CRA: what 11 September 2026 changes for a 20-person manufacturer
This is the first Cyber Resilience Act deadline that really bites, and also the cheapest to handle — provided you act beforehand. It asks for no CE marking, no technical documentation, no notified body. It asks you to know who, in your company, will pick up the phone within twenty-four hours.
What changes exactly
From 11 September 2026, the manufacturer of a product with digital elements must report two categories of facts: any vulnerability in its product that is being actively exploited, and any severe incident having an impact on the security of the product. Reports go to the CSIRT designated as coordinator and to ENISA (Art. 14).
This is an obligation about process, not about the product. It does not judge the quality of your firmware: it judges your ability to react within a deadline counted in hours. A twenty-person company can meet it perfectly well — often better than a group where information takes three days to climb three floors. On one condition: having decided in advance who does what.
That is what makes this deadline unusual. Unlike December 2027, it is not solved with budget. It is solved with an organisational decision and half a day of meetings.
What does not change on 11 September
This is the most widespread confusion, and it is costly in both directions: either you mobilise for obligations that are fifteen months away, or you assume you are safe until 2027 and miss the one that already applies.
| Obligation | Applies from |
|---|---|
| Reporting of actively exploited vulnerabilities and severe incidents | 11 September 2026 |
| Essential design requirements (Annex I) | 11 December 2027 |
| Technical documentation (Annex VII) | 11 December 2027 |
| Conformity assessment, possible involvement of a notified body | 11 December 2027 |
| EU declaration of conformity and CE marking | 11 December 2027 |
In other words: on 11 September 2026, nobody will come asking for your technical file. But if a vulnerability in your product is being exploited and you have not reported it, that is a breach — whatever the state of the rest of your compliance work.
What triggers a report
Two distinct facts, regularly confused. The distinction matters, because the final report deadline is not the same for both.
An actively exploited vulnerability
A flaw in your product that someone is actually using — not a theoretical one. The trigger is not the publication of a CVE, it is the observation of exploitation. You may learn of it from a customer, a security researcher, your own monitoring or a publication.
A severe incident affecting the security of the product
An event that actually compromises the security of the product or of the data it processes. Here too the trigger is knowing about the event, not resolving it or fully understanding it.
In both cases the clock starts when you become aware. Not when you have understood what is going on, nor when you have a fix. This is the point engineering teams find hardest to accept: you report before you know.
The countdown
| Stage | Deadline | What goes in it |
|---|---|---|
| Early warning | 24 hours | The bare minimum: who you are, which product, what you know. The information may be partial — that is by design. |
| Notification | 72 hours | The technical details available and, where applicable, the corrective or mitigating measures already taken. |
| Final report — vulnerability | 14 days | After a fix or a mitigating measure has been made available. |
| Final report — incident | 1 month | After the 72-hour notification. |
Twenty-four hours does not mean twenty-four working hours. A report arising on a Friday evening before a long weekend must go out before Sunday night. That is precisely why the checklist below insists on deputies.
The reporting checklist
Eight points. None requires budget, all require a decision. Allow half a day of meetings to work through them, and one morning for the dry run.
1. Name the person who decides
One named person who settles “we report / we do not”. In an SME this is often the managing director or the technical director. Add a deputy: the question will not arise at a moment when you happen to be available.
2. Name the person who drafts and sends
Not necessarily the same person who decides — and preferably not: whoever decides is usually the one handling the customer side of the crisis at the same moment.
3. Identify the competent CSIRT and the sending channel
Do this now, not on the day. Designating the coordinating CSIRT is a matter for each Member State: identify the one you fall under, locate the reporting channel, and if an account is needed, create it while calm.
4. Write the procedure on one page
One page, not a binder. Who decides, who drafts, where it goes, which deadlines, where the templates are. If it fits on one page, it will actually be read on the day it matters.
5. List the products and versions concerned
You cannot report what you have not inventoried. Which products are on the European market, in which versions, at how many customers. Older products still in service count too.
6. Decide where you are watching
An exploited vulnerability rarely reaches you by registered post. It comes through support, through a customer, through a researcher who does not know whom to write to. Open a visible security contact address and actually watch it.
7. Prepare the early-warning template
A pre-filled document with your company details, your contact, the field structure. On the day, only the facts should be left to fill in.
8. Run a dry run
One morning. Someone announces a scenario, the team works through to a drafted alert — without sending it. Two hours will reveal the three things that would have blocked you on the day.
Who does what in a twenty-person company
You have no CISO, no security operations centre, no in-house lawyer. That is not a handicap for this obligation: three roles are enough. One person can hold two of them, but each must have a name and a deputy.
The decider
Settles it in under an hour: is this a reportable fact? Where there is genuine doubt, report — the two later stages exist precisely to correct course.
The drafter
Fills in the template, sends, files the acknowledgement. Preferably a technical profile, because they will have to describe the flaw without saying too much.
The customer contact
Answers the customers calling in parallel. Without them, the drafter spends the day on the phone and misses the deadline.
The weak point of a twenty-person team is not competence, it is availability. One name per role and you are exposed to holidays, sick leave and travel. Two names per role, and the obligation becomes sustainable.
What the first alert must contain
The twenty-four-hour alert is not an expert report. It is short, factual, and may be incomplete: that is exactly why the Regulation provides two further stages.
- Who you are: legal name, role (manufacturer), a contact who can be reached.
- Which product, which versions, and the estimated deployment footprint.
- The nature of the fact: actively exploited vulnerability, or severe incident.
- What you know at this point and — just as important — what you do not yet know.
- How you learned of it and since when.
- Measures already taken or decided, even provisional ones.
Writing “at this stage we do not know whether other versions are affected” is an acceptable answer in an early warning. Sending nothing because you do not yet know is not.
Five costly mistakes
Waiting to understand before raising the alert
Twenty-four hours does not allow a full analysis, and the Regulation does not ask for one. The early warning is designed to be partial.
Confusing a vulnerability with an incident
Both are reported, but the final report deadline differs — fourteen days on one side, one month on the other. Qualifying the fact in the first hour avoids working to the wrong calendar.
Having only one name per role
Incidents do not consult the holiday planner. A role without a deputy is a vacant role one week in six.
Forgetting older products
Equipment delivered six years ago and still running at a customer site is still your product. It is often the one carrying the most dated components.
Assuming the subcontractor handles it
The obligation falls on whoever places the product on the market under their own name. You can outsource development, not reporting.
And after 11 September
The next deadline is 11 December 2027, and it is nothing like the same volume of work: essential requirements, technical documentation, conformity assessment, CE marking. The best use of the fifteen months between the two dates is to start with the component inventory — without it, none of what follows can be verified.
Frequently asked questions
My product has been on the market for years. Am I concerned?
The Regulation phases in its application (Art. 71) and includes transitional provisions; how exactly this works for a product already on the market is a point to settle with counsel. In practice the question matters little: setting up the reporting chain costs half a day, and an older product still in service is precisely the one most likely to carry an exploited vulnerability.
Which CSIRT is competent for my company?
Designating the coordinating CSIRT is a matter for each Member State. That is exactly why point 3 of the checklist is to identify it now rather than on the day the clock starts running.
What if I report something that turns out to be minor?
The Regulation structures reporting in three stages precisely because the initial information is incomplete and may evolve. An alert later corrected is still an alert; an alert never sent is a breach.
The vulnerability comes from an open-source component. Is it mine to report?
The obligation falls on the manufacturer of the product placed on the market, whatever the origin of the faulty component. A third-party component integrated into your product falls under your responsibility for the purposes of the Regulation.
Should I inform my customers at the same time?
Reporting to the CSIRT and ENISA is distinct from informing your users. Both exist, with different logics and timescales. Do not make the first depend on the second: the twenty-four-hour clock does not pause while you draft a customer notice.
What does meeting this deadline cost?
Almost nothing in euros: half a day of meetings for the eight checklist points, one morning of dry run, and a security contact address. It is the only CRA deadline of which that can be said — all the more reason not to miss it.
Source: Regulation (EU) 2024/2847, Articles 14 and 71. The deadlines quoted are those of Article 14.