
The EU’s 24-Hour Clock Starts 11 September: It Also Covers Products You Shipped Years Ago
By, zero-adm
- 24 Aug, 2026
- 7 Views
From 11 September 2026, every maker of connected products sold in the EU has 24 hours to report an actively exploited vulnerability to the authorities, with fines up to 15 million euros or 2.5% of worldwide turnover for those who fail. The clock also runs for products shipped years ago, including those whose support has ended.
The Cyber Resilience Act is the EU law that makes cybersecurity a condition for selling products with digital elements in the single market. Its first hard obligation is not a technical requirement. It is a deadline.
What starts on 11 September 2026?
Article 14 of the regulation. From that date, a manufacturer that becomes aware of an actively exploited vulnerability in one of its products, or of a severe incident affecting a product’s security, must notify ENISA, the EU cybersecurity agency, and the national CSIRT.
The schedule leaves little room for committees. An early warning within 24 hours of becoming aware. A full notification within 72 hours. A final report within 14 days of a fix being available for a vulnerability, or within one month for a severe incident.
The threshold matters: an actively exploited vulnerability means evidence of real attacks, not theoretical exploitability. The day that evidence lands on someone’s desk, the 24 hours begin.
Which products and companies fall in scope?
Products with digital elements placed on the EU market. Hardware with software in it, software sold as a product, the connected devices your product line has been shipping since before anyone said IoT.
Two details deserve a board’s attention. The obligation follows the product, so it covers items shipped years ago and still available on the EU market, even after their support period ended. And it does not care where the maker sits: a company outside the EU that sells into the single market carries the same duties as one in Munich.
The wider calendar gives the reporting duty its place. Rules for the bodies that certify conformity applied from 11 June 2026. Reporting starts 11 September 2026. The full set of obligations, secure-by-design requirements and CE marking included, applies from 11 December 2027.
| Date | What applies |
|---|---|
| 11 June 2026 | Rules for notifying conformity assessment bodies |
| 11 September 2026 | Reporting: 24h early warning, 72h notification, 14-day final report |
| 11 December 2027 | Full application: essential requirements, CE marking |
What if the reporting platform is not ready?
Reports flow through a Single Reporting Platform run by ENISA, which notifies the national CSIRT at the same time. At the end of June 2026 that platform was not yet operational. ENISA had promised registration instructions, training material and dry-run support during June.
The obligation does not wait for the tool. Article 14 applies from 11 September regardless of the platform’s state. A company that plans to figure out the mechanics on the day it discovers an exploited vulnerability will be doing so inside the same 24 hours it owes the regulator.
We wrote in July about the window between disclosure and exploitation shrinking to days. From September, that window carries a legal clock inside it.
And in Switzerland?
Switzerland is not in the EU, and the CRA applies to Swiss manufacturers anyway, the moment their products are offered, supplied or distributed in the EU or the EEA. A Swiss maker selling into that market carries the same duties as any EU manufacturer, the September reporting clock included. The EU importer, for its part, must verify the manufacturer’s conformity before placing the product.
A product sold only in Switzerland stays outside the CRA. For a Swiss exporter of connected products, that distinction is now worth a line in the risk register: the question is not whether your company is Swiss, it is where your products end up.
What to do now
- Decide whether you are in scope, in writing. List what you sell that contains software and where it is sold. If anything reaches the EU or EEA market, on its own or through an importer or distributor, the September clock is yours.
- Write the 24-hour runbook. Name the person who declares that the company is “aware”, the person who files the report, and their deputies for nights and weekends. A rule nobody wrote down fails at 2 a.m. on a Saturday.
- Inventory the products you have stopped thinking about. The duty covers items still on the EU market whose support ended. The product list for this obligation is longer than your current catalogue.
- Assign an owner for the ENISA platform. Someone in your company should register, run the dry-run material when it arrives, and know the submission screen before the first real incident, not during it.
Frequently asked questions
Does this apply to my company if we only sell software?
Software placed on the EU market as a product with digital elements falls in scope. The fine boundaries, for pure services or open-source components among others, deserve a lawyer’s reading of your specific catalogue.
What must we report, and to whom?
Two things: vulnerabilities in your products that someone is actively exploiting, and severe incidents affecting a product’s security. Reports go to ENISA and the national CSIRT through the Single Reporting Platform, with an early warning due 24 hours after you become aware.
What are the penalties?
Fines up to 15 million euros or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the core obligations.
We are a Swiss company. Does the CRA reach us?
Yes, as soon as your products are offered or supplied in the EU or EEA. The obligations are the same as for an EU manufacturer, the reporting clock included. Products sold only in Switzerland stay outside.
Is a vulnerability report public?
It goes to ENISA and the national CSIRT, and it exists as a record. Deciding what you tell customers, and when, remains your call within the wider disclosure rules that apply to you.
If evidence of an exploited vulnerability in your product arrived this afternoon, who in your company would own the next 24 hours?
Sources
- European Commission, Cyber Resilience Act, reporting obligations (primary).
- ENISA, Single Reporting Platform (SRP) (primary).
- DLA Piper, “The CRA’s 24-Hour Rule”, August 2026.
- Crowell & Moring, EU CRA countdown to 11 September 2026.
- Homburger, “EU Cyber Resilience Act’s Impact on Swiss Companies”.
- cyberresilienceact.eu, SRP status as of 29 June 2026.
Recent Posts
- The EU’s 24-Hour Clock Starts 11 September: It Also Covers Products You Shipped Years Ago
- Three AI Agents, One Project, Four Hours: Anthropic Watched Them Turn on Each Other
- Device Code Phishing Grew 15x in 2026: Why Passkeys Do Not Stop It
- The Swiss Transparency Register Goes Live 1 October 2026: 500,000 Companies, and One More Field Than the Register Just Stolen
- Third-Party Breaches Hit 48% in 2026: EY and a Swiss Fiduciary Leaked the Same Way
Category
- Cyber Security (95)
- Vulnerability Assessment (71)
Newest Posts
All Tag
2025 AI AI Agents AI Governance Anthropic Automation Awareness Beneficial Ownership Business CISO Competition Law Compliance CRA CrowdStrike Cybercriminals Cyber Resilience Act CyberSecurity Academy Cybersecurity Awareness Dataprotection ENISA EU AI Act EU Regulation Future GDPR Identity Security Malware Microsoft Entra ID Multi-Agent Systems nFADP NIS2 nLPD Passkeys Phishing Privacy Product Security Ramsonware Ransomware Supply Chain Threat Intelligence Treat Detection Unit 42 Vulnerability Assessment Vulnerability Management Zero-Day Zeroedge Academy
