Security1 distinct publisher2 min readPublished
Manufacturers selling into the EU owe a regulator notice within 24 hours of learning that a product flaw is being exploited, while the design rules that would produce the records needed to answer arrive 456 days later.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Read the duty as a form. Within 24 hours a manufacturer names the product, names the vulnerability, and says when it learned the flaw was being exploited [1]. At 72 hours it files the fuller account [2]. Two of those fields are not security telemetry. They are release records and an intake timestamp, and a tool bought in late August produces neither.
Nothing in the trigger keys on a severity score. Exploitation starts the clock [1], which means the CVSS argument that usually consumes the first day of a response has no bearing on whether the filing is due.
The interval between the two dates: 365 days from September 11, 2026 to September 11, 2027, then 91 more to December 11, 2027, so 456 days [5]. The column counts it as fifteen months, reporting first [4]. Across that window, manufacturers report exploited flaws in products that the essential cybersecurity requirements do not yet govern [6][3].
The column's reading of why: mandating disclosure costs a regulator almost nothing and becomes very hard to fake once thousands of companies are doing it at once, so what lands on September 11 is a visibility requirement rather than a security one [9]. That is the author's inference about intent, not language from the regulation.
The comparison he draws is worth keeping. GDPR's 72-hour breach notification, from 2018, was the rule that made "we are still looking into it" an insufficient answer [14]. The CRA's first notice is 48 hours tighter than that [17]. Any incident process built to the GDPR clock has a day and a half of verification slack it will not have here. Sarbanes-Oxley did the equivalent in 2002 by putting a CEO's and a CFO's own names on the accuracy of a financial statement [13].
The author writes from eleven days out [19], which places the piece at the end of August 2026 [18], after close to thirty years of watching software organizations prepare for a date on a calendar [16]. His prediction is not that companies miss the deadline. It is that almost none of them finish the exercise able to answer the underlying question any faster than they can today [8]. At hour 24 a punctual filing and a well-founded one look identical from outside; they diverge at hour 72, where the fuller account has to hold together [2].
Ranked by verification strength, evidence, and original report placement.
EU Cyber Resilience Act reporting obligations take effect September 11, 2026: manufacturers of products with digital elements sold into the European Union must tell a regulator within 24 hours of learning that a vulnerability in one of their products is being actively exploited.
A fuller account of the exploited vulnerability is due at 72 hours.
The requirements that govern how a product gets designed and built, which the regulation calls the essential cybersecurity requirements, do not apply until December 11, 2027.
The column describes the two dates as fifteen months apart, with the reporting requirement the one that comes first.
For fifteen months European regulators will require manufacturers to disclose exploited vulnerabilities in products that are not yet subject to the regulation's own engineering requirements, so companies report problems before they are required to have done anything to prevent them.
Sarbanes-Oxley did something similar in 2002, when the accuracy of a financial statement stopped being handled by the accounting department and became something a CEO and a CFO signed their own names to.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
TikTok's international arm hit $9.1 billion while Washington was breaking up its US business1 distinct publisher
product
Grok CSAM suit gains a fourth plaintiff and a 7,000-image count2 distinct publishers
security
NIST's multi-cloud tally: one resilience win against 23 new problems1 distinct publisher
build
Time to revoke: the two timestamps a closed ticket cannot give you1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Dates that survive checking, sourced from one desk
Three dates carry this story — the 24-hour clock starting September 11, 2026, the design rules on December 11, 2027, and the December 10, 2024 entry into force that The Hacker News uses to argue nobody was ambushed — and all three reach us through the same column. The one thing we could verify without a second source is the arithmetic between the first two, and 456 days is correct. Beyond that: no regulation text, no regulator, no corroborating outlet.
Nothing observed, only anticipated
Eleven days out from the deadline, there is nothing here to count: no filings, no readiness survey, no company saying what it built or bought, no regulator describing what it expects to receive. The nearest thing to evidence of behaviour is the author's forecast of weekend spreadsheets and two-week consultants, which is a prediction about firms he does not name.
Deflationary in argument, confident in generalisation
The column is arguing downward, not upward — its whole point is that hitting the deadline proves less than the deadline's coverage implies. That earns it credit. What tips the balance slightly the other way is that its most quotable lines, 'the majority' will file on time and 'almost none' will improve, borrow the certainty of the dates without any of their verifiability. Thirty years of pattern recognition is a real basis for a hunch and not a basis for a percentage.
Trade-press opinion slot, affiliation unstated
This sits in The Hacker News's expert-insights section, the part of a security trade site where vendor-adjacent argument usually lives, and nothing we have names the author's employer or interest. Cutting the other way: the piece treats the two-week scanner purchase as the failure mode and points readers toward unglamorous record-keeping instead, which is a hard shape for a sales pitch to take.
Low-risk facts, single witness
We are fairly comfortable with the skeleton — statutory dates are the kind of claim that is cheap to state and expensive to get wrong, and the internal arithmetic holds. We are not comfortable with the flesh. One publisher, one contributor, no regulator, no manufacturer, and the behavioural core of the piece is untested by anyone. A second account would move this number more than any further reading of this one.