40 Days Out: The EU Cyber Resilience Act's 24-hour reporting clock starts September 11th, 2026

On 27 July 2026, the European Commission published its guidance on the Cyber Resilience
Act (Regulation (EU) 2024/2847). Most CRA obligations don't come into force until December 2027, but the reporting duties start much sooner, and they cover products with digital elements already on the market today, not just future launches.
September 11th 2026
From September 11th 2026, manufacturers must report to ENISA (European Union Agency for Cybersecurity) and the coordinating CSIRT (Computer Security Incident Response Team) via ENISA's Single Reporting Platform:
Early warning within 24 hours of becoming aware of an actively exploited vulnerability -
or a severe incident
Full notification within 72 hours
Final report within 14 days (vulnerabilities) or one month (incidents).
Fines for non-compliance run up to €15 million or 2.5% of worldwide turnover, whichever
is higher.
Two different questions, depending on who you are:
Fund and asset management clients: the obligation sits with your suppliers, not you. But software and hardware vendors feeding into your ICT stack, trading systems, portfolio tools, connected infrastructure, are now on a 24-hour disclosure clock. Whether that flows through to you contractually is exactly the gap DORA's ICT third-party risk management expects you to have closed.
Payment institutions, e-money institutions and fintechs: look harder at your own role. CRA scope turns on product vs. service, not sector. If you develop or market connected devices, POS terminals, card readers, hardware tokens, or software distributed as an installed product (mobile wallet apps, SDKs, card-present modules) rather than consumed purely as SaaS, you may be a manufacturer under the CRA directly, with your own 24-hour clock from 11 September. Pure cloud-hosted payment processing tends to sit with DORA and NIS2 instead, but "mostly SaaS with a companion terminal or SDK" doesn't automatically get a pass.
How MAQIT can help
MAQIT helps Luxembourg financial services clients define which side they are on, and keep DORA, NIS2 and CRA obligations aligned in one register rather than three.
Contact your MAQIT team to discuss how these developments affect your specific regulatory perimeter: info@maqit.lu



Comments