P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The Cyber Resilience Act's 24 hour clock starts on Friday, and the only lawful way to meet it has a documented failure mode

ENISA was asked what to do if the reporting platform is down and answered honestly: wait. The regulation does not stop the clock. Meanwhile not one of twenty-five IFA launch documents mentioned any of this.

By Parminder Kumar Sharma · · 10 min read

A plain unbranded speaker's lectern standing alone on a low stage under a single overhead spotlight, with rows of empty chairs receding into darkness behind it. Nothing rests on the lectern and it carries no signage.

On Friday the European Union's Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours.

Most coverage of the CRA says it applies from December 2027. That is true of almost all of it. Article 71(2), verbatim from the Official Journal:

"This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."

So one article starts fifteen months early, and it is the one with the clocks in it.

What Article 14 requires

Three deadlines, all verbatim from the regulation. An early warning of an actively exploited vulnerability "without undue delay and in any event within 24 hours" of becoming aware. A fuller vulnerability notification "within 72 hours". A final report "no later than 14 days after a corrective or mitigating measure is available". Severe incidents follow the same 24 and 72 hour pattern with a final report within a month.

And one clause that gets much less attention than the numbers, from Article 14(1):

"The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16."

Not "may". Not "including via". The channel is named in the law.

The clock, the channel, and what to do if the channel is down

THE CLOCK, THE CHANNEL, AND WHAT TO DO IF THE CHANNEL IS DOWNArticle 14 of the Cyber Resilience Act, which starts on 11 September 2026.THE STAGES, IN SEQUENCE. NOT DRAWN TO A TIME SCALE.You become awareof an actively exploited flawthe clock starts24 hoursearly warning notificationwithout undue delay72 hoursvulnerability notificationnature, product, mitigations14 daysfinal reportafter a fix is availableThe Single Reporting Platform, and only itArticle 14(1): shall notify “via the single reporting platform established pursuant to Article 16”And if the platform is not there?ENISA, 4 September 2026: “manufacturers should wait until it becomes available again and then submit the required notification.”The clock has no pause. The channel does.Nothing in the regulation suspends the 24 hour deadline while the only lawful route to meeting it is unavailable.
This is not a prediction that the platform will fail. It is that the question was asked, ENISA answered it, and the answer does not resolve the deadline. A manufacturer who waits has missed a statutory 24 hour notification, and a manufacturer who does not wait has nowhere else to file.
Deadlines and the notification clause quoted from Regulation (EU) 2024/2847 as published in the Official Journal. ENISA guidance from its Single Reporting Platform FAQ, which added this answer on 4 September 2026. Both read on 6 September 2026.

The question somebody asked ENISA

ENISA updated its Single Reporting Platform FAQ on 4 September, a week before the obligation starts. Two of the answers are marked as new. One of them is this:

"Manufacturers must fulfil their reporting obligations by submitting notifications through the Single Reporting Platform (SRP), in accordance with Article 14(7). If the SRP is temporarily unavailable, manufacturers should wait until it becomes available again and then submit the required notification."

The regulation contains no provision suspending the 24 hour deadline while the platform is unavailable. So a manufacturer who waits has missed a statutory notification, and a manufacturer who does not wait has nowhere else to file.

I want to be careful here, because this is not a prediction that the platform will fail and it is not an accusation that ENISA has done something wrong. Somebody asked a sensible operational question, ENISA answered it honestly, and the honest answer happens to expose that the deadline and the mechanism for meeting it are not the same system. That is worth knowing before Friday rather than during an incident.

The other new answer is narrower and also worth having:

"On the 11th of September the platform will ONLY allow the submission of mandatory reporting fulfilling Art 14 and 24(x). Voluntary reporting per art15 will not be possible."

If your plan was to file something voluntarily to establish the habit before you need it in anger, that is not available on day one.

Two more things ENISA changed on Friday

The same FAQ rewrite carries two answers that make the timing problem worse rather than better, and neither has been reported.

The platform's own counter is wrong, and ENISA says so. Verbatim:

"72hrs counter: In the current release, the 72hrs counter logic displays the due date/time for the 72hrs report, 48hrs after the submission of the 24hrs report. Due to this, in some cases, a notification might be displayed as overdue before 72 hours from when the manufacturer or open-source software stewards has become aware of the event."

Read that against Article 14, which sets the 72 hour deadline from the moment the manufacturer becomes aware, not from whenever the first report happened to be filed. A manufacturer who files the early warning at hour two has, in law, seventy more hours. The platform will show them overdue at hour fifty.

The rest of that answer is the part that should give a compliance officer pause. The logic "will be updated in future release to start counting using instead the field 'Date and Time when you became aware of the incident/actively exploited vulnerability' ... once this field will be introduced as required".

So the timestamp from which the entire Article 14 regime runs is not yet a required field on the platform built to collect it.

And there is no API. Verbatim: "no Application Programming Interface (API) will be provided at the initial release of the SRP, so notifications must be submitted through the platform interface." Manufacturers may automate internally, then a human retypes it into a web form inside twenty-four hours. API functionality "may be considered in a future phase".

Nobody at IFA mentioned any of this

The largest consumer electronics show in Europe ran in Berlin from 4 September, six days before the obligation starts, and is where a very large proportion of the connected products that fall under the CRA were launched this month.

We read the primary launch documents published between 2 and 5 September: roughly twenty-five releases across fifteen vendors, including LG, Samsung, Lenovo, Bosch, Siemens, Roborock, Dreame, Anker and eufy, Signify, Xiaomi, TCL, NVIDIA, Acer and ASUS.

Not one of them mentions the Cyber Resilience Act. None mentions UK PSTI, the US Cyber Trust Mark, a software bill of materials, or a coordinated vulnerability disclosure policy.

Exactly one product family in the entire set states a security update lifetime in years.

What the launch documents actually committed to

VendorWhat was promisedWhat was not said
Lenovo, Yoga tablets“Up to seven years of security updates through 2033”, with seven Android OS upgrades. The only stated support lifetime in the whole setTheir own footnote: availability and timing “may vary by device, market, carrier” and “schedules are subject to change”
LG, SIGNATURE refrigeratorAn LLM-based conversational assistant in a fridge, and Direct Drive motors “independently certified by TÜV Rheinland for up to 30 years of operation”The words security and software update do not appear anywhere in the release
eufy, NVR Security System E50“Face recognition, cross-cam tracking, and Smart Video Search, all on-device. No monthly plan to unlock them, ever”Footnote 3 on the same page: cloud features send “videos or thumbnail previews” to the cloud. Thumbnails were the 2023 controversy
Signify, Philips Hue Play Screen SyncA fisheye camera pointed at your television, from £89.99, on sale the day it was announcedNo statement on processing location, data capture, or security updates. Signify publishes a detailed end-to-end encryption whitepaper for its Hue Secure cameras, and wrote none for this one
Withings, StethO SenseAI analysis of heart and lung recordings, including from children, via two named third-party processorsNothing on processing location, jurisdiction, data residency or retention. The “Lifetime Guarantee” in the subscription is device warranty, not patching
Roborock, Dreame, Bosch, SiemensNew connected appliances and robots with cameras and on-board perceptionNo security, privacy, encryption, certification or update-support content in any of the four releases
Primary launch releases published 2 to 5 September 2026, read directly. Quotations verbatim. The LG release was checked by full-text search for the terms security, software update and privacy, none of which appear in it.

The one place the regulation did appear at IFA is a thirty minute Expert Talk in Hall 26c on 7 September, the last full day, open to trade visitors only. Its title, and I am not making this up, begins "The Cyber Resilience Act. Don't Panic!"

Why the silence is the story rather than the deadline

It would be easy to write this as vendors ignoring the law, and I do not think that is quite right.

Article 14 does not require anybody to announce anything at a trade show. A vendor can be entirely ready to file a 24 hour notification on Friday and have no reason to say so in a press release about a fridge. Marketing departments do not write about incident reporting because nobody buys a washing machine because of it.

What the silence tells you is narrower and more useful. There is no commercial pressure at all in this direction. Not one vendor at the largest consumer electronics show in Europe judged that "we will tell you within 24 hours when something is being exploited" was worth a sentence, in the week the obligation started. Support lifetimes are the same: one vendor out of fifteen thought seven years was worth advertising, and that vendor was selling tablets rather than the appliances that will still be in a kitchen in 2040.

Regulation is doing all the work here because nothing else is.

What to do about it

Take this with you

Before Friday if you are a manufacturer, before your next purchase if you are not

  • If you place products with digital elements on the EU market, register for the Single Reporting Platform now rather than during your first incident. Registration under pressure at hour three of a 24 hour clock is the worst possible time to discover an account problem.
  • Write the platform-unavailable case into your incident runbook explicitly, including who decides and what is recorded. ENISA’s guidance is to wait, the regulation does not stop the clock, and you want that decision made calmly in advance with a timestamped record of the attempt.
  • Do not plan to rehearse with a voluntary filing on day one. ENISA state that voluntary reporting under Article 15 will not be possible when the platform opens.
  • Check that your definition of “becomes aware” is written down. The 24 hour clock starts from awareness, and in most organisations awareness happens in a support queue or a security mailbox long before it reaches anyone who knows what Article 14 is.
  • If you are buying connected hardware, ask for the security update end date rather than the marketing. For anything sold in the UK that date must already be published under PSTI, so asking costs you nothing and tells you a great deal about the supplier.
  • Treat an on-device claim as a question rather than an answer. The eufy and Withings examples in this piece both describe local processing in the headline and something else in the footnotes.

The position

The Cyber Resilience Act is a serious piece of law and Article 14 is the sharp end of it: a 24 hour clock, a named channel, and real penalties behind it eventually. It starts on Friday.

The two things worth carrying out of this week are that the only lawful route to meeting the deadline has a documented failure mode with no legal answer, and that an entire industry launched a season of connected products six days beforehand without one of them mentioning it.

Neither of those is a scandal. Both of them are the sort of thing you would rather know on the Sunday than on the Friday.

Sources

  1. PrimaryRegulation (EU) 2024/2847, the Cyber Resilience Act. Article 71(2) on application dates and Article 14 on manufacturers' reporting obligations, both read in the Official Journal textOfficial Journal of the European Unionaccessed 2026-09-06
  2. PrimarySingle Reporting Platform FAQ, updated 4 September 2026, including the new answers on what to do if the platform is temporarily unavailable and on voluntary reporting not being possible at launchENISAaccessed 2026-09-06
  3. PrimaryLG Electronics Highlights Seven Home Appliances at IFA 2026, 4 September 2026: the LLM-based refrigerator and the TÜV Rheinland certification of motors for up to 30 years of operation, in a release containing neither the word security nor software updateLG Electronicsaccessed 2026-09-06

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.