Starting September 11, manufacturers selling digital products in the European Union must notify regulators within 24 hours of discovering an actively exploited vulnerability, with a complete report due at 72 hours, according to an analysis published by The Hacker News on August 31. The piece, written by ActiveState CEO Abby Kearns, examines the EU's Cyber Resilience Act and argues that the regulation is designed to expose what companies actually know about their products before requiring them to fix underlying problems. Most firms will meet the filing deadline through last-minute scrambles—spreadsheets built over weekends, notification templates sent to legal teams, consultants on two-week engagements—but that compliance won't answer the deeper question of what's actually inside their software.
The reporting obligations kick in on September 11, 2026, but the essential cybersecurity requirements that govern how products are designed and built don't apply until December 11, 2027—a gap of fifteen months. During that period, European regulators will require manufacturers to disclose exploited vulnerabilities in products not yet subject to the regulation's own engineering standards, meaning companies must report problems before they're required to have done anything to prevent them. The Cyber Resilience Act entered into force on December 10, 2024, giving firms twenty-one months between the law's effective date and the reporting deadline. Kearns notes that mandating disclosure costs a regulator almost nothing and becomes difficult to fake once thousands of companies are doing it simultaneously, allowing Brussels to learn more about the real state of software sold in Europe within a year than a decade of vendor self-certification ever did.
The companies that struggle after September 11 won't be the ones carrying the most vulnerabilities—every large organization carries many and always has—but rather those that can't say on demand what shipped in a given product and when they first learned of a problem, according to Kearns. "What changes in eleven days is that the gap starts getting documented by the company itself, with dates on it, and filed somewhere official," she writes. The analysis draws parallels to Sarbanes-Oxley in 2002, when financial statement accuracy became something CEOs and CFOs signed personally; GDPR in 2018, with its 72-hour breach notification that made "we are still looking into it" insufficient for the first time; and the SEC's 2023 rule requiring public companies to disclose material cybersecurity incidents within four business days.
Kearns argues that boards are asking the wrong question when they seek assurance their companies will be compliant on September 11, because filing a notification inside 24 hours is achievable for any organization willing to dedicate enough people for two weeks. A better question would be whether the company can establish what's in a given product and when it first knew about a vulnerability right now, without standing up a special project to find out—if the answer comes back with a caveat, timeline, or the name of someone who would have to check, the company doesn't have that capability. She predicts that after September 11, the standard excuse will upgrade from "we had a scanner" to "we filed a report," which will establish that somebody knew about a vulnerability but won't show whether the organization can act on what it knows this week or next quarter. The organizations that emerge successfully from these transitions treat knowing what's inside their software as a standing operational capability, funded continuously and owned by somebody, in the same way they already treat knowing what's on their balance sheet—September 11 will come and go with most companies filing on time, but the fifteen months until December 2027's engineering requirements arrive isn't very long, and that's the deadline worth planning against. The real test isn't whether compliance theater can survive a filing deadline, but whether governance models built for software can withstand the kind of personal accountability that's been standard in financial reporting for two decades.

