The bottom line: From September 11, 2026 onward, any manufacturer selling a product with digital elements into the EU must notify ENISA within 24 hours of any actively exploited vulnerabilities. This isn't 2027, it's not just for tech giants, and SMBs have no exemption. Here's what's in scope, the actual timelines, and what to set up in the weeks you have left.
The Cyber Resilience Act (EU Regulation 2024/2847) is the European regulation requiring all products with digital elements—hardware with embedded software, commercial software, connected devices—to meet cybersecurity requirements throughout their entire lifecycle, carry a CE mark for that reason, and notify authorities of vulnerabilities and serious incidents.

What happens exactly on September 11

The CRA entered into force on December 10, 2024 with a long transition period. Most people fixated on one date: December 11, 2027, when the cybersecurity CE mark, technical file, and conformity assessment become due. That's where the mistake lies.

There's an intermediate deadline that's already here: Article 14 takes effect from September 11, 2026. This article mandates manufacturers to report two things: actively exploited vulnerabilities in their products and serious incidents affecting product security.

Here's what most people miss: this notification obligation doesn't wait until 2027 and makes no distinction by product age. It applies to all products with digital elements already on the EU market, including ones you sold five years ago. The full technical requirements do have the 2027 buffer (and products already in circulation only fall under new rules if they undergo substantial modification), but notification starts now.

ENISA's single notification platform must be operational by that same date, with a testing period beforehand. So there's no excuse of "nowhere to report it."

Does this apply to you?

The question I always hear from a factory floor or workshop: "I make machinery, not software—is this just for tech companies?" No. "Product with digital elements" means any hardware or software product that connects, directly or indirectly, to a device or network. That covers:

Watch for one detail that catches a lot of people: if you buy equipment outside the EU and put it on the market under your name or brand, you become the manufacturer for regulatory purposes—not the supplier who assembled it. You.

On company size: micro and small enterprises have no general exemption. The only concession is that the first timeline—the 24-hour early warning—has a lighter burden only for enforcement purposes. Everything else applies equally.

The notification timelines, plain and simple

When you discover a vulnerability that someone is actively exploiting in your product, the clock starts the moment you become aware of it. Not when you fully confirm it, not when the Monday committee meets.

Timeline What you send To whom
24 hours Early warning: active exploitation detected National CSIRT → ENISA
72 hours Full notification: affected product, nature of the flaw, mitigations, and user actions National CSIRT → ENISA
14 days after you have a patch Final report: description, severity, impact, remedial action National CSIRT → ENISA

For serious incidents the schedule is the same at 24 and 72 hours, with the final report due one month after the 72-hour notification. You report once, through the single platform, and the receiving CSIRT distributes it to other member states where you sell.

Think for a moment what 24 hours means for a 30-person company with no dedicated security team. If the alert arrives Friday afternoon through a customer, and your only systems person is on vacation, you've already breached the rule by Sunday morning without realizing it. That's the real problem, not the regulation's wording.

What to set up before September 11

You don't need a SOC or a Chief Information Security Officer. You need four things that take weeks to set up and that almost no industrial SMB has in writing.

A channel for reports to reach you. An address like security@yourdomain.com published on your website, monitored by multiple people, checked daily. Sounds basic. Most Spanish manufacturers don't have it, and vulnerabilities come through there: a customer, a researcher, an integrator.

An inventory of what you've sold and what's inside it. Which firmware versions are deployed, in which customers, with which third-party components and libraries. This is the famous SBOM (software bill of materials). If you don't know what libraries your equipment carries, you can't tell if the flaw in tomorrow's news affects you.

A triage procedure with names and responsibilities. Who decides if a report is active exploitation. Who signs the notification. Who alerts the customer. Include a backup person, because August happens. Half a page of paper solves this.

Ability to release a patch. If updating firmware on deployed equipment means sending a technician in a van to every customer, your 14-day timeline is worthless paper. That's where many companies discover the problem isn't legal—it's a product design issue.

September 11, 2026 - Article 14 notifications begin.
December 11, 2027 - CE mark, technical file, and full requirements.
24 h / 72 h / 14 days - the clock for each notification.

CRA, NIS2, AI Act: they're different and they overlap

I understand regulatory fatigue. In two years you've had the AI Act, NIS2 transposition, the Data Act for connected machinery, and now this. It's worth separating each one into a single sentence.

NIS2 is about how you operate as an organization: risk management, incident reporting for the company, supply chain security. The CRA is about what you sell: the product and its lifecycle. The AI Act is about AI systems you use or embed. You can be subject to all three at once, and a mid-sized industrial manufacturer typically is.

The good news is the foundational work gets reused: asset inventory, alert channel, and incident procedures work for both NIS2 and CRA with minor adjustments. If you've already done the groundwork on industrial cybersecurity, you're halfway there.

What almost nobody is seeing: this is a selling point

I'm going to say something unpopular. Meeting the CRA early isn't just about avoiding a fine—it's a commercial argument your competitors won't have in 2027.

Procurement departments at major manufacturers are already adding product cybersecurity questions to their vendor qualification questionnaires. When December 2027 arrives and the cybersecurity CE mark becomes a requirement to sell, the companies that show up with documentation ready will access contracts they're locked out of today. Those running to meet the deadline will pay consulting fees at rush rates and lose orders because their technical file isn't ready.

It's exactly what happened with GDPR in 2018 and with Verifactu now: the deadline was known years in advance and half the market arrived late.

Frequently asked questions

Does the CRA apply if I only sell in Spain?

Yes. It's a European regulation with direct application and Spain is part of the internal market. You don't need to export to be in scope. What changes by geography is how many CSIRTs receive your notification, but you still report once through the single platform.

I make machinery with no internet connection—am I exempt?

It depends on indirect connectivity. Equipment with an Ethernet port for laptop configuration, or USB for firmware updates, has digital elements. The regulation's strict reading covers direct or indirect connection to a device or network. If you're unsure about a specific product, document your analysis in writing—that already serves as diligence.

What if I don't notify an actively exploited vulnerability?

The CRA's enforcement regime is serious, with fines tied to global turnover, and national market surveillance authorities oversee enforcement. But before the fine comes something more immediate: the customer who experiences the incident and discovers you didn't warn them. That gets paid in lost contracts.

Do I have to create the SBOM now?

The software bill of materials becomes mandatory with the full technical requirements in December 2027, not in September 2026. That said, without an inventory of components it's impossible to respond in 24 hours to a vulnerability in a third-party library. That's the piece I'd build first even though the formal deadline is later.

Does it help to start now if the big date is 2027?

It helps because the two fronts are separate. Notification requires organization and people—that takes weeks to set up. The technical file and conformity assessment require changes to product design, and that's months or over a year if you need to rebuild the update mechanism. Starting in 2027 means doing both at once and badly.

Which CSIRT in Spain is mine?

The CSIRT of the member state where you have your main establishment. For a Spanish private-sector company, the usual reference is INCIBE-CERT. Notification goes through ENISA's single platform, which must be operational by September 11, 2026.

Not sure where to start?

We'll set up your product inventory, alert channel, and notification procedure in weeks, not months. Tell us what you make and we'll let you know what applies to you.

Talk to us →