Answer the 24-hour question.
From 11 September 2026, Cyber Resilience Act reporting obligations apply. When a vulnerability in a product you have placed on the EU market is being actively exploited, you have 24 hours to file an early warning. Vibgrate Evidence tells you which products, which shipped versions, which markets, and which are still in support — with signed evidence.
Most teams are planning for the wrong date
The Cyber Resilience Act has two dates, and most plans look at the second one.
The date in the plan
Conformity assessment, CE marking, technical documentation, and the formal SBOM obligation.
The date that arrives first
Reporting obligations: 24-hour early warning, 72-hour notification, 14-day final report — for products you shipped years ago.
The catch: because the formal SBOM mandate sits in the 2027 tranche, most teams have deferred the inventory work. But you cannot determine within 24 hours whether you are affected unless you already know which components are in which shipped releases. SBOM readiness isn’t a 2027 problem — it’s a September prerequisite.
Are you actually in scope?
We would rather tell you no than sell you something you don’t need.
Likely in scope
- Embedded and IoT products
- Industrial and building automation
- Network and security appliances
- On-premises and installable software
- Firmware and components placed on the market separately
- Hybrid products with an installed client or agent
Likely not in scope
- Software delivered purely through a browser with no installable component
- Standalone SaaS, PaaS and IaaS (generally addressed by NIS2, not the CRA)
Genuinely ambiguous
The boundary between a product’s remote data processing solution and a general cloud service. Cloud enters CRA scope as a remote data processing solution only where the manufacturer supplies it as part of the product and the product cannot perform one of its functions without it. This is a decision aid, not legal advice — confirm your determination with counsel.
What the timeline requires
Early warning, from becoming aware of active exploitation.
Full notification — nature, impact, mitigations, affected population.
Final report, once a corrective or mitigating measure is available.
Reports are filed through the ENISA Single Reporting Platform established under Article 16 — one submission reaches the coordinator CSIRT and ENISA at once. Emailing a national CSIRT directly does not satisfy the obligation. The duty applies to non-EU manufacturers whose products reach the EU market, and to products placed on the market years ago.
11 September is a fixed date
Vibgrate Evidence answers the 24-hour question with signed, reproducible evidence — and runs a timed drill so your first attempt isn’t the real one.
Vibgrate produces evidence to support your CRA obligations. It does not determine compliance and is not legal advice. Obligations under Regulation (EU) 2024/2847 rest with the manufacturer.