Skip to main content
Home/Blog/Starting Tomorrow, Your Software Has 24 Hours to Report a Hack. Is Your Business Ready for the EU Cyber Resilience Act?
Compliance

Starting Tomorrow, Your Software Has 24 Hours to Report a Hack. Is Your Business Ready for the EU Cyber Resilience Act?

The EU Cyber Resilience Act's Article 14 vulnerability reporting obligations take effect September 11, 2026. Every software vendor selling into the EU now has 24 hours to report actively exploited flaws. Here's what business leaders must do right now.

September 10, 2026·7 min read

Tomorrow — September 11, 2026 — a regulatory deadline quietly takes effect that most businesses selling software into Europe aren't ready for.

Under the EU Cyber Resilience Act (CRA), specifically Article 14, any manufacturer of a product with digital elements must now report actively exploited vulnerabilities to European authorities within 24 hours of becoming aware of them. Not 30 days. Not 72 hours for the first step. Twenty-four hours for the initial early warning.

If your business sells software, connected devices, or digital services in the EU — including products already on the market — these obligations apply to you starting tomorrow.

What the Clock Actually Looks Like

The reporting timeline is strict and staged. The moment you become aware that a vulnerability in your product is being actively exploited, three clocks start simultaneously:

Within 24 hours, you must file an early warning notification with ENISA (the EU's cybersecurity agency) and your designated national CSIRT (Computer Security Incident Response Team) via the EU's Single Reporting Platform. This notification doesn't need to be a complete technical investigation — but you must confirm the product, the issue exists, and whether malicious activity is suspected.

Within 72 hours, you must submit a fuller notification describing the general nature of the vulnerability, the exploit, your initial assessment, and any mitigating measures you've taken or users can take.

Within 14 days of a patch being available, you must submit a final report with root cause analysis, full description, severity, impact, and the corrective measures applied.

This isn't a grace period framework. This is a live legal obligation with enforcement teeth — fines up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.

The Part That Catches Most Businesses Off Guard

Here's where businesses make dangerous assumptions.

First: these obligations apply to products already on the market. If your software shipped in 2019 and it's still being used by EU customers, the CRA's Article 14 reporting requirements apply to it starting tomorrow. You don't have to have released something new.

Second: the reporting obligation kicks in when you become aware — not when a patch is available, not when you've completed your investigation. The 24-hour clock starts the moment you have reliable evidence that someone is exploiting a vulnerability in your product. Every hour you spend internally investigating before notifying is an hour the clock is running.

Third: the CRA applies to commercial products across an enormous scope. SaaS platforms. Mobile apps. On-premises software. IoT devices. Industrial controllers. Connected medical equipment. Network appliances. If you sell it commercially and it connects to a network or processes data, the CRA almost certainly applies.

Fourth: open-source software components don't get you off the hook. Once OSS is integrated into a commercial product, the manufacturer inherits the obligations for that component.

Why This Matters Even If You're Not in Europe

If you're a U.S. company with any EU customers — or any European subsidiaries, partners, or distributors — these obligations likely apply to you.

The CRA applies based on where your product is sold, not where you're incorporated. Selling through a UK or German reseller? CRA applies. Having a single EU enterprise customer on your SaaS platform? The EU market test is met. Licensing your software through a European distributor? You are the manufacturer for CRA purposes.

The regulation's reach is deliberately broad. The EU has watched years of software shipped to market with inadequate security baked in, and the CRA is the legislative response. The penalty structure — tied to global revenue, not EU revenue — ensures that even large multinationals can't treat EU compliance as a rounding error.

What Readiness Actually Requires

Reporting compliance under Article 14 is not just a legal checkbox. It requires operational infrastructure that most companies have not built.

You need continuous vulnerability monitoring. You cannot report something you do not know about. If you're not actively monitoring your software components against known-exploited vulnerability databases (NVD, CISA KEV, the EU's own EUVD), you will fail the 24-hour test not because you chose to ignore a report — but because you never saw it. Ignorance doesn't stop the clock; it just means you breach the deadline without knowing it.

You need an accurate Software Bill of Materials (SBOM). ENISA has made clear that you cannot report a vulnerability in a component you didn't know you shipped. If you don't have a current, accurate SBOM mapping every dependency in your product, you have a blind spot that will eventually become a compliance crisis.

You need a reporting runbook. The 24-hour early warning notification is not the result of a full investigation — it's an alert that something is happening. Your team needs to know in advance: who assesses whether a report is due, who drafts it, who submits it, and who's on call to do this at 2 AM on a Saturday. There is no API to the reporting platform; the final step requires a named human at a keyboard.

You need EU login credentials set up. ENISA's Single Reporting Platform requires EU Login accounts created in advance. If your team goes to file a report and hits an account registration screen, you've already burned precious hours.

The Broader Signal for Business Leaders

The EU Cyber Resilience Act is part of a wave of regulatory frameworks — DORA for financial services, NIS2 for critical infrastructure, the upcoming Product Liability Directive — that are collectively rewriting the rules of software accountability in Europe. The era of shipping software and treating security as an optional upgrade is ending, at least in any market that values continued European revenue.

But here's the practical insight that matters most: the operational infrastructure required for CRA Article 14 compliance — continuous monitoring, SBOM management, rapid incident response, clear escalation protocols — is exactly the infrastructure that makes your security program materially stronger, regardless of regulation.

Organizations that build real-time visibility into their software components, that monitor for exploitation signals, that can respond within hours rather than weeks — those organizations are fundamentally harder targets than those operating blind.

The regulation is not asking you to build something exotic. It's asking you to know what software you ship, watch for signs it's being exploited, and tell authorities when it is. That's just good security practice, now with a deadline and a fine attached.

Three Questions to Ask Your Team Today

If you sell software or connected products with any EU exposure, ask these three questions before tomorrow's deadline:

Do we have an accurate, current SBOM for every product in the EU market? If your engineering team can't answer this question with confidence in the next few minutes, you have a visibility gap that predates and outlasts the CRA.

Are we monitoring our products against the CISA KEV and EUVD for active exploitation signals — and if an exploit fires tonight, does someone get alerted? Continuous monitoring is not optional when the clock starts the moment you become aware.

Do we have a documented reporting runbook, and does our legal and security team know which EU CSIRT we report to? ENISA published the full CSIRT list for all 27 member states on September 4th — this is now a task you can complete today.

The CRA is not a surprise. It's been public since December 2024. But most organizations have treated the September 11, 2026 deadline as distant. It arrives tomorrow.

TrustPoint Cyber helps businesses build the security infrastructure that compliance demands — and that attackers force you to have anyway. If you're not sure where your organization stands on CRA readiness or broader vulnerability management maturity, let's talk. We'll tell you what you actually need.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.