
Agenda
- 10 minWho must report from 11 September
- 10 minActively exploited vulnerability versus severe incident
- 10 minThe 24-hour, 72-hour and final-report clocks, and why the last one differs
- 10 minLive simulation: a vulnerability discovered Tuesday at 10:15
- 10 minReadiness checklist you can take away
- 10 minQuestions
The part worth attending for
We simulate a vulnerability discovered on a Tuesday at 10:15 and walk through exactly what happens next: when the early warning is due, when the notification is due, why the final report has no due date yet, and what information you would still be missing at each point.
Who this is for
Product security and security leadership, CTOs, and the compliance or legal colleagues who will be asked what the deadline was. Software manufacturers, connected-device and IoT teams, and anyone placing a product with digital elements on the EU market.
Register
Cannot attend?
Run the readiness check now instead. It is free, needs no email, no account, and nothing is stored.