Regulation + Product

The Cyber Resilience Act starts reporting on 11 September

Huceptron InsightsBy the Huceptron senior partners·5 min read

From 11 September 2026, an actively exploited vulnerability in a product you place on the EU market is no longer only something to fix. It is something to report, on a clock.

01 This is wider than device manufacturers

The Cyber Resilience Act covers products with digital elements placed on the EU market - software and hardware, and the remote data processing the product depends on to work. That catches a machine builder shipping a control panel, a manufacturer whose kit sends telemetry home, a company rebadging someone else’s hardware, and a software vendor whose product runs on the customer’s own servers. The test is not whether you think of yourself as a technology company. It is whether you place a product with digital elements on the EU market.

02 The duty is a clock, not a letter

Reporting is staged: a short early warning once you know, a fuller notification, then a final report when the picture is complete. The windows differ by stage, and you should check them against the text for your product class rather than take them from an article. What matters operationally is the trigger. The clock starts when you become aware - and that includes the support engineer who read the ticket on Friday afternoon and planned to look properly on Monday.

03 Four things to have before you need them

A named owner with the authority to declare an incident out of hours. A current inventory of what you ship and what is inside it, which in practice means a software bill of materials you actually maintain. A path from support ticket to security assessment measured in hours, not sprints. A written decision rule for what counts as actively exploited, agreed before the day you need it, because that judgement made under pressure is where companies get it wrong in both directions.

04 Why this lands as an operating-model problem

The duty crosses engineering, support, legal and communications, and it has a deadline. Any obligation with those two properties fails at the handoffs rather than in the middle of a team. This is why “we have a security team” is not an answer to it. The organisations that handle this well are the ones that have already written down who declares, who drafts, who signs, and who tells the customer.

05 What to do this month

About three hours of work tells you where you stand. List the products you place on the EU market. For each one, name the person who would be told first. Then write down what you would do in the first day. If any of those three is blank, that is your gap - and it is far cheaper to close it now than during an incident.

This describes the shape of the obligation, not legal advice on your products. Dates and thresholds should be checked against the current text before you rely on them. Related: what moved in the AI Act and what did not.

Cyber Resilience ActVulnerability reportingProduct complianceOperating model
One week. Then you know.
The AI audit week - what applies to you, where the gaps are, and what to do first
See what the week covers →