EM1 - CRA Sequence
To view this email as a web page, click here
HackerOne

CYBER RESILIENCE ACT

Two dates to keep

Hi ala,


If an organisation places products with digital elements on the EU market, the Cyber Resilience Act (Regulation (EU) 2024/2847) now sets the rules for how you handle vulnerabilities. Two dates matter, and they are not the same:

  • 11 September 2026: reporting obligations begin (Article 14). Actively exploited vulnerabilities and severe incidents must be reported on a staged clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days (one month for severe incidents).
  • 11 December 2027: full application. A published CVD policy and process, lifecycle vulnerability handling, and a defined support period all need to be in force.

The shift is operational, not paperwork. It is no longer enough to have a policy. You have to prove you can execute it, quickly, with evidence.


That starts with one thing: a monitored reporting channel where every vulnerability is captured, validated, and recorded, so when the clock starts you are acting on real risk, not noise.

More soon on how teams are standing this up without slowing down.


Warm regards,
Rebecca Taylor