On 11 September 2026 the EU Cyber Resilience Act starts to bite, and it does so more than a year before most people have it in their plans. If you put products with digital elements on the EU market, the reporting clock starts that day — including for products you shipped years ago.
What actually changes on 11 September 2026
Regulation (EU) 2024/2847 applies in stages. The stage arriving now is Article 14: manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products with digital elements. The essential requirements, conformity assessment and CE marking do not arrive until 11 December 2027 — but reporting does not wait for them.
The detail that catches people out: this applies to products already on the market. There is no grandfathering for the installed base. A controller you shipped in 2021 and still support is in scope on day one.
The clock is shorter than most incident processes
- 24 hours — early warning, from the moment you become aware.
- 72 hours — full notification.
- 14 days — final report, once a corrective measure is available for an actively exploited vulnerability.
- 1 month — final report for a severe incident.
Twenty-four hours is not long enough to decide who owns the decision. If the answer to “who declares this reportable, at 2am, on a Sunday” is not a named role today, that is the first gap to close.
What has to exist before the date
- A way in. A published route for anyone — researcher, customer, integrator — to report a vulnerability to you, and a person who reads it.
- A triage rule. Written criteria that separate “actively exploited” and “severe” from everything else, so the judgement is not improvised under time pressure.
- A named decision-maker with a deputy, because the clock does not pause for annual leave.
- A rehearsed submission path to the single reporting platform, tested once before you need it.
- Evidence retention. What you knew, when you knew it, and what you did — the record is what an authority will ask for later.
Then December 2027
The larger body of the regulation follows on 11 December 2027: the Annex I essential cybersecurity requirements, conformity assessment routed by product class, technical documentation, and CE marking. That work is measured in quarters, not weeks. Organisations already running an IEC 62443-4-1 secure development lifecycle will recognise most of it — the CRA asks for a great deal that a mature SDL already produces.
Where to start if you have not
Two questions answer most of the scope problem. Which of our products contain digital elements and are placed on the EU market? And which of those are important or critical products under Annex III and IV? The first decides whether the CRA applies to you at all. The second decides whether you can self-assess or need a notified body — which is a lead-time question, and lead times get worse as the deadline approaches.
If you would rather work through the CRA with tooling than with a consultant, we build one: the CRA Workbench — a structured workspace for scope classification, Annex I evidence and the vulnerability handling process the September deadline assumes you already run. Same team, different shape of help.
We help manufacturers answer both, then build the vulnerability handling process that Article 14 assumes you already have. If the September date is closer than your readiness, that is worth a conversation this month rather than next.