Delivery
What the Cyber Resilience Act asks of engineering teams
From September 11 the CRA's reporting clocks start at 24 hours. The obligation is written for manufacturers, but the capability it requires is built by engineers.
Code, Noted2 min readDelivery
On 11 September 2026 the reporting obligations of the EU Cyber Resilience Act begin to apply. A manufacturer of a product with digital elements must report any actively exploited vulnerability in that product, and any severe incident affecting its security, through the CRA Single Reporting Platform: an early warning within 24 hours of becoming aware, a fuller notification within 72, and a final report within 14 days of a corrective measure being available, or within a month for a severe incident.

Those are legal deadlines. What they describe is an engineering capability, and the distinction is the whole essay.
The pattern is not new. California's SB 1386 took effect on 1 July 2003 and created the first general duty to notify people that their data had been taken. Compliance departments wrote the policies. Engineering teams discovered, over the following decade, that a notification duty is really a detection duty wearing formal clothes: an organization cannot notify within any deadline about an event it has no instrument to observe, and cannot scope the notice without knowing which systems held which records.
The CRA repeats the structure with a shorter clock and a wider object. The reportable fact is not a breach of the manufacturer's network. It is exploitation of the product, in the field, on customer premises, in versions shipped years ago. Three questions therefore decide whether a 24-hour clock is survivable, and none of them is a legal question.
The first is what the organization ships. Not what it develops: what is in the hands of customers, at which versions, containing which third party components. Firms that treated software inventory as a build artifact rather than an owned system will find this the expensive part, and it will look familiar to anyone who has met the deprecation nobody owns.
The second is how exploitation becomes known. Awareness starts the clock, and awareness arrives through support tickets, researcher mail, telemetry, and a coordinator's phone call. Whichever route it takes, someone must be reachable on it, at the weekend, with authority.
The third is who can decide. Twenty-four hours does not permit a review board. It permits an on-call engineer, a named decision-maker, and a filing.
The strongest objection to all of this is that it is compliance theatre, and that a firm which is good at security will pass anyway. Half true. A firm good at security will have the detection. What the deadline tests is something else: whether detection connects to a decision within a day, without a meeting. Most large organizations have never measured that latency, because nothing before now billed them for it.