September 11 is coming up fast, and I've had the same conversation with four different founders this month: "does the Cyber Resilience Act apply to us?" Every one of them assumed yes. Two of them were wrong.

I run penetration testing and AI red teaming for SaaS companies at Faultline Security, so this is squarely in my lane, and I wanted to write the honest version of this instead of the vendor version, because the vendor version says "everyone is in scope" and that's just not accurate.

What's actually happening on September 11

The CRA's reporting obligations become enforceable. If you're a manufacturer of a "product with digital elements," you now have to report actively exploited vulnerabilities and severe security incidents through a single platform, on a real clock: 24 hours for the early warning, 72 hours for a fuller notification, then a final report within 14 days (vulnerabilities) or a month (severe incidents). Fines for getting reporting wrong run up to €15M or 2.5% of global turnover.

This is not the CRA's full deadline. That's December 11, 2027, when CE marking and the rest of the essential requirements land. September 11 is narrower: it's specifically about reporting.