EU Cyber Resilience Act: SMEs face the September deadline
Europe's Cyber Resilience Act is about to become operational in a way manufacturers can no longer treat as a distant compliance project. From 11 September 2026, manufacturers of products with digital elements must begin reporting actively exploited vulnerabilities and severe security incidents. The Act's broader obligations apply from 11 December 2027, but the first reporting clock starts in less than eight weeks.
A new ENISA study suggests that smaller companies are not equally ready. Published on July 13, the agency's SME Cyber Resilience Maturity Assessment Model and accompanying survey turn a regulatory deadline into a practical question: can a product company identify an exploited flaw, make the right decision, and submit defensible information within 24 hours?
Awareness is not operational readiness
ENISA surveyed 194 organisations across 31 countries, including 25 EU Member States. Sixty-six percent of respondents had heard of the Cyber Resilience Act before the survey, but the results still showed a gap in understanding its practical requirements. Company size was the most consistent predictor of maturity: medium-sized organisations scored about one point higher than microcompanies across all five surveyed domains.
The weakest area was particularly revealing. Incident response and product life-cycle management scored lowest overall, especially among microcompanies. Those are precisely the capabilities needed when an actively exploited vulnerability appears in a shipped product and the statutory clock begins.
More than 70% of respondents requested technical-documentation and secure- development templates. ENISA also reports that 142 respondents highlighted a need for financial support. This is not simply resistance to paperwork; it is evidence that many small manufacturers lack repeatable product- security operations.
What starts on 11 September
The CRA reporting rules cover actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. According to the European Commission's implementation guidance, a manufacturer must send an early warning within 24 hours of becoming aware and a fuller notification within 72 hours.
A final report follows no later than 14 days after a corrective measure is available for an actively exploited vulnerability, or within one month for a severe incident. Reports go through the CRA Single Reporting Platform, addressed to the CSIRT where the manufacturer has its main establishment and made available to ENISA under the regulation's sharing process.
Scope depends on the product and the organisation's role. ENISA designed its new model primarily for companies that manufacture and place products with digital elements on the EU market. Integrators and service providers can also use it to improve product-security practices, but using the model does not decide whether a company is legally in scope. That determination needs to be tied to the actual product, supply chain, and CRA definitions.
The five domains ENISA wants SMEs to measure
- Governance and documentation: named ownership, product records, decisions, policies, and evidence that can survive staff turnover.
- Risk management and secure-by-design defaults: threat modelling, risk treatment, safe configuration, and controls built into the product rather than added after release.
- Vulnerability and patch management: intake, prioritisation, coordinated disclosure, remediation, customer communication, and supported update paths.
- Product life-cycle management: component inventory, maintenance windows, end-of-support decisions, and security across development, release, operation, and retirement.
- Awareness, competence, and skills: people who understand both the product and the reporting decision, backed by exercises instead of a policy nobody has tested.
The model offers basic, intermediate, and advanced profiles, plus a downloadable spreadsheet for repeated assessments. ENISA is careful about the boundary: an advanced score neither replaces legal obligations nor proves compliance. It is a readiness tool, not a certificate.
A 53-day readiness plan
- Map products and roles. Identify every product with digital elements offered in the EU, the legal manufacturer, responsible teams, supported versions, and external components. Get legal advice for ambiguous scope rather than assuming “small company” means exempt.
- Define the reporting decision. Write down what evidence reaches the product-security owner, who can classify an incident, who can approve a report, and who is the backup outside business hours.
- Rehearse 24 and 72 hours. Run a tabletop exercise around an exploited dependency. Produce the early warning and full notification with incomplete information, clearly separating confirmed facts from assessment.
- Prepare evidence before the incident. Maintain an SBOM, build provenance, vulnerability contact, affected-version logic, patch process, customer-notification channel, and logging sufficient to determine product impact.
- Protect the response channel. Incident reports, build logs, tickets, and vendor exchanges often contain credentials or exploit details. Use scoped accounts and expiring encrypted transfers rather than copying sensitive material into long-lived email threads.
September is not the end of CRA implementation; it is the first production test of it. A manufacturer that can meet the reporting clock will also have built much of the muscle needed for the wider December 2027 obligations. The useful question for an SME today is therefore not “have we read the regulation?” but “could we execute the first 24 hours on a Friday night?”
