The vulnerability report lands on a Friday afternoon. Someone on a security mailing list has proof that a bug in your firmware is being exploited in the wild, on customer devices, right now. Before 11 September 2026 that started a conversation with engineering. After it, it starts a stopwatch. Cyber Resilience Act compliance turns that moment into a filing deadline measured in hours, and the clock does not care that your incident lead is on a plane.

Why Does The 11 September Deadline Matter?
The 11 September 2026 date matters because it is the first Cyber Resilience Act obligation with real enforcement behind it, arriving well ahead of the full application of the Act at the end of 2027.
The mechanism is narrower than the headlines suggest. You file once, through the CRA Single Reporting Platform, to the computer security incident response team in the country where your main establishment sits, and that team passes it on to every other CSIRT where the product is sold. ENISA sees it at the same time. One filing, one platform, twenty-seven markets covered. Set against the patchwork most manufacturers already handle under other EU rules, including the transparency duties that came into force under the EU AI Act in August, this part is a real simplification.
The common advice right now is to wait for the harmonised standards before doing anything. That advice is wrong for reporting. Wrong for most of the Act, actually, but reporting is where it costs you soonest. Standards govern how you demonstrate that a product meets the essential requirements, and those obligations arrive more than a year later. Article 14 reporting does not wait for a standard. It needs a named person, a monitored inbox and a decision rule about what counts as evidence of exploitation, all of which you can build this month.
Cost is where this stops being an engineering conversation. The European Commission's 2022 impact assessment, the document that underpins the Act, priced compliance at roughly 2% of the €1.485 trillion of EU turnover the rules touch. That is the same order of magnitude producers found when packaging EPR reporting landed across seven US states this year, and the pattern rhymes. A rule written for accountability produces, first, a data collection problem.
Early warning
24 hours
To your national CSIRT
Average cost
€47,000
Per manufacturer, one-off
Firms in scope
615,272
The Commission's own count
Development uplift
30.5%
Added to build cost
Look at the development uplift on its own. It is not a fee you pay at the end, and it is not something a certification body sells you. It is threat modelling, dependency hygiene, a signed update channel and someone whose job is to say no to a shipping date. Firms already doing that will barely feel the Act. Firms treating security as a pre-launch audit will find that the money was never the hard part.
Twenty-four hours is not an incident response window. It is a notification window that opens before you know what you are dealing with, and the two are not the same thing.
What Cyber Resilience Act Compliance Costs
The Act charges a manufacturer twice, once to prove a product is secure before it ships and then continuously for its whole supported life, which is why the assessment fee everyone quotes understates the bill.
The numbers below are the ones a finance lead asks for first. Two of them are choices rather than fixed costs, namely the assessment route you take and how long you commit to supporting the product.
| Category | Detail | Insight |
|---|---|---|
| Scope | Cyber Resilience Act scope covers any product with digital elements sold in the EU, hardware and standalone software alike | Software counts, not only devices |
| Trigger | CRA reporting obligations fire on an actively exploited vulnerability or a severe incident, not on a routine CVE | Evidence of exploitation, not suspicion |
| Second filing | Actively exploited vulnerability reporting needs a fuller notification within 72 hours of awareness | Two filings before day four |
| Final report | 14 days after a corrective measure is available; one month for a severe incident | The clock outlives the patch |
| Top fines | Cyber Resilience Act fines reach €15m or 2.5% of worldwide annual turnover, whichever is higher | Turnover test bites larger firms hardest |
| Lower tiers | €10m or 2% for vulnerability handling failures; €5m or 1% for misleading information to authorities | Paperwork errors carry their own tier |
| Assessment | €18,400 per product to self-assess, against €25,000 for third-party conformity assessment | Route choice moves the per-product bill |
| Support | At least five years of security updates under Article 13(8), longer where expected lifetime is longer | Cost runs long after launch day |
| Full effect | The cyber resilience act deadline for everything else is 11 December 2027 | Reporting is only the opening move |
Read the fines rows twice. Each tier is an amount or a percentage of worldwide turnover, whichever is higher, so the ceiling scales with the company rather than with the product. A small firm's exposure sits near the cash figure. A large one's does not, and that asymmetry is deliberate.
Where the EUR 29 billion goes: the three shares of the total Cyber Resilience Act bill, from the same 2022 European Commission impact assessment.
How Do Manufacturers Comply Without Tripping Up?
Manufacturers comply by deciding now who files, from which legal entity, and on what evidence, because most first-year failures will be procedural rather than technical: the right facts, reported by the wrong entity, after the window closed.
Start with the definition, because it is doing more work than people expect. A vulnerability counts as actively exploited when there is reliable evidence that a malicious actor has exploited it in a system without the owner's permission. Reliable evidence, not a proof of concept, and not a scanner finding. A severe incident is one affecting the product's ability to protect sensitive data or functions, or one that has led to malicious code being introduced or executed. Both definitions are broad enough that your triage rule matters more than your detection tooling.
Small manufacturers feel this hardest, for the same reason they felt AI adoption hardest: the fixed cost of doing something properly does not shrink with headcount. The arithmetic in the real costs and honest ROI of AI agents for small business has the same shape here. What nobody can tell you yet is how proportionately enforcement will land on a small firm whose exposure arrived through an unmaintained dependency it did not write. The Act has language for open source stewards. Whether a market surveillance authority reads that language generously in year one is a guess, and the likelier outcome is that early enforcement targets firms that ignored a report rather than firms that filed a clumsy one.
- End-of-life components. If a dependency stopped receiving fixes, you inherit the reporting duty for whatever it does next.
- Entity confusion. The filing comes from the manufacturer, which in a group structure is often not the company whose name sits on the support portal.
- Clock start. The window opens when you become aware, not when you finish investigating.
- Contract gaps. Suppliers who owe you nothing on disclosure timing will quietly consume a window you cannot extend.
Three things to settle before the deadline
Name the filer. One person, one deputy, both reachable on a weekend, both with authority to submit without a legal review first.
Register early. Get onto the Single Reporting Platform before you need it, not during an incident at two in the morning.
Write the triage rule down. What counts as reliable evidence should be a document that survives an argument, not the argument itself.
If you make anything with software in it and sell it in Europe, the useful step this week is small. Find out which legal entity is the manufacturer, and give that entity a monitored address a CSIRT filing can come from. Most of the rest can wait a month. That cannot.
No comments:
Post a Comment