← All articles

Cyber Resilience Act: the first deadline is not 2027, it is 11 September 2026

28 July 20263 min read

The CRA's first binding obligation is not December 2027: it is 11 September 2026, when reporting of actively exploited vulnerabilities begins. What the Commission's new guidance says and what to prepare now.

Almost everyone has filed the Cyber Resilience Act under one date: December 2027. That is wrong. The first binding obligation starts on 11 September 2026: reporting of actively exploited vulnerabilities and severe incidents. On 27 July the Commission published its first official application guidance, Communication C(2026) 5252.

What starts on 11 September

In force since 10 December 2024, it applies in full from 11 December 2027. In between sits Article 14, from 11 September 2026. From that day a manufacturer of a product with digital elements has three clocks: early warning within 24 hours of becoming aware, full notification within 72 hours, final report within 14 days of a corrective measure being available for exploited vulnerabilities, or within one month for severe incidents.

Reports go through the Single Reporting Platform ENISA is building, operational by 11 September, landing with the CSIRT of your main establishment and ENISA at once. For an Italian manufacturer that is CSIRT Italia, the same counterpart as NIS2, so a NIS2 procedure gives you a head start. And note: it also covers products already on the market before the CRA applies in full, if they are still on sale in the EU in September.

You are a manufacturer even if you do not feel like one

This is where the typical manufacturing SME gets caught. Sell a machine with a web dashboard, a connected sensor, a device with a companion app, firmware or packaged software and you are a manufacturer under the CRA, whatever your website calls you.

Where the product ends

On the most argued-over point the guidance gives a test: standalone SaaS generally stays out, but remote data processing designed by the manufacturer, without which the product cannot perform one of its functions, falls inside the product boundary. Translated: if the machine does not work without the portal, the portal is part of the machine. Not a yes or a no: a test to apply function by function.

What to do before September

  • Assign the 24 hours: you need a reachable person with a name, not a shared mailbox. The clock starts when you become aware, not when someone opens a ticket.
  • Prepare the EU Login, not the SRP account: credentials can be created in advance, but ENISA asks you to register on the platform only when you have a real report to file.
  • Generate the SBOM in the pipeline: on a Node or PHP build that is CI work, not a spreadsheet updated once a year.
  • Check the support period: five years minimum, unless the expected lifetime is shorter, and must square with frameworks whose LTS is far shorter.

Verdict

C(2026) 5252 is non-binding, and no harmonised standard has been cited in the Official Journal: the Article 27 presumption of conformity does not exist today. But it is unusually readable for a Commission document: 67 practical examples, microenterprises and SMEs as the stated audience. Penalties on reporting reach 15 million euro or 2.5% of annual worldwide turnover, whichever is higher; but for an SME the real risk is not the fine, it is reaching September without knowing who answers the phone. If you build software for a manufacturer, your client's CRA problem becomes a clause in your contract by the autumn. Better to arrive having read the guidance.