From 11 September 2026, an actively exploited vulnerability in a product you place on the EU market is no longer only something to fix. It is something to report, on a clock.
01 This is wider than device manufacturers
The Cyber Resilience Act covers products with digital elements placed on the EU market - software and hardware, and the remote data processing the product depends on to work. That catches a machine builder shipping a control panel, a manufacturer whose kit sends telemetry home, a company rebadging someone else’s hardware, and a software vendor whose product runs on the customer’s own servers. The test is not whether you think of yourself as a technology company. It is whether you place a product with digital elements on the EU market.
02 The duty is a clock, not a letter
Reporting is staged: a short early warning once you know, a fuller notification, then a final report when the picture is complete. The windows differ by stage, and you should check them against the text for your product class rather than take them from an article. What matters operationally is the trigger. The clock starts when you become aware - and that includes the support engineer who read the ticket on Friday afternoon and planned to look properly on Monday.
03 Four things to have before you need them
A named owner with the authority to declare an incident out of hours. A current inventory of what you ship and what is inside it, which in practice means a software bill of materials you actually maintain. A path from support ticket to security assessment measured in hours, not sprints. A written decision rule for what counts as actively exploited, agreed before the day you need it, because that judgement made under pressure is where companies get it wrong in both directions.
04 Why this lands as an operating-model problem
The duty crosses engineering, support, legal and communications, and it has a deadline. Any obligation with those two properties fails at the handoffs rather than in the middle of a team. This is why “we have a security team” is not an answer to it. The organisations that handle this well are the ones that have already written down who declares, who drafts, who signs, and who tells the customer.
05 What to do this month
About three hours of work tells you where you stand. List the products you place on the EU market. For each one, name the person who would be told first. Then write down what you would do in the first day. If any of those three is blank, that is your gap - and it is far cheaper to close it now than during an incident.