Blog Post

The 24-Hour Clock Starts When You Notice

September 12, 2026

Table of Contents

From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to the European cybersecurity agency and a national response team. An early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days once a corrective measure is available.

The timeline is widely published and it is not the hard part. The obligation attaches to awareness, and awareness is a determination that requires two capabilities the regulation does not require anyone to have.

What Does the 24-Hour Report Contain?

Considerably less than people expect, which is the first thing worth establishing because it redirects the preparation.

The early warning is deliberately thin. It states that an actively exploited vulnerability exists in the product and identifies the member states where the product is available. No root cause, no fix, no detailed assessment. Those arrive at 72 hours and in the final report, by which point the manufacturer has had time to investigate.

The Reporting Workflow Is Not the Constraint

A submission that thin can be filed by anyone with access to the platform and the facts. Building an elaborate reporting process in advance solves a problem that was never the difficult one, and most of what a report contains concerns the specific event and cannot be prepared before it occurs.

When Does the Clock Start?

On a two-part determination rather than on an event, and each part depends on a capability.

Control assessment results against a framework with the weakest identified areas listed in a panel alongside the maturity scores
Where the weakest functions are the ones that detect and measure, an awareness-triggered obligation lands on the part of the program least able to answer it.

The manufacturer has to determine that its product is affected, which requires knowing what the product contains, including third-party and open-source components. It also has to determine that exploitation is occurring, which requires threat intelligence or field observation rather than a published advisory. The clock runs from the point both are established, not from when a vulnerability was disclosed publicly.

Which Capability Is Usually Missing?

The first, more often than the second. Threat intelligence is a purchasable feed, and knowing whether a specific product build contains a specific vulnerable component requires a dependency record per product version that many manufacturers do not maintain. Without it, an advisory arrives and nobody can say whether it applies, and knowing what a shipped product contains is what converts an advisory into a determination.

Which Products Are in Scope?

Everything already on the market, which is the least understood part of the obligation and the one most likely to catch manufacturers out.

The rest of the regulation, covering essential requirements, technical documentation and conformity marking, applies from December 2027 and only reaches products placed on the market before then if they are substantially modified. The reporting obligation is expressly carved out of that limitation. A product shipped years ago and never touched since needs a working 24-hour reporting capability from this month.

Why Does That Catch People?

Because the December 2027 date is the one everybody has planned around. A manufacturer reading that legacy products fall outside the regulation unless modified has read Article 69 correctly and stopped one paragraph early. The reporting duty runs regardless, and it is the provision most likely to produce the first enforcement, since a missed deadline is easy to establish after the fact, and a calendar built from other people's deadlines is where this belongs.

Who Makes the Determination?

Somebody has to decide that exploitation is active rather than theoretical, under time pressure, and the decision needs an owner named before it is required.

Peer incident view filtered by industry, country and revenue band showing comparable events at similar organizations
Evidence that a vulnerability is being exploited against comparable organizations is part of what an awareness determination rests on.

The trigger is real exploitation rather than a theoretical flaw, so the judgment sits between security engineering, which sees the evidence, and legal, which owns the notification. A determination deferred while those two consult is a determination made late, and the clock does not pause for internal coordination.

What Should Be Settled in Advance?

Three things, none requiring the platform to exist. Who can declare active exploitation, named rather than described. What evidence threshold that person applies, since credible reporting of exploitation in the wild is different from a proof of concept. Then who files, with platform access already arranged, since registering during a live incident consumes hours the deadline does not provide.

Does a Third-Party Component Move the Duty?

No, and that is the structural point underneath the whole obligation. A vulnerability in an integrated component is still the manufacturer's to report.

Where the component was placed on the market separately, its own manufacturer carries the same duty independently, so both report. Practically, compliance depends on upstream suppliers communicating quickly, which is a contractual arrangement rather than a security control, and what a component inventory does and does not establish applies to the determination as much as to the inventory. A manufacturer whose suppliers notify on a quarterly cycle cannot meet a 24-hour deadline regardless of its own capability.

Which Makes This a Procurement Problem

The clause required is notification of actively exploited vulnerabilities within a period short enough to leave the manufacturer time to report. Anything longer transfers the deadline risk downstream without transferring the duty, and assessing suppliers rarely reaches notification timing at this resolution.

What Is the Exposure?

Penalties reaching fifteen million euro or two and a half percent of worldwide turnover, and the more useful figure is the probability of the deadline being missed rather than the ceiling.

A manufacturer with a component inventory and a named decision owner will meet the deadline in most cases. One lacking either will miss it whenever an advisory arrives that requires investigation, which is most of them. So the exposure is a function of detection capability rather than of intent, and it can be estimated from how long the organization currently takes to establish whether an advisory applies to a shipped product.

How Do You Measure That Today?

Take the last three significant advisories affecting your component stack and time how long it took to determine whether your products were affected. Where that figure exceeds 24 hours, the reporting capability does not exist yet regardless of what process has been documented, and cyber risk quantification converts the shortfall into a figure somebody can fund.

Is There a Retroactive Obligation?

No, which is one of the few pieces of good news in the provision and worth knowing before somebody starts a backlog review.

Guidance confirms there is no duty to report vulnerabilities whose active exploitation the manufacturer had already become aware of before the obligation took effect. An organization holding knowledge of an exploited vulnerability from earlier in the year does not have to file for it. The obligation runs forward from the date the regime applies.

Where Does That Leave a Known Open Vulnerability?

Outside the reporting duty and inside every other one. An unremediated exploited vulnerability in a shipped product remains a product safety question, a contractual question with customers and, from December 2027, a conformity question. The reporting carve-out removes one obligation rather than the problem, and what an open weakness costs while it stays open prices the interval.

Does the Reporting Duty Interact With Coordinated Disclosure?

Yes, and the accommodation runs in the receiving direction rather than the filing one. A response team may delay onward dissemination of a notification on justified grounds, including where a vulnerability sits inside a coordinated disclosure process. The manufacturer still files within 24 hours, and the authority manages what happens to the information afterward, so an ongoing disclosure process is not a reason to defer the notification.

What Should Be Done This Week?

Four things, and none is a reporting workflow.

Establish whether a component record exists per shipped product version, since without it awareness cannot be determined. Name the person who can declare active exploitation and the evidence they require. Arrange platform access before it is needed. Then check supplier contracts for notification timing, because the fastest internal process cannot outrun a supplier who tells you next quarter. Other clock-based regimes have the same structure and the preparation largely overlaps.

The Clock Is a Detection Requirement

The 24-hour early warning is thin and the reporting workflow is not what makes this difficult. The obligation attaches to awareness, and awareness means determining both that your product contains the vulnerable component and that exploitation is occurring, neither of which the regulation requires you to be capable of. Legacy products are in scope even though the rest of the regulation defers to December 2027, which is the provision most likely to surprise manufacturers who planned around that date. A component supplied by somebody else is also still yours to report, making supplier notification timing a compliance dependency rather than a procurement preference. Kovrr's cyber risk quantification prices the interval between an advisory arriving and a determination being possible.

To see what a missed reporting deadline would cost against the capability you currently have, book a demo with our risk experts.

Yakir Golan

CEO

CRA Reporting FAQs

Speak to an Expert

What does the 24-hour report have to contain?

When does the reporting clock start?

Are products already on the market in scope?

Who should make the active exploitation determination?

Does a vulnerability in a third-party component move the duty?

How do you measure whether the capability exists?