Disclosure Before Design: The Cyber Resilience Act Binds Every Connected Product Already on the EU Market from 11 September
From 11 September 2026 manufacturers must report exploited vulnerabilities in any product already on the EU market to ENISA and a national CSIRT within 24 hours, fifteen months before the Cyber Resilience Act's design rules apply. Exposed: device makers, software vendors, industrial OEMs.
The consensus reading of the Cyber Resilience Act is that it is a December 2027 problem: secure-by-design engineering, conformity assessment, CE marking. The first binding duty arrives this week and it is the reporting duty. From 11 September every manufacturer with a connected product on the EU market, including products shipped years ago, must give ENISA and a national CSIRT an early warning within 24 hours of learning that a vulnerability is being exploited. The Commission calls this one milestone in a staged implementation. From the manufacturer's side the order matters: the duty binds the installed base fifteen months before the design rules, on a platform that opens the same day and takes no automated submissions.
Signal Identification
A sequencing shift inside a staged regime. The Commission, ENISA and BSI present the reporting duty as one CRA milestone among several. The weak signal sits in the order: standards, notified bodies and the presumption of conformity are not yet in place, but the duty to notify exploited vulnerabilities is, it covers products already on the market, and it carries fines of up to €15 million or 2.5% of turnover before any product has been assessed under the Act.
What's Changing
The dates are fixed by regulation. From 11 September manufacturers file an early warning within 24 hours and a full notification within 72, through one platform, to their home CSIRT and to ENISA; the receiving CSIRT shares it “without delay” with every CSIRT where the product is sold (European Commission, 31/07/2026). The Commission's 27 July guidance confirms the split: main obligations from 11 December 2027, reporting from 11 September 2026 (European Commission, 27/07/2026). Germany's BSI lists the same milestone, with notified bodies due only by 11 December 2026 (BSI, accessed 07/09/2026).
The scope reaches backwards. The reporting obligations “also cover PDEs placed on the EU market before the CRA becomes fully applicable in December 2027”; the clock starts at a “reasonable degree of certainty” of exploitation and runs through weekends (Freshfields, 31/08/2026). Fines reach EUR 15,000,000 or 2.5% of worldwide turnover, though small firms are exempt for missing the 24-hour deadline (Hogan Lovells Cadwalader, 10/06/2026). The trigger is narrow: only “belastbare Hinweise auf eine aktive Ausnutzung”, reliable evidence of active exploitation (IT-Administrator, 26/08/2026).
The platform arrives with the obligation. ENISA's FAQ, updated 4 September, says the SRP opens on 11 September for mandatory reports only, that “no Application Programming Interface (API) will be provided at the initial release”, and that firms should register only when they need to file (ENISA, 04/09/2026). Readiness is thin: the Linux Foundation's 2026 survey found 66% of respondents unfamiliar with the CRA, 72% in the US and Canada, and 32% producing SBOMs for all products (Linux Foundation, 19/06/2026).
The CRA arrives in reverse order: the reporting clock binds the installed base before standards, notified bodies or design rules exist
Sources: European Commission reporting page (31 July 2026) and guidance notice (27 July 2026); BSI CRA timeline; ENISA SRP FAQ (4 September 2026); Freshfields (31 August 2026); Linux Foundation (19 June 2026).
Disruption Pathway
Three stages. Through 2026 the duty runs on a minimum platform: web-form filing, validation in parallel, no voluntary channel. Early filings come from firms with SBOM pipelines; legacy devices stay dark until a botnet or a researcher forces awareness. In 2027, surveillance authorities receive CSIRT referrals, enforcement cases test what becoming aware means, and the Digital Omnibus decides whether CRA, NIS2 and GDPR clocks merge (Freshfields, 31/08/2026). From December 2027 the design rules apply to new products; by then ENISA holds fifteen months of exploited-vulnerability data and owes its first trend report by September 2028 (ENISA, 04/09/2026).
Stress concentrates at three points. Awareness: the clock starts at reasonable certainty, so a firm without component-level visibility of old products cannot know when it is aware. Confidentiality: a pre-patch report is shared across member states unless a CSIRT holds it on cybersecurity grounds (European Commission, 31/07/2026), and each holder widens the leak surface. Duplication: the “single” platform does not replace GDPR, NIS2 or DORA notices (Hogan Lovells Cadwalader, 10/06/2026). Two adaptations follow. Manufacturers build SBOM-to-exploit-feed correlation for the installed base, because a 24-hour answer on affected products cannot be assembled by hand. On this scan's reading, CSIRTs also acquire a product-vulnerability role, with ENISA's vulnerability database fed from the platform (ENISA, 04/09/2026).
Why This Matters Now
The constituency is boards and general counsel of any firm with a connected product or software on sale in the EU. On the available evidence, compliance plans built for December 2027 have the order wrong: reporting readiness is a September 2026 obligation with a top-tier fine, covering products the programme has not yet inventoried. Three things should be settled this week: who holds the EU Login credential and the authority to file at the weekend; which entity is the manufacturer for each legacy product (Hogan Lovells Cadwalader, 10/06/2026); and what evidence threshold counts as awareness. Taken together, the sources suggest the CRA's first year will be judged on notifications, not CE marks.
Decision-action posture for this signal: Decide — the obligation is live from 11 September for products already on the market, carries the Act's highest penalty tier and cannot be met without a named filer and a legacy-product inventory.
Counter-Argument
The strongest objection: this is the routine milestone the regulators describe. The Commission calls its guidance simplification in action (European Commission, 27/07/2026); the trigger is reliable evidence of active exploitation, not any bug (IT-Administrator, 26/08/2026); small firms cannot be fined for missing the 24-hour window (Hogan Lovells Cadwalader, 10/06/2026); the platform has no API and ENISA is asking firms not to register in advance (ENISA, 04/09/2026); and harmonised standards are still being drafted (BSI, accessed 07/09/2026). On this reading September is a soft launch and the real CRA starts in December 2027.
Routine for the regulator is not routine for the regulated. The milestone is manageable for a firm that knows what it has on the EU market and what is in it; the Linux Foundation's figures suggest most do not (Linux Foundation, 19/06/2026). Even a trickle of filings starts the habit: CSIRTs referring, ENISA aggregating, supervisors learning who never files. And the narrow trigger cuts the other way: a firm that cannot tell whether an old product is being exploited may hear it first from a CSIRT.
Implications
This reads as durable. The reporting duty is regulation, not guidance; it binds the installed base; and each later CRA phase (notified bodies, design rules, ENISA trend reporting from 2028) builds on its data. The inflection window is now to December 2027. Manufacturers with SBOM-backed inventories of legacy products gain: they file cleanly and avoid the penalty tier. Firms treating the CRA as a 2027 launch requirement lose, as do non-EU vendors unaware of scope. National CSIRTs, for the first time, receive product-vulnerability notifications and share them across the Union (European Commission, 31/07/2026).
Early Indicators to Monitor
- ENISA publishing the SRP URL and the full list of coordinating CSIRTs on or before 11 September.
- A first public enforcement action or market-surveillance referral for a missed 24-hour early warning.
- Manufacturers' security advisories starting to cite SRP notification references.
- The Digital Omnibus merging CRA, NIS2 and GDPR incident channels into one entry point.
- ENISA's first trend report, due by September 2028, quantifying notifications.
Disconfirming Signals
- The SRP slipping past 11 September, or the Commission granting a formal grace period for Article 14.
- Notification volumes in ENISA's first reporting that are negligible against exploited-vulnerability catalogues.
- A delegated act or Omnibus amendment narrowing Article 69(3) so legacy products fall outside the duty.
- Surveillance authorities declining to pursue reporting failures until harmonised standards exist.
- CSIRTs routinely invoking exceptional circumstances to withhold notifications from ENISA.
Strategic Questions
- Do we inventory every legacy product to component level now, or carry awareness risk to 2027?
- Who files on a Sunday night, and does that person hold the EU Login and the authority?
- Should the EU reporting threshold become our global disclosure standard, or do we run two?
- Which products do we withdraw from the EU market rather than carry inside the clock?
Keywords
Cyber Resilience Act; CRA Article 14; vulnerability reporting; Single Reporting Platform; ENISA; CSIRT; actively exploited vulnerability; legacy products; Article 69(3); SBOM; product security
Bibliography
Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.
- Tier 1 Cyber Resilience Act: reporting obligations (policy page). European Commission (31/07/2026).
- Tier 1 Commission guidance on the Cyber Resilience Act, C(2026) 5252. European Commission (27/07/2026).
- Tier 1 CRA Single Reporting Platform: frequently asked questions. ENISA (04/09/2026).
- Tier 1 Cyber Resilience Act: Informationen und Empfehlungen für Unternehmen (German). Bundesamt für Sicherheit in der Informationstechnik (evergreen reference page, accessed 07/09/2026).
- Tier 2 Cyber Resilience Act reporting obligations take effect on 11 September 2026. Freshfields (31/08/2026).
- Tier 2 EU Cyber Resilience Act: preparing for vulnerability and incident reporting. Hogan Lovells Cadwalader (10/06/2026).
- Tier 3 24 Stunden für die erste Schwachstellenmeldung (German). IT-Administrator (26/08/2026).
- Tier 4 The CRA Readiness Reality: 2026 CRA Awareness and Readiness Report. Linux Foundation (19/06/2026).