Early warning
within 24 hours
What the vulnerability is, which product it affects, and that you are looking into it. ENISA and your national CSIRT receive it.
The obligation is not to be secure. It is to notice within 24 hours, tell ENISA, and be able to show afterwards what you knew and when. That is a different job from securing a product, and it is the job this page is about.
Since 11 September 2026, a manufacturer who becomes aware of an actively exploited vulnerability in a product with digital elements must report it, including for products already on the market. Three stages, each with a clock that runs on weekends and holidays.
within 24 hours
What the vulnerability is, which product it affects, and that you are looking into it. ENISA and your national CSIRT receive it.
within 72 hours
What you know by then: severity, what you have done, and what users should do.
within 14 days of a fix
The vulnerability, the fix or mitigation, and how it reached the people who need it.
Not every vulnerability starts a clock. The obligation is about vulnerabilities that somebody is using against real systems. Two public sources say which those are, and both are read every hour here.
The US catalogue of known exploited vulnerabilities: the list most of the industry treats as the definition of "being used".
The European vulnerability database, with its own exploited list, published by the authority that receives your report.
Every team that tries it discovers the same four things, usually on a Saturday.
It is not a scanner and not a security product. It is the desk that keeps the obligation moving while you get on with fixing things.

Nothing in these pictures belongs to a customer: they are taken from our demonstration account, which is why the banner says so.
If you can answer these ten, you are ready. If not, each one is a small piece of work now and a bad hour later.
Want it on paper for the meeting? Print this page: the print layout carries the ten questions and nothing else.
General information, not legal advice. Whether and how the Cyber Resilience Act applies to your products is for you and your counsel to decide.