September 2026: the 11th has passed, the CRA reporting duty is live
Welcome to the first issue of State of Play. One email a month on what actually moved in the rules that touch the industrial product — AI Act, Cyber Resilience Act, NIS2 — with one rule: only what changes a decision, no press round-up.
What changed this month
On 11 September 2026, the reporting obligation under Article 14 of the Cyber Resilience Act kicked in. It is no longer a date on the calendar: it is an active duty, and it applies to products already on the market too.
The clock runs in hours, not weeks:
- early warning within 24 hours of discovering an actively exploited vulnerability or a severe incident;
- notification within 72 hours;
- final report within 14 days.
The channel is the single reporting platform operated by ENISA (Article 16), routing to the national coordinating CSIRTs.
Why it matters for you
A reporting process cannot be stood up the moment you need it: by the time you discover the vulnerability, the 24 hours have already started. The three questions you must be able to answer today:
- Who is authorised to notify on behalf of your company?
- Do you have an EU Login account ready, with the right people able to access it?
- Is there a minimum process for the first 24 hours — who decides, what gets written, who it goes to?
If any of these answers is “I don’t know”, you are exposed to a deadline that is already in force.
Where it turns into opportunity
Reaching this deadline with a clean process is not just about avoiding a penalty: it builds a trust advantage with customers and distributors, who increasingly ask for evidence of reporting readiness before they sign. Orderly reporting is a commercial argument, not only a compliance box.
The operational detail of the channel is in the guide on the single reporting platform; the up-to-date status of every CRA deadline is in the implementation tracker.
See you next month.