Skip to content
All insights

CRA readiness · · 6 min read

CRA reporting obligations begin 11 September 2026 — what operational readiness means

The reporting duties arrive well before the main obligations. They are the first point where a product organisation is measured on process, not intention.

The Cyber Resilience Act phases in over several years, and the first hard operational date concerns reporting. From 11 September 2026, manufacturers of products with digital elements must notify actively exploited vulnerabilities and severe incidents affecting the security of their products. The timelines are short: an early warning within 24 hours and a fuller notification within 72 hours.

For most organisations the difficulty is not understanding the requirement. It is that a 24-hour clock exposes every unowned step in the chain between a security signal arriving and a decision being made.

What has to work before the date

  • A single, monitored intake path for vulnerability reports that does not depend on one individual.
  • A triage rule set that distinguishes an exploited vulnerability from a routine finding, written down rather than improvised.
  • A named decision-maker, and a named deputy, with the authority to submit a notification.
  • An accurate product and version inventory, so the scope of an incident can be stated rather than estimated.
  • Prepared notification content: what is known, what is not, and what mitigation is available.
  • A record of the decision and its rationale, retained as evidence.

Why the product inventory decides the outcome

Almost every reporting failure we see in rehearsals traces back to the same gap: the organisation cannot say quickly which shipped versions contain the affected component, which customers run them, and whether a fix path exists. This is where SBOM work stops being a documentation exercise and becomes an operational capability. If the component inventory is not queryable within hours, the 72-hour notification will be vague — and vagueness is visible.

Reporting is a symptom test for the lifecycle

The reporting duty is narrow, but passing it requires most of the underlying CRA machinery: risk assessment, secure development practice, update and support definitions, and coordinated disclosure. Teams that treat September 2026 as a compliance form to fill in tend to discover the missing lifecycle work at the worst possible moment. Teams that rehearse the flow discover it early, in a meeting, where it is cheap to fix.

Run one tabletop exercise on a realistic vulnerability. The gaps it exposes are your actual readiness roadmap.

A sensible sequence

  • Confirm product scope, classification and your role as an economic operator.
  • Establish intake, triage and the decision chain, including deputies.
  • Make the component and version inventory queryable.
  • Rehearse a notification end to end against the 24 and 72-hour timelines.
  • Capture the gaps and prioritise them against the December 2027 obligations.

None of this requires a large programme to begin. It requires ownership, a written process and one honest rehearsal.

More insights