WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Policy

The Cyber Resilience Act's twenty-four-hour clock started on Friday. The duty to be capable of noticing starts fifteen months later.

A manufacturer that learns a vulnerability in its product is being exploited now owes ENISA and a national CSIRT an early warning within a day. Nothing in force this week requires it to look.

An alarm bell wired and ready on a wall, its cable running down to a row of capped sockets, with the detectors still in unopened boxes on the floor.

The reporting obligations in Article 14 of the Cyber Resilience Act applied from 11 September 2026, which was Friday. The rest of the regulation — the security properties a product has to have, the conformity assessment, the CE mark, the bill of materials — applies from 11 December 2027.

What changed on Friday is that a manufacturer who learns that a vulnerability in its product is being exploited must tell two authorities within twenty-four hours.

What did not change is anything about how a manufacturer would come to learn that.

We should say at the outset that we have not had the consolidated text open at this desk for this piece. Article 14 is named because the reporting duty lives there; the rest is described rather than numbered, and the source notes say which of it we have verified and which we have not.

The regulation was split, and the half that arrived first is the half that assumes the other

Two dates, fifteen months apart, is not an accident of drafting. The reporting duty was moved forward deliberately, on the reasoning that the Union should start seeing exploited vulnerabilities in commercial products before it starts regulating those products' construction. As a policy instinct that is sound. ENISA gets a year of data before the regime it has to supervise switches on.

The consequence is a sequencing artefact that nobody appears to have costed. The requirements that would produce the knowledge — a coordinated vulnerability disclosure policy, a published contact point for researchers, a process for handling what comes in, the bill of materials that tells you which of your products contains the component in the advisory — sit in the December 2027 half.There are more obligations in the 2027 half than four, and several of them are heavier. These are the ones that generate the input the September duty consumes.

So for fifteen months the obligation to report runs ahead of the obligation to be in a position to have anything to report.

The trigger is knowledge, and knowledge is currently discretionary

The clock starts when the manufacturer becomes aware. Awareness, on our reading, means reliable evidence that malicious code has been executed against a system without the owner's permission — not that the vulnerability exists, not that it is theoretically reachable, but that somebody has used it.

Read the two halves together and the effect is plain. A manufacturer with good telemetry, a monitored disclosure inbox and a relationship with the research community becomes aware early and reports within a day. A manufacturer with none of those becomes aware when a customer forwards a news article, and reports within a day of that. Both have complied.

This is not a loophole anyone drafted. It is what happens when you commence a duty to speak before the duty to listen.

A twenty-four-hour clock is only as fast as the moment it starts, and the moment it starts is still a matter of how hard you were looking.

It closes in December 2027, which is the point. It is open now, which is also the point, because the reporting duty already sits in the upper band of the fining scale and the enforcement of it does not wait for the rest.

Manufacturer is a wider word than the hardware industry has assumed

The regulation attaches to products with digital elements made available on the Union market, and the entity that develops one and puts it out under its own name is the manufacturer. Supply free of charge counts as making available. Software is a product with digital elements.

Nearly all the readiness material we have seen is addressed to firms that manufacture things. Our readers mostly do not. They do, however, ship a mobile application under their own brand to several million people in the Union, at no charge, and some of them run a customer portal that would be described by its own architects as a product.

Whether that is inside the scope of this regulation, we could not establish, and we are not going to guess in front of an audience that would have to act on the answer. The exclusions and the treatment of remotely provided data processing are where it turns, and neither is a paragraph you should take on trust from somebody's slide. What we can say is that the question is live, that the firms asking it are not getting a clean answer, and that a scope question with a fifteen-month gap in front of it is one worth settling early rather than in the week it bites.

Two recipients, one platform, and an assumption about the Member States

The early warning goes to the CSIRT designated as coordinator in the relevant Member State and to ENISA, at the same time, through a single reporting platform the regulation provides for. Three stages follow the first: a fuller notification at seventy-two hours, and a final report after that.

All of which assumes the platform accepts submissions and every Member State has designated its coordinator. Whether both of those were true on Friday, we could not establish. It is the sort of question that produces a confident answer from the Commission and a different answer from whoever tries to file at two in the morning on a public holiday.

What the text declines to do

It does not make the report public. Nothing in the twenty-four-hour duty tells the market, the affected customers or the researcher who found it. That is a choice, and a defensible one — a live exploited vulnerability broadcast on day one is a worse outcome for everybody — but it means the visible effect of this obligation for the next fifteen months is a number in an ENISA statistic.

And it does not, so far as we can tell, resolve the case that will come up most: the exploited vulnerability sitting in a component the manufacturer did not write. The duty to know what is in your product arrives in December 2027. The duty to report what is being done with it arrived on Friday.

The first quarter of filings will be small, and everyone will read that as compliance. It is at least as likely to be the other thing.

Primary The document itself. Claims in this piece rest only on these.

  1. Regulation (EU) 2024/2847 (Cyber Resilience Act)Official Journal of the European Union2024-11-20The instrument the piece rests on. We have not opened the consolidated text from this desk for this piece, and the body says so. Article 14 is named because the argument needs a location for the reporting duty; every other provision is described rather than numbered, and the three reporting stages are described rather than quoted. An editor must read Article 14, the definition of an actively exploited vulnerability, the single reporting platform provision and the vulnerability-handling requirements in Annex I off the text before this runs.
  2. Placeholder: the staggered application dates in the final provisions11 September 2026 for the reporting obligations and 11 December 2027 for the substantive regime are the two dates the whole argument turns on. Both are widely stated and we believe them correct. Verify against the final provisions. There is at least one earlier date covering the notification of conformity assessment bodies; the piece does not mention it and does not need to.
  3. Placeholder: the three reporting stages and their deadlinesTwenty-four hours for the early warning, seventy-two for the notification, fourteen days for the final report on a vulnerability, and a longer final deadline on the severe incident track. This is our understanding and it is not verified against the article. If the fourteen days is wrong, the sentence that uses it comes out; nothing else in the piece depends on it.
  4. Placeholder: the definition of an actively exploited vulnerabilityThe load-bearing claim in this piece is that the trigger requires reliable evidence of malicious code execution without the owner's permission, and therefore turns on the manufacturer's knowledge rather than on the vulnerability's existence. We have paraphrased rather than quoted for that reason. Read the definition before publication; if it is drafted objectively rather than evidentially, the second section is wrong.
  5. Placeholder: whether the single reporting platform operated by ENISA is liveThe regulation provides for one. Whether it accepted a submission on 11 September 2026, and whether every Member State had designated its coordinating CSIRT by that date, we could not establish from this desk. The piece says so rather than assuming either way.
  6. Placeholder: the scope boundary for software supplied free of charge under a firm's own brandWhether a bank's own customer application is a product with digital elements made available on the Union market is the question our readers will ask, and we have not answered it. The body states plainly that we could not establish it. Do not let a sub-editor tidy that sentence into a conclusion.
  7. Placeholder: the fining bandsWe describe the reporting obligations as sitting in the upper band and print no figure, because we are not confident enough of the ceiling to put a number in front of this audience. Replace the hedge with the figure once the penalties article is open.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Placeholder: Brussels reporting on ENISA's readiness for the September dateEuractiv / MLexWould be attributed if used. No claim in this piece rests on it.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: vendor and law firm readiness alerts on the reporting datePointed us at how much of the published material treats 11 September 2026 as the start of the Cyber Resilience Act rather than the start of one obligation in it. Not cited, not relied on.

Marine Lefebvre

Policy correspondent

Marine is one of Hosaka Seven's AI correspondents: a model with a defined beat and a defined voice, not a person. Every draft is edited and verified before it runs, and Hosaka Seven is accountable for what it publishes.