Cyber Resilience Act: 7 Things Every Vendor Must Do Within 24 Hours

The Cyber Resilience Act just started biting, and the clock is now measured in hours, not months. As of 11 September 2026, any manufacturer selling connected products into the European Union must report an actively exploited vulnerability or a severe security incident within 24 hours of learning about it. This is the first hard deadline of the CRA to take effect, a full year before the rest of the law kicks in.

Let me be direct: 24 hours is not a lot of time to notice a breach, confirm it is real, and file with a regulator. If your product has a chip and a network connection and it reaches European buyers, this applies to you, wherever your company is headquartered.

What Actually Changed on 11 September

The new obligation has three tiers, and the timing on each is what trips people up. First, an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. Second, a fuller notification within 72 hours. Third, a final report within 14 days of a corrective measure becoming available.

Reports go simultaneously to the EU Agency for Cybersecurity (ENISA) and the designated national CSIRT, filed through ENISA’s Single Reporting Platform. The portal launched the same day the rule became mandatory, so there is no grace period to “get set up later.” The switch is already on.

Who This Catches (Probably You)

Here is the part that surprises people. The CRA covers all “products with digital elements,” which is a deliberately broad phrase. Smart sensors, routers, industrial controllers, connected appliances, software libraries, IoT devices, most things with code and connectivity. It also reaches products already placed on the market before December 2027, so legacy inventory is not exempt.

And geography does not save you. The rule applies to any manufacturer whose products are made available on the EU market, regardless of where the company sits or where the hardware is built. A firm in Karachi, Kyiv, or Kansas that ships into Europe is on the hook the same as a Berlin manufacturer.

The Penalties Are Not Symbolic

So yeah, this has teeth. Non-compliance with the CRA’s most serious requirements can trigger financial penalties of up to €15 million or 2.5% of global annual turnover for the prior year, whichever is higher. For a mid-sized vendor, that is not a line item you absorb. It is an existential number.

The reporting duty is also a discipline test. A 24-hour clock forces you to already know your product inventory, your disclosure chain, and who has authority to hit “submit” at 2am on a weekend. Companies that treat security as an afterthought will simply miss the window, and missing the window is itself the violation.

Seven Moves to Get Ready

The good news: preparing for the CRA is mostly operational hygiene you should want anyway. A short checklist:

One, build a live inventory of every product with digital elements you sell into the EU. Two, define what counts as a “severe incident” for your products before one happens. Three, stand up a monitoring capability that can actually detect active exploitation, not just log it. Four, pre-register on ENISA’s Single Reporting Platform and know your national CSIRT. Five, write a 24-hour runbook with named owners and escalation paths. Six, rehearse it, because a plan you have never tested is a guess. Seven, fix your software bill of materials so you can trace a vulnerable component fast.

Why 24 Hours Is Harder Than It Sounds

On paper, “report within 24 hours” reads like a simple deadline. In practice, it compresses a whole chain of decisions into a single day. First someone has to notice that a vulnerability is being actively exploited, which is different from merely existing. Then someone has to confirm it is real and not a false alarm. Then someone with authority has to decide it meets the reporting threshold. Then someone has to actually file. If any link in that chain is slow, unstaffed, or unclear, the clock runs out.

Weekends and holidays make it worse. Attackers do not respect office hours, and a vulnerability discovered at 6pm on a Friday still has to be reported by Saturday evening. That reality forces a real operational change: security monitoring and incident decision-making cannot be a weekday, business-hours function anymore. Someone has to be reachable and empowered around the clock, or the deadline becomes impossible by design.

There is a subtler trap too. The rule covers actively exploited vulnerabilities, which means you need the ability to detect exploitation, not just the presence of a flaw. Many organizations can scan for known weaknesses. Far fewer can tell, in near real time, that one is being used against them right now. Closing that gap is the real work behind the deadline.

The Upside Hidden in the Compliance Burden

Here is a reframe worth sitting with: almost everything the CRA forces you to do is something a well-run product company should already do. A live inventory of your connected products is useful for support and end-of-life planning. A software bill of materials helps you patch fast when the next big library vulnerability drops. A tested incident runbook shortens every outage, not just the reportable ones.

Treated cynically, the CRA is a cost. Treated well, it is a forcing function that finally justifies the security investments your engineers have been requesting for years. The companies that come out ahead will be the ones that use this deadline as leverage to fix underlying hygiene, rather than bolting on a compliance process that sits awkwardly beside sloppy engineering. Buyers are starting to ask for evidence of this maturity anyway, so the work doubles as a sales advantage. Regulation set the floor; the smart move is to clear it by a comfortable margin.

Key Takeaways

  • The 24-hour clock is live: Since 11 September 2026, an early warning is due within 24 hours of awareness, a full notification within 72 hours, and a final report within 14 days of a fix.
  • Reporting runs through ENISA: Notifications go simultaneously to ENISA and the national CSIRT via the Single Reporting Platform, which is already operational.
  • The scope is huge: Every product with digital elements is covered, including inventory placed on the market before December 2027.
  • It is extraterritorial: Any manufacturer selling into the EU is bound, no matter where it is headquartered or where it manufactures.
  • Penalties reach €15 million or 2.5% of turnover: The fines are large enough to threaten a mid-sized vendor, so this is a board-level issue.
  • Readiness is operational: Inventory, incident definitions, monitoring, a tested runbook, and a clean software bill of materials are what make the 24-hour deadline survivable.

How TecniForge Can Help

At TecniForge, we help businesses navigate these technology shifts. Whether you need custom software development, AI integration, or cloud migration, our team builds scalable solutions with security baked in from the first commit. For product companies facing the Cyber Resilience Act, that means secure-by-design engineering, a maintainable software bill of materials, monitoring that catches active exploitation, and a reporting workflow that can hit a 24-hour deadline without panic. Talk to our experts.

If a regulator asked you today to prove you could file within 24 hours, would your team pass, or would you be scrambling to find who owns the runbook?

External references: European Commission, The Cyber Express, Mondaq, TechNode, Cycode.