Sunday, September 27, 2026

CRA Reporting Gives Vendors 24 Hours

Here is the rule. Since 11 September 2026, any company selling software or connected hardware in the European Union that learns one of its products is being actively exploited has 24 hours to send an early warning to the authorities, and 72 hours to follow it with a full notification. That is CRA reporting, set out in the European Commission's guidance on the Cyber Resilience Act, and it is already live. A vendor in Austin that sells the same router in Berlin and Boston now owes Berlin a warning. Boston gets nothing.

Laptop security alert beside a 24-hour stopwatch, illustrating CRA reporting deadlines for vendors

That gap should close by law, and the usual objection is mostly answered by how the rule is written.

Key Takeaways

A 24-hour exploited-flaw warning should be a legal duty for every software vendor, not a perk reserved for EU buyers.

  • The EU gives vendors 24 hours to warn and 72 to notify once they know of an exploit.
  • Warnings go to a national CSIRT through ENISA's platform, not to the public.
  • US law puts reporting on the breached operator, not the vendor whose product failed.
  • Outside the EU, write a 24-hour exploited-flaw notice into every contract you renew.

Why CRA reporting should be the global floor

A vendor knows first when its product is being exploited, so the duty to warn belongs with the vendor, and a rule that protects only EU customers leaves every other buyer of the same product exposed.

The manufacturer sees the crash reports, the researcher emails and the telemetry spike days before customers notice anything. The Act makes that knowledge travel: manufacturers must also inform impacted users, according to Hogan Lovells' 11 September 2026 briefing. An EU hospital running a VPN appliance gets told. A clinic in Ohio running the identical box does not.

The American answer is thinner. CIRCIA puts the reporting duty on critical-infrastructure operators, the victims, not on the vendor whose code let the attacker in. CISA's Secure by Design pledge is voluntary, so a US buyer holds no enforceable promise unless it sits in the contract. Treating a pledge as a rule is outdated advice.

Anyone who tracked the DPDP consent manager deadline in India or post-quantum migration deadlines under NIST IR 8547 knows the pattern: a regulator sets a clock, and vendors discover how little of their process was built for one.

Run the clock on a real calendar. Confirm exploitation at 5pm on a Friday and the early warning is due by 5pm Saturday, the full notification by 5pm Monday. That is our own arithmetic, and it means someone with authority to file must be reachable all weekend. The four numbers below, from the Commission and Article 64 of the Act, decide whether vendors take that seriously.

Early Warning Window

24 hours

One unstaffed weekend breaches it

Flat Fine Ceiling

EUR 15 million

Enough to sink a small vendor

Filings Per Exploited Flaw

3

A paper trail buyers can cite

Turnover-Based Fine

2.5%

Whichever is higher applies

The revenue-linked ceiling is what changes behaviour at large vendors. A flat cap is a budget line; a share of global revenue grows with the company, so the suppliers in the most networks carry the steepest exposure.

"

In Europe, sitting on an exploited flaw over one weekend risks a fine priced against a vendor's entire global turnover. In America, the same silence costs nothing.

Does the Cyber Resilience Act apply to US companies?

Yes, the Cyber Resilience Act applies to any manufacturer placing products on the EU market, wherever it is based, so a US vendor selling into Europe already owes EU buyers warnings its home customers never receive.

US figures below come from Ballard Spahr's Byte Back analysis of CIRCIA (February 2026) and CISA's pledge page.

Dimension EU vs US What it means for you
💰 Who reports EU The product vendor
US The breached operator
⚠️ A supplier's flaw becomes your filing
⚖️ Legal force EU Binding since Sept 2026
US Pledge, signed by choice
❌ Only your contract makes it enforceable
⏱ First alert EU 24 hours, to a CSIRT
US 72 hours, operators only
✅ EU buyers hear two days sooner
⏱ Final report EU 14 days after a fix
US No vendor duty
✅ A patch date you can hold them to
🌍 Users told EU Impacted users, by law
US No such right
⚠️ Same product, warned only in Europe
🔒 Who sees it EU A CSIRT, not the public
US Nobody, by rule
✅ The warning gives attackers nothing
🛠 Old products EU Past end of support
US No duty at all
❌ Legacy kit goes quiet outside the EU
🏁 Best suited for EU Any buyer inside the EU
US Buyers who contract for 24h
🏁 Elsewhere, the clause is your only clock

The vendor builds the triage desk for Europe anyway, so American customers pay for output they never see. Vendors treating 2027 as the start date have the calendar wrong.

Oct 2025. May 2026. 11 Sep 2026. 11 Dec 2027. US rule first due. US rule new target. EU vendor clock live. Open source joins. 15 months.

If you sell to EU customers, your reporting clock is already running, while the US incident rule has already missed its first deadline. Dates from the European Commission and Ballard Spahr's Byte Back; the final gap is our own count.

Won't a 24-hour rule crush small vendors?

No, because the 24-hour step is an early warning to a national security team, not a public disclosure or a finished report, and the fuller detail follows on a structured, longer schedule.

At its strongest, the objection says a ten-person firm has no security team and a panicked filing could leak. Filings go through ENISA's Single Reporting Platform to the CSIRT of the manufacturer's main establishment, so the warning never touches the open internet. Attackers learn nothing from a message they cannot read.

The burden is real but scoped: a written threshold for "actively exploited" and a named Sunday filer. Plus a rehearsal. Two, honestly, because the first always finds the gap nobody wrote down. AI tooling vendors have more ground to cover, with flaws surfacing in MCP servers flagged in the NSA's advisory and in AI agent credentials nobody has inventoried.

The genuine grey area is the word "aware". In our view the clock should start at credible evidence of exploitation, not legal sign-off, but enforcement will settle it. Watch for these:

  • Community-maintained components sit outside the clock until open-source stewards join.
  • Severe incidents run a different final-report schedule, so check which your contract names.
  • US buyers hold no right to the EU notice, even for identical firmware.

Check these before your next renewal

Your contract sets an exploited-flaw notice of one day or less.

Your vendor names who files on a Sunday.

The product is also sold in Europe, so the warning exists.

Unsupported products still carry a written warning promise.

Do not wait for Washington. This week, pull your three largest software contracts and add one clause: the vendor notifies you within 24 hours of confirming active exploitation, on the same terms it already owes EU regulators. A vendor that refuses a promise it already keeps in Europe has told you what you need to know.

No comments

Post a Comment