You develop software or sell connected hardware, and one date keeps coming up: 11 September 2026. It is real, it is close, and it is widely misread — it is not the day Regulation (EU) 2024/2847 applies in full, it is the day a single one of its obligations starts to apply. This article separates what becomes mandatory that day from what does not, with the text to back it.

What applies on 11 September

The obligation entering into application is Article 14: reporting any actively exploited vulnerability (a flaw someone is demonstrably using) and any severe incident having an impact on the security of a product with digital elements, meaning software or connected hardware placed on the Union market. Reporting happens in three stages (24 hours, 72 hours, final report) to the designated national CSIRT, the computer security incident response team appointed by each Member State, and simultaneously to ENISA, the European Union’s cybersecurity agency. In practice, one submission is enough: the single reporting platform, described below, serves both recipients at once. The calendar itself comes from the text of the regulation:

This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.
Regulation (EU) 2024/2847, Article 71(2)

Chapter IV concerns the designation and notification of conformity assessment bodies, that is, administrative infrastructure on the Member State side. For a manufacturer, the only obligation starting before December 2027 remains reporting.

One point consistently takes companies by surprise: the obligation also covers products already on the market. A product placed on the market in 2023 and still in use falls within the reporting obligation on 11 September 2026: the transitional provisions of Article 69 expressly provide for it, without waiting for the other obligations to apply to it.

What does not apply yet

Everything else waits until 11 December 2027: the essential cybersecurity requirements of Annex I, conformity assessment and CE marking, technical documentation, the support period, market surveillance. On 11 September 2026, a manufacturer has to be able to report, without having to be compliant with the regulation in the full sense.

What about fines? The regulation provides for them, and failure to comply with the reporting obligation sits in the highest tier:

Non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.
Regulation (EU) 2024/2847, Article 64(2)

But Article 64 itself is not among the exceptions in the calendar quoted above: like the rest of the regulation, it applies from 11 December 2027. Between 11 September 2026 and that date, the obligation to report is in force; the regulation’s administrative fine regime is not yet. This gap is not a grace period: the text says where the obligation starts and where the fine starts; it says nowhere that a failure committed before December 2027 is erased.

Another absence, less widely known: the format of the notifications. No legal act defines it. The regulation merely opens a door for the Commission, that of an implementing act, an application text it can adopt on its own, without going back to the legislator:

The Commission may, by means of implementing acts, specify further the format and procedures of the notifications referred to in this Article as well as in Articles 15 and 16.
Regulation (EU) 2024/2847, Article 14(10), first sentence

As of 19 August 2026, that power has not been exercised: no implementing act specifies the format. The only available field-by-field structure comes from ENISA’s frequently asked questions, whose question 16 details, stage by stage, what the platform will expect.

The platform opens the day the obligation starts

The practical consequence fits in one sentence: the tool opens on the very day the obligation starts, and nobody will have used it in real conditions before the deadline. No postponement of the date has been announced as of 19 August 2026, and no public request for one has been recorded. Preparing the content of your notifications without waiting for the tool is the only tenable position.

Three things to do before 11 September

  • Settle the scope, product by product. The obligation only covers products with digital elements placed on the Union market in the course of a commercial activity. Knowing which of your products are covered is the prerequisite for everything else: our analysis “Does the CRA apply to your product?” walks through the criteria one by one.
  • Prepare what can be prepared cold. In ENISA’s structure, part of the fields can be filled in ahead of time (identity, product, contact details) and the decisions of the 72-hour stage can be framed before any incident: who assesses severity, who describes corrective measures, who informs users. Our two Article 14 analyses cover the structure field by field.
  • Decide who decides, and on what criterion. The line between the Article 14 obligation and voluntary notification under Article 15, the channel open to reports without established evidence of exploitation, is precisely that evidence. The guidance reads awareness as formed after an initial assessment, with a reasonable degree of certainty (§ 211 to 214). Deciding now who rules “exploited or not” beats finding out mid-incident, with the 24-hour clock already running.

11 September 2026 asks you to be organised and able to report within 24 hours. CE marking, complete documentation and full compliance are only due on 11 December 2027. These three steps fit in the time that remains.