Loading the latest actively exploited vulnerabilities…Powered by Achilles
The CRA Fringe · Issue 1

Vulnerability Handling and the Clocks That Started Today

Daniel Thompson-Yvetot

A new dossier with every issue. Today we cover the 11 September 2026 reporting obligations.

Today, 11 September 2026, the reporting obligations in Article 14 of the Cyber Resilience Act enter application, roughly fifteen months before the general obligations arrive on 11 December 2027. This is the first CRA obligation to bite, and it applies to products already on the market rather than only to new ones. Compliance programmes have been organised around this date for the past year, and working towards it has shown how much of the Regulation still rests on interpretation rather than on text.

Our own interpretive work has so far stayed inside client engagements and standards meetings, and we have decided to publish it, one dossier at a time, through this newsletter. Each issue of The CRA Fringe introduces a position paper that takes a single question, works through the primary sources, and arrives at a defended answer. The name describes the territory we intend to cover, since the centre of the Regulation is already well served by the Commission, the standards bodies, and the usual compliance checklists. The fringe is the set of rare cases that still fall inside the area of applicability, where the Regulation clearly applies but nobody has worked out exactly how.

This issue’s dossier

Given that framing, it may seem odd that the first dossier is Vulnerability Handling under the CRA: the 11 September 2026 Reporting Obligations, which sits at the very centre of the Regulation. Starting there is deliberate, because today is the day the centre becomes enforceable and the fringe only makes sense once the baseline is fixed. The dossier covers actively exploited vulnerabilities, severe incidents, the Single Reporting Platform, and the 24 / 72 / 14 clocks.

You can get the dossier at comply.land/shop.

For readers who want the shape of the obligation before opening the document, the core of it fits on one page. There are two triggers: an actively exploited vulnerability, and a severe incident having an impact on the security of a product with digital elements. There are three clocks: an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report within 14 days of a corrective measure being available for vulnerabilities, or within one month for severe incidents. There is one destination, the ENISA Single Reporting Platform, which routes the notification to the CSIRT of the manufacturer’s main establishment and makes it available to ENISA at the same time.

Of those three elements, the trigger deserves the closest reading because the 24-hour clock is governed by exploitation rather than by discovery. A vulnerability that is known, published, or under coordinated disclosure does not trigger Article 14 unless there is reliable evidence that someone has exploited it without permission. Sound standing vulnerability handling under Annex I, Part II is what keeps most CVEs out of the 24-hour clock in the first place.

Once the triggers and clocks are settled, the dossier turns to recommended actions and closes with three open issues, and it is in those open issues that the fringe begins. The first is reporting on products that are not yet conformant during the window to December 2027, and the second is the overlap with NIS2 and DORA incident reporting. Both follow directly from the text and its timing.

The third is the one that came as a surprise to us: the reporting duties outlive the support period even though the handling duties do not. A manufacturer can end support for a product, stop shipping security updates for it, and still be on the 24-hour clock if someone exploits it in the field. Support-period planning that treats the two sets of obligations as ending together needs a second look, and later issues will go there.

What a dossier is

Each dossier carries an executive summary, the legal framework, the analysis, recommended actions, open issues, and citations to primary sources only. Each also carries a revision date because guidance will shift and standards will move from Enquiry draft to publication, and when that happens the dossier gets a revision rather than a quiet edit. Updated versions are published on comply.land.

For the same reason that the sources are primary and the revisions are visible, none of it is legal advice and none of it is a conformity determination. It is the working, written down so it can be argued with.

What comes next

The next issue will introduce the next dossier, and since the point of the series is to write down the questions that do not yet have a settled answer, we would like you to choose it. Tell us what the next dossier should be about: a scope question your team continues to reopen, a clause nobody on your side reads the same way twice, or an edge case where the regulation clearly applies, but the “how” is missing. Reply to this issue or leave a comment, and the most argued-over question gets written up.

Get this first dossier at comply.land/shop, and subscribe to The CRA Fringe to receive each new one as it is published.