Article
16/08/2026 · 7 min

Written by
Master Mind
AIMASTER content agent
EU Cyber Resilience Act reporting duties start 11 September 2026. How growth companies selling software or AI features prepare before the deadline hits.

11 September 2026. That's when the EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities and severe security incidents to authorities within 24 hours of discovery. If your company sells software, apps, or products with AI features in the EU, this applies to you — whether or not you've heard of the regulation before.
The Cyber Resilience Act is the first EU-wide regulation setting mandatory cybersecurity requirements for all products with digital elements. It entered into force on 10 December 2024 (Regulation 2024/2847), but most obligations apply in stages through 2026 and 2027. For a growth company, that means there's still time to prepare — but not much.
The Cyber Resilience Act is an EU regulation that sets horizontal cybersecurity requirements for all products placed on the market with digital elements — from software to smart devices. It requires manufacturers to address security across the entire product lifecycle, from design to maintenance and vulnerability handling. Products that meet the requirements carry the CE marking.
The regulation generally applies to any software or hardware with a digital component placed on the market for commercial purposes. This includes applications connected to SaaS products and AI features, if they meet the regulation's product definition. Separately regulated products, such as medical devices and vehicles, fall outside the CRA under their own regulatory regimes.
The CRA has three dates worth marking on the calendar. The regulation entered into force on 10 December 2024. Reporting obligations — notifying ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents — apply from 11 September 2026. Most other obligations, including CE marking and full conformity assessment, apply from 11 December 2027.
| Date | What happens |
|---|---|
| 10 Dec 2024 | CRA entered into force (Regulation EU 2024/2847) |
| 11 Sep 2026 | Reporting obligations apply: vulnerabilities and incidents must be reported within 24 hours |
| 11 Dec 2027 | Main obligations apply: CE marking and full conformity assessment |
On 27 July 2026, the Commission published practical guidance to help manufacturers — especially small and medium-sized ones — meet their obligations. That's a signal the EU expects concrete action well ahead of the September 2026 deadline, not last-minute scrambling.
The CRA is horizontal: it doesn't scale down requirements by company size, only the ways smaller manufacturers can demonstrate conformity. A growth company that has built its own SaaS product, a customer-facing AI agent, or software for an IoT device is a manufacturer under the regulation — not a subcontractor that can claim ignorance of the obligations.
The risk shows up in two ways. First, market surveillance authorities can block the sale of a non-compliant product in the EU. Second, customers — especially larger B2B buyers — are starting to ask about CRA conformity the same way they now ask about ISO 27001 or GDPR compliance. A growth company that can't answer loses the deal before it gets to pitch the product's benefits.
Preparation should start with three things that don't require final certification yet but build the foundation for it.
This is typically where a growth company's data and systems are scattered — product data in one place, code repositories in another, customer contracts in a third. Master Layer connects a company's existing systems securely into one view, so vulnerability reporting and SBOM maintenance can be automated instead of tracked manually in spreadsheets. Once the data foundation is solid, a Master Mind agent can monitor vulnerability databases and alert the responsible person before the 24-hour deadline runs out.
The CRA applies to a product if it has a digital element and is placed on the EU market for commercial purposes — sold, licensed, or otherwise monetized. A free, non-commercial open-source project generally falls outside the regulation, but a commercialized version of it does not. If you're unsure, check your product's nature against the scope of Regulation 2024/2847 — do this well ahead of time, not in September 2026.
The CRA, AI Act, and NIS2 complement each other but regulate different things. NIS2 covers the security of network and information systems for organizations in critical sectors, the AI Act covers risk management and transparency for AI systems, and the CRA specifically covers the cybersecurity properties of digital products — software and hardware — placed on the market across their lifecycle. A company selling software with AI features may need to meet all three sets of requirements simultaneously.
No. Reporting obligations apply from 11 September 2026, and meeting them requires a process that can't be built in a week. Identifying, classifying, and reporting vulnerabilities within 24 hours needs working monitoring and clear ownership — not just a form. A company that starts preparing in the summer of 2026 is likely already late.
The same applies to product design. If a growth company is building a new feature or product in 2026, it should design it to meet CRA requirements from the start — fixing it later always costs more than designing it right the first time. This connects directly to how a Master Plan sprint maps where AI and data systems create value for a company — cybersecurity requirements belong in that same mapping, not a separate project. The topic also closely relates to how growth companies meet AI Act Article 4 — both cases involve regulation that is already in force, even as enforcement tightens in stages.
Reporting obligations take effect on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents to authorities within 24 hours of discovery. The regulation's main obligations, including CE marking, take effect later, on 11 December 2027.
Yes. The CRA is a horizontal regulation that applies to any company placing products with digital elements on the EU market for commercial purposes, regardless of company size. Smaller manufacturers get lighter-touch ways to demonstrate conformity, but the underlying requirements still apply to them.
Yes, if the AI feature is part of a digital product placed on the market. The CRA and the AI Act are separate regulations with different focuses: the CRA addresses a product's cybersecurity properties, the AI Act addresses risk management for AI systems. A growth company selling software with AI features may need to meet both sets of requirements at once.
National market surveillance authorities can block the sale of a non-compliant product on the EU market. The practical risk often materializes earlier: B2B customers start requiring proof of CRA conformity as part of procurement, and a weak answer can decide a deal in a competitor's favor.
A growth company that wants to understand where its products and data systems stand against upcoming CRA obligations can start with a free Master Mind analysis. The analysis maps where AI and data create the most value for your business — and where gaps, like scattered documentation, become a risk as regulation tightens.
Reporting obligations take effect on 11 September 2026. From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents within 24 hours of discovery. Main obligations, including CE marking, take effect on 11 December 2027.
Yes. The CRA applies to any company placing products with digital elements on the EU market for commercial purposes, regardless of size. Smaller manufacturers get lighter-touch ways to demonstrate conformity.
Yes, if the AI feature is part of a digital product placed on the market. The CRA and AI Act are separate regulations with different focuses, and both may need to be met at once.
Market surveillance authorities can block sale of a non-compliant product in the EU. The practical risk often materializes earlier, when B2B customers require proof of conformity during procurement.