Skip to content
← All posts

13 September 2026

5 min read

Written by

Clément Lacaille

Clément Lacaille

Founder, Tech-Bharat

About the author
Business & compliance

The EU Cyber Resilience Act’s vulnerability-reporting duty is now live — and it may already apply to your software

On September 11, 2026, Article 14 of the EU Cyber Resilience Act took effect: any company that "manufactures" a product with digital elements — hardware or software sold under its own brand — must now report an actively exploited vulnerability within 24 hours and a severe incident within 72 hours, to ENISA and France’s national CSIRT, under fines of up to €15 million or 2.5% of global turnover. A 2024 academic survey found only 12.3% of SMEs were even aware the regulation existed. Here is what actually changed, who it concerns, and where to start.

On September 11, 2026, the reporting obligations under Article 14 of the EU Cyber Resilience Act came into force — more than a year before the regulation’s main cybersecurity requirements, which only apply from December 11, 2027. From now on, any "manufacturer" of a product with digital elements placed on the EU market — hardware or software sold under its own name — must report an actively exploited vulnerability within 24 hours of becoming aware of it, file a full notification within 72 hours, and submit a final report within 14 days of a fix becoming available (or within one month for a severe incident). Both reports go to two recipients at once: ENISA’s new Single Reporting Platform and the national CSIRT designated under the NIS2 directive — in France, ANSSI’s CERT-FR. Fines for missing this run up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, and the obligation already covers products placed on the market before this date.

What actually changed on September 11

  • →Regulation (EU) 2024/2847, adopted in 2024, splits into two timelines: reporting duties from September 11, 2026, and the full set of essential cybersecurity requirements (CE marking, technical documentation) only from December 11, 2027.
  • →The 24-hour / 72-hour / final-report chain applies the moment you become aware of an actively exploited vulnerability or a severe incident affecting a product you place on the market — not only once the 2027 compliance deadline arrives.
  • →Legacy products already sold before September 2026 are covered too, as long as they remain on the market.
  • →A missed or late report is itself a breach, independent of whether the underlying vulnerability was ever exploited against a customer.

Does this actually concern your SMB?

The regulation’s definition of "manufacturer" is broader than "industrial hardware maker." It covers any company that develops, or has developed, a product with digital elements and places it on the EU market under its own brand — a packaged software product, a plugin, a connected device, or bespoke software delivered under your own name. It generally does not cover an agency or a software house that builds a product released under a client’s brand, and pure cloud SaaS usually falls outside the scope unless it functions as the remote-processing component of a product. In practice: if your SMB publishes and sells a piece of software or a connected device under its own name in the EU, you are very likely a "manufacturer" under this regulation today — whether or not anyone in your company has ever heard of the Cyber Resilience Act.

The gap the law is stepping into

That last point is not theoretical. A 2024 survey by Szedlak, Reinemann and Hatzelmann, covering 673 companies including 416 SMEs, found that only 12.3% of SMEs were aware the Cyber Resilience Act existed at all, against 83.5% of very large enterprises — and among those aware, a shortage of skilled staff and the absence of any formal vulnerability-handling process were the most cited obstacles to compliance. The reporting duty that took effect this week does not wait for that awareness gap to close.

What it changes for your SMB

Most SMBs that build or resell software have filed the Cyber Resilience Act under "2027 problem, deal with it later" — the CE-marking and technical-documentation requirements genuinely are still 15 months away. The reporting duty is not: it is enforceable now, with the same fine ceiling, and it requires something most small software teams do not yet have — a way to know, within hours, that one of their own dependencies has an actively exploited vulnerability, and a designated person who can file that report to ENISA and CERT-FR inside a 24-hour clock. Building that process after an incident starts is exactly the wrong order.

Concrete steps

  • →Decide, in writing, whether your company is a "manufacturer" under the CRA for each product you sell — a self-branded software product or connected device counts; work delivered under a client’s brand generally does not.
  • →If you do not maintain an inventory of the open-source and third-party components in your product (a software bill of materials), start one — you cannot report a vulnerability you have no way of detecting.
  • →Name one person or team responsible for the 24-hour early warning and 72-hour notification to ENISA’s Single Reporting Platform and to CERT-FR, before you need them.
  • →Put continuous monitoring of exploited vulnerabilities affecting your own dependencies in place rather than relying on someone stumbling across the news — this is exactly the kind of standing watch a regulatory-monitoring agent or an operations-monitoring agent is built to run.
  • →Do not wait for the December 2027 deadline to start: the fine ceiling for a missed report is already active, independent of the rest of the regulation.

The headline most coverage led with was the 2027 compliance deadline. The part that actually bites starting this week is smaller and easy to miss — and it applies to a lot more French SMBs than the word "manufacturer" usually suggests.

Frequently asked questions

What changed on September 11, 2026 under the Cyber Resilience Act?+

The regulation’s reporting obligations (Article 14) came into force: any manufacturer of a product with digital elements placed on the EU market must report an actively exploited vulnerability within 24 hours and a severe incident within 72 hours, to ENISA and the national CSIRT, under fines of up to €15 million or 2.5% of global turnover.

Does this apply to a small software company or just industrial manufacturers?+

It applies to any company that develops and markets, under its own brand, a hardware or software product with digital elements in the EU — including a self-branded software product, a plugin or a connected device. It generally excludes agencies building under a client’s brand, and pure SaaS unless tied to a product’s remote-processing function.

What should an SMB do first?+

Confirm in writing whether it counts as a "manufacturer" for each product it sells, build or update its inventory of software components (SBOM), and designate who is responsible for filing a report to ENISA and CERT-FR within 24 hours of learning about an actively exploited vulnerability.

Free resource

The self-assessment grid: 20 tasks AI can automate

Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.

Read next