> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# EU's Cyber Resilience Act starts the 24-hour vulnerability clock
- URL: https://f4n6.co.uk/security-feed/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/
- Published: 2026-09-11T21:28:17.000Z
- Updated: 2026-09-11T21:28:17.000Z
- Author: Jeff Davies
- Tags: #security-feed

## 1\. Executive summary

The EU Cyber Resilience Act's Article 14 mandatory vulnerability and incident reporting duties became applicable on 2026-09-11\. Manufacturers of products with digital elements made available in the EU — regardless of where the manufacturer is based — must now file an early warning with ENISA's Single Reporting Platform within 24 hours of becoming aware of an actively exploited vulnerability, a detailed notification within 72 hours, and a final report within 14 days of making a corrective or mitigating measure available (one month after first report for serious incidents). These reporting duties are classified as core responsibilities under the Act, meaning non-compliance can attract the maximum fines: €15 million ($17.4 million) or 2.5 percent of annual turnover, whichever is higher. For EMEA financial services clients the near-term exposure is twofold: (1) any client that manufactures or rebrands software/hardware placed on the EU market is now directly in scope, and (2) all clients gain a faster upstream feed of actively exploited vulnerabilities in their third-party products, which shortens the window in which their own incident classification and reporting decisions under DORA/NIS2 must be made. No CVEs, threat actors, or exploitation events are named in the source material; this is a regulatory change, not a vulnerability disclosure.

## 2\. Regulatory framing

| Article                                                 | Trigger (the fact in this item)                                                                                                                                                                                                                                                  | Practical impact                                                                                                                                                                                                                                                           |
| ------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 28: ICT third-party risk — general principles | The CRA's 24-hour manufacturer early-warning regime will surface actively exploited vulnerabilities in ICT products used by financial entities faster than before, and CRA Article 14 notifications are addressed to member-state CSIRTs rather than to financial-sector clients | Clients will learn of exploited product flaws via ENISA/CSIRT channels on a clock set by their vendors' compliance, not by their own monitoring — third-party risk monitoring and vendor notification clauses should anticipate receiving 24h/72h/14-day-cycle information |
| NIS2 Art. 21(2)(d): supply chain security measures      | The source explicitly frames the CRA as forcing manufacturers to maintain continuous, lifecycle-long visibility of product components, dependencies and SBOMs, which directly relates to the supply-chain security measures entities must take towards their ICT suppliers       | Clients procuring products with digital elements can and should demand SBOMs and vulnerability-handling commitments from vendors as part of supply-chain security measures, since CRA-covered vendors are being compelled to produce exactly this information              |

No DORA or NIS2 incident-reporting article is engaged by this item: the CRA reporting clock binds *manufacturers*, not financial entities or NIS2 operators, and no incident at a client is described. Clients' own reporting duties under DORA Art. 19 or NIS2 Art. 23 are unchanged by this item.

## 3\. Technical analysis & attack chain

This is a regulatory development, not a threat event; there is no attack chain, CVE, actor, or malware to analyse. The mechanics that matter to defenders are procedural:

### How the reporting regime works (from the source)

1. **Scope.** The duties apply to manufacturers of products with digital elements made available in the EU, regardless of where the manufacturer is based, subject to the regulation's exemptions. Non-EU manufacturers are explicitly covered.
2. **Trigger.** The clock starts when the manufacturer *becomes aware* of an actively exploited vulnerability, or of a severe incident affecting the security of a product with digital elements.
3. **Timeline — actively exploited vulnerability:** early warning within 24 hours; detailed notification within 72 hours; final report within 14 days of making a corrective or mitigating measure available.
4. **Timeline — serious incidents:** same 24h/72h deadlines; final report due one month after the first report.
5. **Channel.** Reports are filed through ENISA's Single Reporting Platform (SRP) and are addressed to the coordinating CSIRT determined under the CRA — for an EU manufacturer, generally the CSIRT of the member state of its main establishment; separate rules determine the coordinator for non-EU manufacturers.
6. **Downstream notice.** Manufacturers must also inform affected users, where appropriate, of actively exploited vulnerabilities or severe incidents, and must inform users of available corrections or mitigations "without undue delay."
7. **Enforcement.** The reporting duties are core responsibilities; failures can attract the maximum fine tier of €15 million ($17.4 million) or 2.5 percent of annual turnover, whichever is higher.
8. **What follows.** Most remaining CRA provisions become applicable on 2027-12-11: security by design and default (no default passwords, security updates no longer optional), mandatory SBOMs, conformity assessment, and CE marking for covered products.

**Why this changes defender workflows.** The source's core operational point: because the 24-hour clock starts on manufacturer awareness, manufacturers cannot begin mapping an affected product after a vulnerability emerges — they must maintain a continuously current view of the product, related products sharing the flaw, and the software supply chain (proprietary code, open-source packages, third-party components, and increasingly AI models and services) across the product lifecycle. For consumers of those products, this means vulnerability intelligence about exploited flaws in commercial products should reach the market faster and more consistently than the current voluntary-disclosure status quo.

**Caveats.** This advisory is based on a single primary source (The Register, 2026-09-11) with a corroborating one-line summary from Dark Reading; the specific 24h/72h/14-day/one-month deadlines and the ENISA SRP filing mechanism are single-sourced in the material provided and should be verified against the official CRA text before being embedded in client compliance procedures. No specific product categories in scope, exemption criteria, or first enforcement actions are described in the sources.

## 4\. Mitigation & containment

No technical containment applies. Actions are process and contractual:

### P1 — within 24 hours

- Determine whether your organisation is a *manufacturer* of products with digital elements made available in the EU — including rebranded/OEM'd products and software sold into the EU market. The source notes many organisations still associate the CRA with consumer IoT when its reach is much broader; if you are in scope, the 24-hour early-warning clock is live as of today and you need a documented awareness-to-ENISA-SRP filing path.
- If in scope: confirm access to ENISA's Single Reporting Platform and identify your coordinating CSIRT (for EU-established entities, generally the CSIRT of the member state of main establishment; non-EU manufacturers follow separate coordinator rules).

### P2 — within 72 hours

- If in scope: stand up the internal pipeline that feeds the 72-hour detailed notification and the 14-day post-remediation final report — this requires that vulnerability triage, affected-product mapping, and corrective-measure tracking are already instrumented, not started on the clock.
- If a customer of CRA-covered products: update third-party risk procedures so that vendor "affected user" notifications (which the CRA obliges manufacturers to send without undue delay) route directly into your vulnerability management and DORA/NIS2 incident classification processes.

### P3 — within 7 days

- Add CRA Article 14 reporting capability — SBOM provision, vulnerability-handling SLAs, and user-notification commitments — to contract clauses with ICT third-party providers, ahead of the 2027-12-11 wave that makes SBOMs and security-by-design mandatory for covered products.
- Inventory your software supply chain for products with digital elements sold into the EU and flag any where you act as manufacturer or importer; brief compliance on the interaction with existing Digital Decade obligations (NIS2, DORA, Data Act, AI Act), which the source identifies as an overlapping-rules challenge.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- The Register — "EU's Cyber Resilience Act starts the 24-hour vulnerability clock" — https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821 — 2026-09-11
- Dark Reading — "EU Cyber Resilience Act to Enforce New Reporting Requirements" — https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements — (corroborating summary; 24-hour notification deadline)

## 8\. Adverse Trace position

This is a low-urgency, high-consequence regulatory shift, not a threat event: no severity score applies because no vulnerability is in scope, and no attribution or exploitation activity is claimed in the source material. The immediate risk to EMEA financial services clients is compliance-side — any client that manufactures, rebrands, or imports products with digital elements into the EU is now on a 24-hour reporting clock with maximum-tier fine exposure (€15M or 2.5% of turnover), and the source indicates this first wave has caught many organisations off guard. The defensive upside for the wider client base is a faster, mandatory feed of actively exploited vulnerability intelligence from vendors, which should be wired into existing DORA/NIS2 classification and reporting workflows rather than treated as a separate stream. The specific deadlines and filing mechanics are single-sourced in the material provided; we will verify against the official CRA text and ENISA SRP documentation, track the first CRA vulnerability reports and any enforcement signals, and issue a follow-up ahead of the 2027-12-11 applicability wave covering SBOM, security-by-design, and CE-marking requirements.

---

[Read the original source →](https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*