What takes effect on 11 September
On 11 September 2026, the reporting obligation in the EU Cyber Resilience Act comes into force. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe security incidents to the authorities.
There are three deadlines, and they are short:
- 24 hours: early warning, counted from the moment you become aware.
- 72 hours: full notification with a description and the measures taken.
- 14 days: final report, counted from when a corrective measure is available. For severe incidents the deadline is one month.
Reports go through a shared reporting platform, the Single Reporting Platform, managed by the EU cybersecurity agency ENISA. You report once, and the platform routes it to the relevant national CSIRT, which in turn shares the information with other countries where the product is sold. According to the European Commission, the platform is due to be operational on 11 September.
"We do not manufacture products"
That is the most common reaction to the CRA, and it is wrong more often than it is right.
"Product with digital elements" is defined broadly. Forefront summarises it as essentially all software and all hardware that can connect to a network, directly or indirectly. If you sell an app, a cloud service, an integration, a connected product or software under your own name on the EU market, you are a manufacturer in the meaning of the regulation. Being five people in Gothenburg without a factory changes nothing.
It does not stop there. Importers and distributors who make substantial modifications to a product are also classified as manufacturers, with a manufacturer's full responsibility.
It also covers what you have already sold
This is where September 2026 differs from the rest of the regulation, and it is the detail that surprises most people.
The bulk of the CRA requirements, meaning security requirements in the design, technical documentation and CE marking, apply from 11 December 2027 and then to new products. The reporting obligation is the exception. It applies from 11 September 2026 and covers products already placed on the market.
In other words: a vulnerability in something you launched in 2023 and barely think about any more can start a 24 hour clock next month.
24 hours is no time to improvise
The clock starts when you become aware, not when you have decided what you think. In practice the deadline therefore expires in the middle of the phase where you are still trying to understand what actually happened.
What decides whether you make it is rarely technology. It is three things that are either written down or they are not:
- Who receives the alert. Is there an address where a security researcher or customer can report, and does anyone read it on a Sunday?
- Who decides. A named person allowed to make the "actively exploited or not" call without first convening a meeting.
- Who writes the notification. Find out how the reporting platform works before you need it, and keep a template with the required fields. Nobody drafts well from zero at 11pm.
Setting this up takes an afternoon. Doing it under pressure takes considerably longer.
What does not trigger a report
For the sake of honesty, since a fair amount of panic gets sold around new EU rules: the obligation covers vulnerabilities that are actually being exploited by an attacker. A vulnerability found in good faith, for example in your own testing or through a bug bounty programme, is according to Traficom not in itself reportable.
And if you sell no software or hardware under your own name, and merely use other people's products, you are not a manufacturer. The relevant question then becomes what your suppliers do, which is the same mechanic as in the Swedish cyber security act and NIS2: the requirements reach you through the chain rather than directly.
What we recommend
- Determine whether you are a manufacturer. Do you sell something with code in it, under your own name, on the EU market? Then the answer is probably yes. Write down the conclusion and the reasoning behind it.
- Inventory what you have out there. Including older versions and things you have stopped developing. What you have forgotten about is still covered.
- Appoint someone responsible, and a deputy. A 24 hour deadline takes no account of holidays.
- Write the routine down on one page. Who raises the alert, who assesses, who reports, in what order. One page that actually exists beats a framework that is going to be developed.
- Run it once as a drill. Take an invented vulnerability and walk the chain. The gaps show up within twenty minutes.
This is exactly the kind of work included in our IT consulting: documented routines in plain language, sized for your business rather than for a certification project. They are kept alive over time through Managed IT. Want to know whether you are a manufacturer in the CRA sense, and what that requires if you are? Book a free consultation and we will go through it together.