Skip to main content
EU Cyber Resilience Act

Answer the 24-hour question.

From 11 September 2026, Cyber Resilience Act reporting obligations apply. When a vulnerability in a product you have placed on the EU market is being actively exploited, you have 24 hours to file an early warning. Vibgrate Evidence tells you which products, which shipped versions, which markets, and which are still in support — with signed evidence.

Most teams are planning for the wrong date

The Cyber Resilience Act has two dates, and most plans look at the second one.

11 December 2027

The date in the plan

Conformity assessment, CE marking, technical documentation, and the formal SBOM obligation.

11 September 2026

The date that arrives first

Reporting obligations: 24-hour early warning, 72-hour notification, 14-day final report — for products you shipped years ago.

The catch: because the formal SBOM mandate sits in the 2027 tranche, most teams have deferred the inventory work. But you cannot determine within 24 hours whether you are affected unless you already know which components are in which shipped releases. SBOM readiness isn’t a 2027 problem — it’s a September prerequisite.

Are you actually in scope?

We would rather tell you no than sell you something you don’t need.

Likely in scope

  • Embedded and IoT products
  • Industrial and building automation
  • Network and security appliances
  • On-premises and installable software
  • Firmware and components placed on the market separately
  • Hybrid products with an installed client or agent

Likely not in scope

  • Software delivered purely through a browser with no installable component
  • Standalone SaaS, PaaS and IaaS (generally addressed by NIS2, not the CRA)

Genuinely ambiguous

The boundary between a product’s remote data processing solution and a general cloud service. Cloud enters CRA scope as a remote data processing solution only where the manufacturer supplies it as part of the product and the product cannot perform one of its functions without it. This is a decision aid, not legal advice — confirm your determination with counsel.

What the timeline requires

24 hours

Early warning, from becoming aware of active exploitation.

72 hours

Full notification — nature, impact, mitigations, affected population.

14 days

Final report, once a corrective or mitigating measure is available.

Reports are filed through the ENISA Single Reporting Platform established under Article 16 — one submission reaches the coordinator CSIRT and ENISA at once. Emailing a national CSIRT directly does not satisfy the obligation. The duty applies to non-EU manufacturers whose products reach the EU market, and to products placed on the market years ago.

11 September is a fixed date

Vibgrate Evidence answers the 24-hour question with signed, reproducible evidence — and runs a timed drill so your first attempt isn’t the real one.

Vibgrate produces evidence to support your CRA obligations. It does not determine compliance and is not legal advice. Obligations under Regulation (EU) 2024/2847 rest with the manufacturer.