Finite State Customers Are Ready for CRA's September 11 Reporting Deadline
When the EU Cyber Resilience Act's first reporting obligations take effect on September 11, 2026, manufacturers working with Finite State can establish within minutes whether an actively exploited vulnerability is present and reachable in a product they shipped.
Finite State, a leader in product security and software supply-chain risk management, today announced that connected device manufacturers using its platform are ready for the EU Cyber Resilience Act's September 11 reporting obligations. These manufacturers will enter the deadline able to answer the notification's hardest question: whether an actively exploited vulnerability is present and reachable in the build they shipped.
The rule reaches ordinary connected equipment—a home router or a controller on a factory line—and it covers products still under support that shipped long before anyone was planning for the regulation.
From September 11, 2026, onward, a manufacturer that determines that a vulnerability in one of its products is being actively exploited in the wild has 24 hours to notify ENISA and a designated national CSIRT simultaneously through the EU's Single Reporting Platform, 72 hours to file a detailed follow-up, and 14 days after a mitigation is available to file a final report.













