The problem
Most CRA planning is aimed at 11 December 2027, when the essential requirements, conformity assessment and CE marking apply. That is the wrong first date.
Article 14 reporting starts on 11 September 2026, and it does not wait for the rest of the regulation. It applies to every product with digital elements already made available on the Union market, including things placed there years ago and never touched since. An actively exploited vulnerability triggers an early warning to your national CSIRT and ENISA within 24 hours, a fuller notification within 72 hours, and a final report within 14 days. For a severe incident the final report runs to one month.
Three things usually go wrong at once. Nobody has decided which products are in scope. Nobody has worked out which conformity route each product takes, and the route changes what evidence you need to have been generating all along. And nobody has a duty officer who can produce a CSIRT notification on a Saturday.
What you get
- A scope determination across your product estate, separating what the CRA covers from what other legislation already governs
- Classification into default, Important Class I, Important Class II or Critical, with the conformity route each implies and the reasoning written down
- A reporting capability that can actually meet 24 hours: who decides, what "actively exploited" means for you, who holds the ENISA and CSIRT channel, and what gets sent
- A gap assessment against the essential requirements in Annex I, ahead of the 2027 date rather than into it
- Support period determination, which has to be stated at the point of sale in months and years and is a commercial decision as much as a technical one
- Technical documentation and vulnerability handling reviewed as evidence, not as policy
Proof point
Delivered alongside the regulatory work this practice already runs across NIS2, DORA and the EU AI Act, where the recurring lesson is the same: the reporting clocks start at the moment somebody notices, and the organisations that struggle are the ones without a named person who can act inside a day. ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor.