Blog
What the Cyber Resilience Act requires, article by article, and by when. Every claim links to its source; what is not binding is flagged as such.

The ENISA platform is open: what it requires at 24 hours, and five things to do this week
Since 11 September 2026, reporting an actively exploited vulnerability goes through ENISA’s Single Reporting Platform, now live. Screen by screen, as recorded on the platform on 12 September: what it requires at 24 hours, what it does not do, and what can be prepared before a clock starts.

The Cyber Resilience Act: cybersecurity is no longer just for regulated industries
For years, a company selling software, a connected device or an app in Europe had no legal obligation to secure its product. A toaster had to prove it wouldn’t catch fire; a connected thermostat had to prove nothing at all. The Cyber Resilience Act (Regulation (EU) 2024/2847) closes that door — and its first binding milestone falls on 11 September 2026.
What becomes mandatory on 11 September 2026 — and what does not, yet
On 11 September 2026, reporting actively exploited vulnerabilities becomes a legal obligation, including for products already on the market. The rest of the regulation, penalties included, waits until 11 December 2027. In between: a platform that is not open yet, and a format no legal act defines.
Does the CRA apply to your product? Three questions to place it
The Cyber Resilience Act is the EU regulation that imposes cybersecurity obligations on digital products made available on the Union market. It does not cover everyone, and the dividing line is not the one most people expect: it depends neither on your sector nor on your technology.
The 26 fields of the ENISA notification: what to prepare before 11 September 2026
The reporting form for an actively exploited vulnerability has 26 fields. The Regulation itself names almost none of them. Five carry information you already hold today; seven will have to be written during the incident.
Article 14: five mandatory fields at 24 hours
The Article 14 reporting obligation applies from 11 September 2026. The first stage asks for five fields, with no CVE identifier and no CVSS score. The real load lands at 72 hours, and it calls for judgement rather than data.