26/08/2026
In sixteen days the EU starts a clock on every connected product sold into Europe. From 11 September, once you know a vulnerability in your product is being actively exploited, you have twenty-four hours to file a first report with ENISA, and seventy-two for the full notification.
That is not the requirement most hardware teams have been preparing for. The Cyber Resilience Act does not ask whether your product is secure. It asks whether you noticed. Noticing is a capability, and almost nobody bought it.
Most connected devices ship with no fleet telemetry worth the name, so you learn about exploitation the way manufacturers always have — a customer complains, a researcher publishes, or a journalist calls. In 2015 Charlie Miller and Chris Valasek took over a Jeep Cherokee on a St. Louis highway from ten miles away, and Fiat Chrysler recalled 1.4 million vehicles, mailing owners a USB stick so they could patch their own cars. That counted as a fast response at the time. Under the rule that starts on 11 September, the first report would have been due before most of that company knew anything had happened.
Here is the part worth arguing about. The teams who find this trivial are the ones who already built the dull software layer: device identity, signed over-the-air updates, telemetry that reports something other than uptime. They built it to run a business on the installed base rather than to satisfy a regulator, and the compliance falls out of it for free. Everyone else is about to find that the certificate on the box was never the security story — the ability to see and to fix was.
So which is it: a twenty-four hour clock as a compliance tax on hardware, or the first regulation that actually pays back the companies who invested in the software layer?