Most conversations about the Cyber Resilience Act point to December 2027. That is when full conformity requirements apply, when CE marking depends on meeting the essential cybersecurity requirements, and when the regulation takes complete effect.
But the first binding obligation arrives more than a year earlier. From September 11, 2026, any manufacturer selling a product with digital elements into the EU must report an actively exploited vulnerability within 24 hours of becoming aware of it.
Twenty-four hours is not a documentation window. It is an operational one.
What the CRA asks of you
The scope is wider than many teams assume. It covers products with digital elements, which means almost anything that runs code or connects: software, firmware, connected hardware, and the components inside them. It applies whether or not you are based in Europe. If you place the product on the EU market, you are in.
The reporting is staged. An early warning within 24 hours. A fuller notification within 72 hours. A final report within 14 days of a fix, or a month for a severe incident. Reports go to ENISA and the relevant national CSIRT through a single platform.
Miss it and the penalties sit at the top end of EU regulation: up to €15 million or 2.5% of global turnover, whichever is higher.
Why 24 hours is an operational problem, not a paperwork one
You cannot report a vulnerability you have not found. And you cannot report it accurately if you cannot separate a real, exploitable flaw from scanner noise.
Most security programs are not short on alerts. They are short on signal. A tool that floods a team with unvalidated findings does not help you hit a 24-hour deadline. It buries the one finding that matters under a hundred that do not.
So CRA readiness is less about writing a policy and more about two capabilities: continuous visibility of what you have built and exposed, and confidence that a flagged vulnerability is genuine before the clock starts.
Where Edgescan fits
This is the work Edgescan was built for.
Attack Surface Management and Dynamic Application Security Testing run continuously, so assets, exposed APIs, and code-level flaws surface across the product lifecycle rather than at a single point in time. Findings are prioritized against EPSS, CISA KEV, and CVSS, so the exploited and the exploitable rise to the top.
For teams operating in Europe, discovered vulnerabilities are mapped against the EU Vulnerability Database, the ENISA-run source built alongside the CRA. That gives you the European context regulators are working from, not only the US view from the NVD.
Every finding passes through a validation layer that pairs automation with human review, which is how Edgescan delivers zero false positives. Your team hears about real, exploitable issues, not a queue it has to triage before the 24-hour window closes.
And for products that need formal evidence, penetration testing as a service provides on-demand assessment and unlimited retesting, so you can confirm a fix holds and keep the audit trail that conformity and CE marking will ask for.
December 2027 is the deadline people plan around. September 2026 is the one that will catch teams out. The manufacturers who handle it well will not be the ones with the longest policy documents. They will be the ones who can already see their exposure and trust what their tooling tells them.
See where you stand before the clock starts.
