A Deadline That Does Not Wait for Its Own Tool

Starting September 11, 2026, any manufacturer selling a product with digital elements into the EU must report an actively exploited vulnerability within 24 hours of becoming aware of it, under Article 14 of the Cyber Resilience Act. The European Commission's own guidance, issued in March 2026, sets the bar for becoming aware at a reasonable degree of certainty that exploitation is happening, not a completed forensic investigation. An open investigation is, in the Commission's own words, in principle no defence for missing the 24-hour clock.

The single channel for that report, ENISA's Single Reporting Platform, only becomes fully operational on the same date the obligation takes effect. As of 29 June 2026 the platform was confirmed not yet live, according to the compliance tracker cyberresilienceact.eu, and ENISA's own FAQ for the tool describes it as having undergone user and security testing before launch, with further review and re-testing planned as necessary afterward. A legal deadline with zero tolerance for delay meets a reporting tool with zero history of live incident traffic on the exact day both start.

The Coverage Is Wider Than a New Product Launch

The obligation reaches far beyond newly certified EU hardware. Legal guidance from Crowell and Moring confirms the Cyber Resilience Act applies to manufacturers both inside and outside the EU who market connected products in the EU market, and that non-EU manufacturers selling into the bloc are equally fully subject to the regulation, including Article 14 reporting. That includes UK manufacturers exporting into the EU: Britain's own product security rules run on a separate track, but they do not exempt a UK-made router or camera sold to an EU customer from this clock. The duty also does not care how old the product is, only whether it still ships to an EU buyer today.

The covered category is broad by design: smart home devices, industrial control systems, operating systems, routers, firewalls, password managers, VPN software, wearables with health monitoring, and smart meter gateways all qualify as products with digital elements. Sector-regulated products such as medical devices, aviation equipment, and motor vehicles are carved out because they already answer to their own reporting regimes, and open-source software supplied outside a commercial context, standalone SaaS, and products built solely for national defence sit outside the CRA's reach. Everything else that connects to a network and reaches an EU customer is in scope, whether the manufacturer sits in Munich or Michigan.

The Clock, in Hours and in Euros

StageDeadline from awareness
Early warning24 hours
Full notification72 hours
Final report, vulnerability14 days after a fix is available
Final report, incident1 month
Violation typeMaximum fine
Essential cybersecurity or Article 14 reporting failure15,000,000 euros or 2.5 percent of global turnover
Other Cyber Resilience Act obligations10,000,000 euros or 2 percent of global turnover
False or misleading information5,000,000 euros or 1 percent of global turnover

Whichever figure in each pair is higher is the one that applies, and regulators keep a second lever beyond the fine itself: they can order corrective action, restrict or prohibit sale of a non-compliant product, or force a recall from the EU market outright. For a manufacturer with EU revenue in the billions, the percentage-of-turnover clause, not the flat euro figure, is the number that actually bites.

What Reduces the Risk Before September 11

Crowell and Moring's readiness guidance narrows the pre-deadline list to a few concrete steps: identify the national CSIRT that will receive the manufacturer's reports, put continuous monitoring in place across threat-intelligence feeds and vulnerability databases, write the contractual requirement that upstream component suppliers must flag known and actively exploited weaknesses, and fold the CRA timeline into existing NIS2 and GDPR incident-response plans so cybersecurity, legal, product, and communications teams already know who has authority to file. Keeping an up-to-date software bill of materials sits on the same list, because a manufacturer that cannot map which product uses which component cannot assess exposure inside 24 hours.

One detail sits underneath all of that advice and rewards acting early rather than on the day itself. ENISA's own guidance, issued 14 August 2026, caps unverified accounts on the Single Reporting Platform at 10 notifications, and account verification is not instant. A manufacturer that leaves registration until its first live incident is treating a new, unverified, API-free web portal as the only channel for a legally binding 24-hour deadline. Registering and verifying the account now, while there is nothing to report, is the one step that costs nothing and removes an entirely avoidable failure mode.

Servola Journal

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.