The Cyber Resilience Act's 24 hour clock starts on Friday, and the only lawful way to meet it has a documented failure mode
ENISA was asked what to do if the reporting platform is down and answered honestly: wait. The regulation does not stop the clock. Meanwhile not one of twenty-five IFA launch documents mentioned any of this.
By Parminder Kumar Sharma · · 10 min read

On Friday the European Union's Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours.
Most coverage of the CRA says it applies from December 2027. That is true of almost all of it. Article 71(2), verbatim from the Official Journal:
"This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
So one article starts fifteen months early, and it is the one with the clocks in it.
What Article 14 requires
Three deadlines, all verbatim from the regulation. An early warning of an actively exploited vulnerability "without undue delay and in any event within 24 hours" of becoming aware. A fuller vulnerability notification "within 72 hours". A final report "no later than 14 days after a corrective or mitigating measure is available". Severe incidents follow the same 24 and 72 hour pattern with a final report within a month.
And one clause that gets much less attention than the numbers, from Article 14(1):
"The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16."
Not "may". Not "including via". The channel is named in the law.
The clock, the channel, and what to do if the channel is down
The question somebody asked ENISA
ENISA updated its Single Reporting Platform FAQ on 4 September, a week before the obligation starts. Two of the answers are marked as new. One of them is this:
"Manufacturers must fulfil their reporting obligations by submitting notifications through the Single Reporting Platform (SRP), in accordance with Article 14(7). If the SRP is temporarily unavailable, manufacturers should wait until it becomes available again and then submit the required notification."
The regulation contains no provision suspending the 24 hour deadline while the platform is unavailable. So a manufacturer who waits has missed a statutory notification, and a manufacturer who does not wait has nowhere else to file.
I want to be careful here, because this is not a prediction that the platform will fail and it is not an accusation that ENISA has done something wrong. Somebody asked a sensible operational question, ENISA answered it honestly, and the honest answer happens to expose that the deadline and the mechanism for meeting it are not the same system. That is worth knowing before Friday rather than during an incident.
The other new answer is narrower and also worth having:
"On the 11th of September the platform will ONLY allow the submission of mandatory reporting fulfilling Art 14 and 24(x). Voluntary reporting per art15 will not be possible."
If your plan was to file something voluntarily to establish the habit before you need it in anger, that is not available on day one.
Two more things ENISA changed on Friday
The same FAQ rewrite carries two answers that make the timing problem worse rather than better, and neither has been reported.
The platform's own counter is wrong, and ENISA says so. Verbatim:
"72hrs counter: In the current release, the 72hrs counter logic displays the due date/time for the 72hrs report, 48hrs after the submission of the 24hrs report. Due to this, in some cases, a notification might be displayed as overdue before 72 hours from when the manufacturer or open-source software stewards has become aware of the event."
Read that against Article 14, which sets the 72 hour deadline from the moment the manufacturer becomes aware, not from whenever the first report happened to be filed. A manufacturer who files the early warning at hour two has, in law, seventy more hours. The platform will show them overdue at hour fifty.
The rest of that answer is the part that should give a compliance officer pause. The logic "will be updated in future release to start counting using instead the field 'Date and Time when you became aware of the incident/actively exploited vulnerability' ... once this field will be introduced as required".
So the timestamp from which the entire Article 14 regime runs is not yet a required field on the platform built to collect it.
And there is no API. Verbatim: "no Application Programming Interface (API) will be provided at the initial release of the SRP, so notifications must be submitted through the platform interface." Manufacturers may automate internally, then a human retypes it into a web form inside twenty-four hours. API functionality "may be considered in a future phase".
Nobody at IFA mentioned any of this
The largest consumer electronics show in Europe ran in Berlin from 4 September, six days before the obligation starts, and is where a very large proportion of the connected products that fall under the CRA were launched this month.
We read the primary launch documents published between 2 and 5 September: roughly twenty-five releases across fifteen vendors, including LG, Samsung, Lenovo, Bosch, Siemens, Roborock, Dreame, Anker and eufy, Signify, Xiaomi, TCL, NVIDIA, Acer and ASUS.
Not one of them mentions the Cyber Resilience Act. None mentions UK PSTI, the US Cyber Trust Mark, a software bill of materials, or a coordinated vulnerability disclosure policy.
Exactly one product family in the entire set states a security update lifetime in years.
What the launch documents actually committed to
| Vendor | What was promised | What was not said |
|---|---|---|
| Lenovo, Yoga tablets | “Up to seven years of security updates through 2033”, with seven Android OS upgrades. The only stated support lifetime in the whole set | Their own footnote: availability and timing “may vary by device, market, carrier” and “schedules are subject to change” |
| LG, SIGNATURE refrigerator | An LLM-based conversational assistant in a fridge, and Direct Drive motors “independently certified by TÜV Rheinland for up to 30 years of operation” | The words security and software update do not appear anywhere in the release |
| eufy, NVR Security System E50 | “Face recognition, cross-cam tracking, and Smart Video Search, all on-device. No monthly plan to unlock them, ever” | Footnote 3 on the same page: cloud features send “videos or thumbnail previews” to the cloud. Thumbnails were the 2023 controversy |
| Signify, Philips Hue Play Screen Sync | A fisheye camera pointed at your television, from £89.99, on sale the day it was announced | No statement on processing location, data capture, or security updates. Signify publishes a detailed end-to-end encryption whitepaper for its Hue Secure cameras, and wrote none for this one |
| Withings, StethO Sense | AI analysis of heart and lung recordings, including from children, via two named third-party processors | Nothing on processing location, jurisdiction, data residency or retention. The “Lifetime Guarantee” in the subscription is device warranty, not patching |
| Roborock, Dreame, Bosch, Siemens | New connected appliances and robots with cameras and on-board perception | No security, privacy, encryption, certification or update-support content in any of the four releases |
The one place the regulation did appear at IFA is a thirty minute Expert Talk in Hall 26c on 7 September, the last full day, open to trade visitors only. Its title, and I am not making this up, begins "The Cyber Resilience Act. Don't Panic!"
Why the silence is the story rather than the deadline
It would be easy to write this as vendors ignoring the law, and I do not think that is quite right.
Article 14 does not require anybody to announce anything at a trade show. A vendor can be entirely ready to file a 24 hour notification on Friday and have no reason to say so in a press release about a fridge. Marketing departments do not write about incident reporting because nobody buys a washing machine because of it.
What the silence tells you is narrower and more useful. There is no commercial pressure at all in this direction. Not one vendor at the largest consumer electronics show in Europe judged that "we will tell you within 24 hours when something is being exploited" was worth a sentence, in the week the obligation started. Support lifetimes are the same: one vendor out of fifteen thought seven years was worth advertising, and that vendor was selling tablets rather than the appliances that will still be in a kitchen in 2040.
Regulation is doing all the work here because nothing else is.
What to do about it
Take this with you
Before Friday if you are a manufacturer, before your next purchase if you are not
- If you place products with digital elements on the EU market, register for the Single Reporting Platform now rather than during your first incident. Registration under pressure at hour three of a 24 hour clock is the worst possible time to discover an account problem.
- Write the platform-unavailable case into your incident runbook explicitly, including who decides and what is recorded. ENISA’s guidance is to wait, the regulation does not stop the clock, and you want that decision made calmly in advance with a timestamped record of the attempt.
- Do not plan to rehearse with a voluntary filing on day one. ENISA state that voluntary reporting under Article 15 will not be possible when the platform opens.
- Check that your definition of “becomes aware” is written down. The 24 hour clock starts from awareness, and in most organisations awareness happens in a support queue or a security mailbox long before it reaches anyone who knows what Article 14 is.
- If you are buying connected hardware, ask for the security update end date rather than the marketing. For anything sold in the UK that date must already be published under PSTI, so asking costs you nothing and tells you a great deal about the supplier.
- Treat an on-device claim as a question rather than an answer. The eufy and Withings examples in this piece both describe local processing in the headline and something else in the footnotes.
The position
The Cyber Resilience Act is a serious piece of law and Article 14 is the sharp end of it: a 24 hour clock, a named channel, and real penalties behind it eventually. It starts on Friday.
The two things worth carrying out of this week are that the only lawful route to meeting the deadline has a documented failure mode with no legal answer, and that an entire industry launched a season of connected products six days beforehand without one of them mentioning it.
Neither of those is a scandal. Both of them are the sort of thing you would rather know on the Sunday than on the Friday.
Sources
- PrimaryRegulation (EU) 2024/2847, the Cyber Resilience Act. Article 71(2) on application dates and Article 14 on manufacturers' reporting obligations, both read in the Official Journal textOfficial Journal of the European Unionaccessed 2026-09-06
- PrimarySingle Reporting Platform FAQ, updated 4 September 2026, including the new answers on what to do if the platform is temporarily unavailable and on voluntary reporting not being possible at launchENISAaccessed 2026-09-06
- PrimaryLG Electronics Highlights Seven Home Appliances at IFA 2026, 4 September 2026: the LLM-based refrigerator and the TÜV Rheinland certification of motors for up to 30 years of operation, in a release containing neither the word security nor software updateLG Electronicsaccessed 2026-09-06


