Signal Scanner · REGULATION, STANDARDS & POLICY CHANGE · 7 September 2026

Disclosure Before Design: The Cyber Resilience Act Binds Every Connected Product Already on the EU Market from 11 September

From 11 September 2026 manufacturers must report exploited vulnerabilities in any product already on the EU market to ENISA and a national CSIRT within 24 hours, fifteen months before the Cyber Resilience Act's design rules apply. Exposed: device makers, software vendors, industrial OEMs.

The consensus reading of the Cyber Resilience Act is that it is a December 2027 problem: secure-by-design engineering, conformity assessment, CE marking. The first binding duty arrives this week and it is the reporting duty. From 11 September every manufacturer with a connected product on the EU market, including products shipped years ago, must give ENISA and a national CSIRT an early warning within 24 hours of learning that a vulnerability is being exploited. The Commission calls this one milestone in a staged implementation. From the manufacturer's side the order matters: the duty binds the installed base fifteen months before the design rules, on a platform that opens the same day and takes no automated submissions.

Signal Identification

A sequencing shift inside a staged regime. The Commission, ENISA and BSI present the reporting duty as one CRA milestone among several. The weak signal sits in the order: standards, notified bodies and the presumption of conformity are not yet in place, but the duty to notify exploited vulnerabilities is, it covers products already on the market, and it carries fines of up to €15 million or 2.5% of turnover before any product has been assessed under the Act.

Time horizon: 0-3 years (reporting duty 11 September 2026; notified bodies due 11 December 2026; full application 11 December 2027; ENISA's first trend report by September 2028)
installed base inside the clock202620272028
Plausibility band: High
LowMediumHigh
Geographic / Jurisdictional Scope: Primary: EU-27, every product with digital elements made available on the EU market. Spillover: non-EU manufacturers and software vendors selling into the EU, notably US, UK, Chinese, Korean and Japanese firms; open-source stewards.
PrimaryEU-27
SpilloverUS vendorsUKChina / Korea / JapanOpen-source stewards
Sectors exposed:
Connected-device makersSoftware vendorsIndustrial and machinery OEMsNetworking and telecom equipmentAutomotive and medical suppliers outside sector exemptionsOpen-source stewardsNational CSIRTs and market surveillance

What's Changing

The dates are fixed by regulation. From 11 September manufacturers file an early warning within 24 hours and a full notification within 72, through one platform, to their home CSIRT and to ENISA; the receiving CSIRT shares it “without delay” with every CSIRT where the product is sold (European Commission, 31/07/2026). The Commission's 27 July guidance confirms the split: main obligations from 11 December 2027, reporting from 11 September 2026 (European Commission, 27/07/2026). Germany's BSI lists the same milestone, with notified bodies due only by 11 December 2026 (BSI, accessed 07/09/2026).

The scope reaches backwards. The reporting obligations “also cover PDEs placed on the EU market before the CRA becomes fully applicable in December 2027”; the clock starts at a “reasonable degree of certainty” of exploitation and runs through weekends (Freshfields, 31/08/2026). Fines reach EUR 15,000,000 or 2.5% of worldwide turnover, though small firms are exempt for missing the 24-hour deadline (Hogan Lovells Cadwalader, 10/06/2026). The trigger is narrow: only “belastbare Hinweise auf eine aktive Ausnutzung”, reliable evidence of active exploitation (IT-Administrator, 26/08/2026).

The platform arrives with the obligation. ENISA's FAQ, updated 4 September, says the SRP opens on 11 September for mandatory reports only, that “no Application Programming Interface (API) will be provided at the initial release”, and that firms should register only when they need to file (ENISA, 04/09/2026). Readiness is thin: the Linux Foundation's 2026 survey found 66% of respondents unfamiliar with the CRA, 72% in the US and Canada, and 32% producing SBOMs for all products (Linux Foundation, 19/06/2026).

The CRA arrives in reverse order: the reporting clock binds the installed base before standards, notified bodies or design rules exist

CRA CALENDAR (positions to scale, June 2026 to December 2027) 15 months: installed base inside the clock, no harmonised standard cited Jun 2026 Dec 2026 Jun 2027 Dec 2027 11 Jun: notifying authorities 11 Sep 2026: reporting duty, all products on the market 11 Dec 2026: notified bodies due 11 Dec 2027: design and conformity rules apply THE REPORTING CLOCK Early warning 24 h Notification 72 h Final report 14 days after a fix Clock starts at reasonable certainty of active exploitation; runs through weekends; web-form filing only. READINESS (Linux Foundation survey, June 2026) 66% unfamiliar with the CRA 32% produce SBOMs for all products 41% expect full compliance by Dec 2027 Bar length = share of respondents (150 px = 100%). Red: the duty that binds first. Grey band: period in which reporting applies but design rules and harmonised standards do not.

Sources: European Commission reporting page (31 July 2026) and guidance notice (27 July 2026); BSI CRA timeline; ENISA SRP FAQ (4 September 2026); Freshfields (31 August 2026); Linux Foundation (19 June 2026).

Disruption Pathway

Three stages. Through 2026 the duty runs on a minimum platform: web-form filing, validation in parallel, no voluntary channel. Early filings come from firms with SBOM pipelines; legacy devices stay dark until a botnet or a researcher forces awareness. In 2027, surveillance authorities receive CSIRT referrals, enforcement cases test what becoming aware means, and the Digital Omnibus decides whether CRA, NIS2 and GDPR clocks merge (Freshfields, 31/08/2026). From December 2027 the design rules apply to new products; by then ENISA holds fifteen months of exploited-vulnerability data and owes its first trend report by September 2028 (ENISA, 04/09/2026).

Stress concentrates at three points. Awareness: the clock starts at reasonable certainty, so a firm without component-level visibility of old products cannot know when it is aware. Confidentiality: a pre-patch report is shared across member states unless a CSIRT holds it on cybersecurity grounds (European Commission, 31/07/2026), and each holder widens the leak surface. Duplication: the “single” platform does not replace GDPR, NIS2 or DORA notices (Hogan Lovells Cadwalader, 10/06/2026). Two adaptations follow. Manufacturers build SBOM-to-exploit-feed correlation for the installed base, because a 24-hour answer on affected products cannot be assembled by hand. On this scan's reading, CSIRTs also acquire a product-vulnerability role, with ENISA's vulnerability database fed from the platform (ENISA, 04/09/2026).

Why This Matters Now

The constituency is boards and general counsel of any firm with a connected product or software on sale in the EU. On the available evidence, compliance plans built for December 2027 have the order wrong: reporting readiness is a September 2026 obligation with a top-tier fine, covering products the programme has not yet inventoried. Three things should be settled this week: who holds the EU Login credential and the authority to file at the weekend; which entity is the manufacturer for each legacy product (Hogan Lovells Cadwalader, 10/06/2026); and what evidence threshold counts as awareness. Taken together, the sources suggest the CRA's first year will be judged on notifications, not CE marks.

Decision-action posture for this signal: Decide — the obligation is live from 11 September for products already on the market, carries the Act's highest penalty tier and cannot be met without a named filer and a legacy-product inventory.

Counter-Argument

The strongest objection: this is the routine milestone the regulators describe. The Commission calls its guidance simplification in action (European Commission, 27/07/2026); the trigger is reliable evidence of active exploitation, not any bug (IT-Administrator, 26/08/2026); small firms cannot be fined for missing the 24-hour window (Hogan Lovells Cadwalader, 10/06/2026); the platform has no API and ENISA is asking firms not to register in advance (ENISA, 04/09/2026); and harmonised standards are still being drafted (BSI, accessed 07/09/2026). On this reading September is a soft launch and the real CRA starts in December 2027.

Routine for the regulator is not routine for the regulated. The milestone is manageable for a firm that knows what it has on the EU market and what is in it; the Linux Foundation's figures suggest most do not (Linux Foundation, 19/06/2026). Even a trickle of filings starts the habit: CSIRTs referring, ENISA aggregating, supervisors learning who never files. And the narrow trigger cuts the other way: a firm that cannot tell whether an old product is being exploited may hear it first from a CSIRT.

Implications

This reads as durable. The reporting duty is regulation, not guidance; it binds the installed base; and each later CRA phase (notified bodies, design rules, ENISA trend reporting from 2028) builds on its data. The inflection window is now to December 2027. Manufacturers with SBOM-backed inventories of legacy products gain: they file cleanly and avoid the penalty tier. Firms treating the CRA as a 2027 launch requirement lose, as do non-EU vendors unaware of scope. National CSIRTs, for the first time, receive product-vulnerability notifications and share them across the Union (European Commission, 31/07/2026).

Early Indicators to Monitor

Disconfirming Signals

Strategic Questions

Keywords

Cyber Resilience Act; CRA Article 14; vulnerability reporting; Single Reporting Platform; ENISA; CSIRT; actively exploited vulnerability; legacy products; Article 69(3); SBOM; product security

Bibliography

Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.


Prepared by Shaping Tomorrow: 7 September 2026