Skip to content
Phalanx
roRequest a quote
Menu+

Cyber Resilience Act

The CRA clocks started running on 11 September 2026.

Regulation (EU) 2024/2847 requires manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents. The first question is not how you report. It is whether you must.

11 September 2026The date the reporting obligations took effect.

Step one

Most companies owe nothing here. That answer is the first thing the platform gives you.

Scope determination is not setup you do before the feature works. It is the feature first deliverable, and it is what stops the platform from opening a regulatory clock on a company with no standing to file anything. Every product gets a role, and the role decides what you owe.

Own product

Full obligation

You are the manufacturer. The deadlines run for you, and the platform prepares the export for the single reporting platform.

Supplier to a customer

Contractual notice, no filing

Somebody else is the manufacturer. What you owe is fast notice to them, on a contractual clock, because their 24 hours starts when they become aware and your silence spends it. The platform produces no filing export for this role.

Internal only

Out of scope

Not covered by the regulation. Recorded anyway, because a dated negative determination is exactly what an auditor wants when they ask why you filed nothing.

The deadlines

Four clocks, started by the same event.

The trigger is an actively exploited vulnerability, or a severe incident affecting the security of the product. From the moment you become aware, the deadlines run.

24 h

Early warning

The first notification, from the moment you became aware.

72 h

Full notification

The complete description of the vulnerability or incident and the measures taken.

14 days

Final report, vulnerability

From the point a corrective measure is available.

1 month

Final report, incident

From the 72 hour full notification.

What else the module does

The evidence, not just the alarm.

SBOM

Upload the SBOM. Vulnerabilities attach themselves to the product.

The platform reads your component list and links known vulnerabilities to the product they affect, so you know which clock started and over what.

Annex I

Annex I, mapped onto the ISO controls you already run.

The essential cybersecurity requirements overlay your active ISO 27001 controls, the same way NIS2 does. No second document set for a second regulation.

Register

Every filing keeps its state and its evidence.

What was sent, when, to whom, and off which finding. Missed deadlines are flagged as missed rather than quietly absorbed.

Export

The report leaves the platform already formatted.

The content the single reporting platform asks for, prepared for the CSIRT in the state where you are established. For Romania, that is DNSC.

The boundary

The platform prepares and exports. It does not file on your behalf.

Submission to the ENISA single reporting platform stays an act of your company, performed by a person who answers for it. We say so here because this is the kind of claim a buyer checks during the security review, and an ambiguous phrasing costs more than a missing page.

Request a quote