A 24-Hour Clock Starts Across the EU on September 11
The EU's Cyber Resilience Act reaches its first live reporting deadline on September 11, 2026. From that date, any manufacturer selling a product with digital elements into the EU market must report actively exploited vulnerabilities and severe security incidents on a strict clock rather than a best-effort basis. The European Commission's own reporting page states that the obligation covers hardware and software alike, and that it extends to older or even unsupported products still available on the EU market, not only current product lines.
Börse Express's coverage of the rollout corroborates both the date and the scope, describing September 11 as the point at which the first concrete notification duties under the Cyber Resilience Act become enforceable rather than theoretical. A manufacturer that has spent the run-up treating the CRA as a future compliance project now has a window measured in days to finish building an actual reporting process.
Three Deadlines Follow the First Alert
Freshfields' analysis lays out the exact sequence a manufacturer has to hit once it reaches "a reasonable degree of certainty" that a product has an actively exploited vulnerability or has suffered a severe incident. An early warning is due within 24 hours, a fuller notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident. None of those windows pause for a weekend or a public holiday, so a vulnerability discovered on a Friday evening still needs an early warning by Saturday evening.
| Stage | Deadline from "reasonable degree of certainty" | What is required |
|---|---|---|
| Early warning | 24 hours | Initial notice that a product is affected |
| Full notification | 72 hours | Fuller technical detail on the vulnerability or incident |
| Final report, vulnerability | 14 days | Complete report once the issue is understood |
| Final report, incident | 1 month | Complete report once the issue is understood |
The compressed early window is the operational sting in the design. Twenty-four hours gives a manufacturer little room to improvise: without someone already designated to draft and file the notice before an incident happens, that deadline is difficult to meet after the fact.
The Reports Travel Through ENISA and National CSIRTs
The mechanism for filing sits at the center of the new obligation. The European Commission's reporting page describes a new EU-wide Single Reporting Platform, built by ENISA, as the intake point: a manufacturer files there, the report reaches the manufacturer's national CSIRT, and that CSIRT relays it onward to ENISA and to the CSIRTs of any other EU member state whose market the affected product also reaches.
Every step of that chain sits inside EU institutions, from the national CSIRT that first receives the filing to ENISA's coordination role across member states. A manufacturer selling the same product in multiple EU countries can expect its report to circulate through several national CSIRTs rather than a single central authority.
A Parallel System Built Inside the EU
That design choice is the real story underneath the September 11 date. For decades, the CVE and NVD system run by the US government has functioned as the de facto global registry of what is vulnerable and when, the record that security teams everywhere check first regardless of where a product is made or sold. The Single Reporting Platform does not feed into that US system; it is a separate pipeline, built by ENISA, producing its own record inside the EU's own CSIRT network.
That makes the Cyber Resilience Act's reporting regime an act of digital-sovereignty infrastructure with a compliance deadline attached, giving the EU the institutional capacity to know, on its own authority and inside its own systems, what is vulnerable across products sold in its market, independent of whether or when the same information ever reaches an American database.
Two Clocks Now Run on Every Incident
Every vendor with hardware or software on the EU or UK market now carries two separate obligations on the same discovery. One is the reporting rhythm the industry has built around the US-centric CVE and NVD ecosystem over the past two and a half decades. The other is the EU's 24-hour early-warning clock, stricter than typical industry practice and indifferent to time zones, weekends, or which team happens to be on call.
Freshfields' analysis flags the practical strain this creates: the compressed windows require an escalation process built and rehearsed in advance, and they land on top of reporting duties many of the same companies already carry under NIS2 and GDPR. Missing the EU's 24-hour window is now a compliance failure in the EU on its own terms, separate from and additional to however promptly a company reports the same issue anywhere else.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Europe's Open-Weight AI Now Runs Through One Firm | Berlin's New AI Watchdog Has No Bite Yet



