Threat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mapping

Editorial explainer · official sourcesmedium

Cyber Resilience Act: what kicks in on 11 September 2026, and what waits for 2027

Not an attack, but a deadline drawing closer. The Cyber Resilience Act — Regulation (EU) 2024/2847 — has been in force since 10 December 2024, but its obligations arrive in stages. The first concrete block lands on 11 September 2026: from that day, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours and a notification within 72. The bulk of the obligations — essential security requirements, conformity assessment, CE marking — applies instead from 11 December 2027. Anyone who makes or sells software and hardware in the EU has a window that is closing.

An explainer, not the attack of the day

This piece does not tell a breach: it tells a rule that is about to bite. Nearly every dossier we publish runs into the same question — who was supposed to secure this vulnerable product, and who was supposed to disclose it? Since 2024 Europe has a horizontal answer, valid for almost anything with a chip or software inside: the Cyber Resilience Act. But it is a clockwork regulation, and the first hand strikes in a few weeks.

What it is, and since when

Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), entered into force on 10 December 2024. It is the first European framework to impose cybersecurity requirements on products — not on the organizations that use them, as NIS2 does, but on the objects being sold. It covers products with digital elements: hardware and software placed on the Union market, from routers to connected appliances, from firmware to applications, including remote data-processing solutions tied to the product. Out of scope are the categories that already have their own rules: medical devices, motor vehicles, aviation.

The principle is simple to state and demanding to implement: a digital product must be secure by design, receive updates for a declared support period, and come with clear information about its security profile. Primary responsibility falls on the manufacturer, with cascading obligations on importers and distributors.

The near deadline: reporting, from 11 September 2026

The date that matters now is not the distant one in 2027. It is 11 September 2026: from that day the reporting obligations take effect. Manufacturers must notify two things — actively exploited vulnerabilities in their products and severe incidents that compromise their security — and they must do so on tight timelines.

  1. Within 24 hours
    Early warning

    An early warning as soon as the exploited vulnerability or incident becomes known.

  2. Within 72 hours
    Notification

    The notification proper, with the details available.

  3. 14 days / 1 month
    Final report

    Within 14 days of a corrective measure being available for exploited vulnerabilities; within one month for severe incidents.

Reporting is done only once, through the regulation's Single Reporting Platform, and is addressed to the CSIRT of the state where the manufacturer has its main establishment; the information is made available simultaneously to ENISA, barring exceptional circumstances. The less obvious point: these reporting obligations apply to products already on the market before full CRA application, not only to new ones. Anyone with an installed base already sold in the EU does not start from a blank page at the end of 2027.

What waits for 2027

The core body of the regulation — the essential cybersecurity requirements, the conformity assessment, the CE marking attesting conformity, the documentation duties across the whole lifecycle — becomes applicable on 11 December 2027. That is the point at which a non-compliant product should, in theory, no longer be placeable on the Union market.

10 Dec 2024
In force
The regulation is law, but with deferred application.
11 Sep 2026
Reporting
Exploited vulnerabilities and severe incidents must be notified.
11 Dec 2027
Full application
Essential requirements, conformity, CE marking.

Between the two dates there is a difference of nature, not just of calendar. The 2026 deadline demands an operational capability: knowing when one of your products is under real attack and having a process to say so within 24 and 72 hours. The 2027 one demands a product transformation: designing, documenting and certifying security from the start. The first can be improvised, painfully; the second cannot.

What to verify at the source

On a matter where the Commission is still publishing guidance, implementing acts and harmonised standards, the rule stays the one from our dossiers: do not trust summaries, ours included. The full text is on EUR-Lex; the framing, FAQs and the pages dedicated to reporting obligations are on the European Commission portal. The product classes (the "important" and "critical" products subject to stricter conformity assessment) and the precise deadlines applicable to your case should be confirmed there, because that is the part the guidance is still refining. This article frames the design and the two dates that matter; an organization's concrete compliance is built on the official texts.

More dossiers