Sembra che tu preferisca leggere in italiano.

Passa all'italiano
← All issues

15 September 2026·CRA

September 2026: the 11th has passed, the CRA reporting duty is live

Welcome to the first issue of State of Play. One email a month on what actually moved in the rules that touch the industrial product — AI Act, Cyber Resilience Act, NIS2 — with one rule: only what changes a decision, no press round-up.

What changed this month

On 11 September 2026, the reporting obligation under Article 14 of the Cyber Resilience Act kicked in. It is no longer a date on the calendar: it is an active duty, and it applies to products already on the market too.

The clock runs in hours, not weeks:

  • early warning within 24 hours of discovering an actively exploited vulnerability or a severe incident;
  • notification within 72 hours;
  • final report within 14 days.

The channel is the single reporting platform operated by ENISA (Article 16), routing to the national coordinating CSIRTs.

Why it matters for you

A reporting process cannot be stood up the moment you need it: by the time you discover the vulnerability, the 24 hours have already started. The three questions you must be able to answer today:

  1. Who is authorised to notify on behalf of your company?
  2. Do you have an EU Login account ready, with the right people able to access it?
  3. Is there a minimum process for the first 24 hours — who decides, what gets written, who it goes to?

If any of these answers is “I don’t know”, you are exposed to a deadline that is already in force.

Where it turns into opportunity

Reaching this deadline with a clean process is not just about avoiding a penalty: it builds a trust advantage with customers and distributors, who increasingly ask for evidence of reporting readiness before they sign. Orderly reporting is a commercial argument, not only a compliance box.


The operational detail of the channel is in the guide on the single reporting platform; the up-to-date status of every CRA deadline is in the implementation tracker.

See you next month.

Alberto Scarpa

AI · Cybersecurity · Regulation — I help industrial manufacturers integrate regulatory requirements into product decisions.

Not sure where to start?

45 free minutes to map your regulatory exposure — applied to your specific product.

Book the Regulatory Spark