A month ago we wrote that almost everyone had filed the Cyber Resilience Act under the wrong date, December 2027, while its first binding obligation starts on 11 September 2026. Nothing has changed since, except the calendar: under three weeks left. If you build or sell a product with digital elements, this is the checklist to close now, not the article to read at leisure.
What starts on 11 September
Under Article 14 the manufacturer has three clocks: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident, full notification within 72 hours, a final report within 14 days of a fix being available for vulnerabilities and one month for severe incidents. Reporting goes through the single platform ENISA is bringing online for that date, landing with your national CSIRT at the same time. For an Italian manufacturer that is CSIRT Italia, the same counterpart as NIS2.
The SME parachute, and its limits
Microenterprises and small enterprises cannot be fined for missing the 24-hour deadline. Read it carefully: the duty to report still applies, only the late-filing fine falls away. And standalone SaaS is, in general, outside the CRA's boundary, while remote data processing without which the product does not work falls inside: a test to run function by function, not a yes or no.
The final checklist, in this order
- Assign the 24 hours to a person: a named, reachable individual, not a shared mailbox. The clock starts when you become aware, not when someone opens a ticket.
- Prepare the EU Login: credentials can be created in advance. ENISA asks you to register on the platform only when you have a real report to file, but the access should be tested first.
- SBOM in the pipeline: on a Node or PHP build that is CI work, not a spreadsheet updated once a year. You need it to know what to report when the flaw is in a dependency.
- Check the support period: five years minimum unless the expected lifetime is shorter, to be squared with frameworks whose LTS is far shorter.
- Write the procedure: who decides an event is reportable, who drafts, who files. The 24-hour window is not improvised at three in the morning.
Verdict
If you build software for a manufacturer, your client's CRA problem is about to become a clause in your contract, and the conversation is far easier if you reach 11 September with the procedure already written. Penalties on reporting reach 15 million euro or 2.5% of worldwide turnover, but for an SME the real risk is not the remote fine: it is facing an exploited vulnerability with nobody who knows who to call, and in how many hours. Close the five points before September.