On Friday, a regulatory clock arms itself across the European Union. It comes from the Cyber Resilience Act, the EU regulation on the cybersecurity of digital products. CRA for short, and no, not the tax agency. Most teams do not know yet that it concerns them.

TL;DR: from 11 September 2026, the Cyber Resilience Act makes reporting mandatory. An actively exploited vulnerability in your product leaves you 24 hours for the early warning. Then 72 hours for the notification, and 14 days for the final report. The real subject is not legal. It is your ability to know fast, qualify fast and write fast. Here is the pipeline-side runbook.

This article is for software makers selling in the EU, especially small teams without in-house counsel. I am not a lawyer: dates and scope come from the primary sources listed at the bottom.

Are you in scope?

The CRA targets "manufacturers": anyone placing a product with digital elements on the EU market. Sold software, an app, firmware, a connected device.