← Back to news 24.08.2026

Old does not mean exempt

The Cyber Resilience Act applies from December 2027, and existing products are spared until then. For the reporting duty starting 11 September, exactly that does not hold: a separate paragraph explicitly withdraws the exemption.

In just over two weeks, on 11 September 2026, the first binding obligation of the Cyber Resilience Act takes effect. That is remarkably early, because the Regulation itself only applies from 11 December 2027. Article 71 names both dates in one sentence: the Regulation applies from December 2027, but Article 14 from September 2026.

More interesting than the date is the question of which products it covers. And there sits a construction that is easy to miss on a first reading.

Paragraph 2 grants, paragraph 3 withdraws

The transitional provision in Article 69(2) sounds reassuring: products placed on the market before 11 December 2027 are subject to the Regulation's requirements only if they undergo a substantial modification after that date. Reading that, one reasonably concludes that the installed base stays out of scope as long as it is left alone.

The next paragraph withdraws exactly that. By way of derogation from paragraph 2, the obligations of Article 14 apply to all products with digital elements within scope that were placed on the market before 11 December 2027.

The grace period for the installed base therefore covers the product requirements, not the reporting. Anything that has been in the field for years and never touched again becomes reportable on 11 September just like a new product.

Two clocks running at once

Reporting goes to two places simultaneously: the CSIRT designated as coordinator and ENISA, via a single reporting platform. Responsible is the CSIRT of the member state where the manufacturer has its main establishment in the Union.

The deadlines for an actively exploited vulnerability are staggered in Article 14:

Within 24 hours of becoming aware, an early warning, stating the member states in whose territory the product has been made available. That detail is the quiet landmine: it presumes you know where your own products went.

Within 72 hours, the vulnerability notification with information on the product, the nature of the exploitation and measures already taken, including what users can do themselves.

No later than 14 days after a corrective measure becomes available, a final report with severity, impact and, where known, information on the attacker.

The same mechanism runs for severe incidents. There, the early warning must state at least whether the incident is suspected to result from unlawful or malicious acts.

The obligation nobody has on their list

Alongside reporting to the authorities, paragraph 8 sets a second duty: the manufacturer informs the affected users, and where appropriate all users, about the vulnerability or incident and about what they themselves can do. The Regulation expressly asks for this in a structured, machine-readable format.

That is no aside. It means that in a real case you must be able to write not only to an authority within hours, but to your own customers, in a form their tools can ingest.

What this means now

24 hours from awareness is not a deadline you organise once the event happens. Anyone who may have to report in September needs three things beforehand: a place where reports about their own products arrive, a list of which products were made available in which member states, and a named access to the reporting platform of the responsible CSIRT.

More on the Cyber Resilience Act solution page.

Matching solution isidaten for Cyber Resilience Act

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.