Andrea Margiovanni .it
Closed red stage curtain in a theatre, lit by a single overhead spotlight, with the silhouettes of an audience already seated. No dress rehearsal: when the curtain rises, the first performance is opening night.

No Dress Rehearsal

On September 11 the Cyber Resilience Act's reporting obligations kick in: 24 hours for the early warning, on a platform that goes operational the very day the duty binds. No API, no test environment, an address that isn't public yet. Onboarding is a compliance requirement nobody wrote down, and whoever registers on September 12 has already lost.

On July 31 ENISA published a factsheet and two step-by-step guides for the Single Reporting Platform, the tool through which, from September 11, manufacturers of software and connected products must report actively exploited vulnerabilities and severe incidents. The guides explain how to register, who may do it, which fields to fill in. Read back to back, they yield a picture no press release has had any interest in spelling out: the platform goes operational on September 11, the same day the obligation becomes binding. No manufacturer will have ever seen it. There is no test environment, no API is foreseen, the public address hasn’t been announced, and the list of national CSIRTs you will be talking to will arrive, verbatim, “at a later stage”. When the curtain rises, the first performance is opening night, and the audience is already seated.

Twenty-four hours, measured from the moment you know

It’s worth recalling exactly what kicks in. Article 14 of the Cyber Resilience Act requires a manufacturer that becomes aware of an actively exploited vulnerability in one of its products, or of a severe incident affecting the product’s security, to submit an early warning within 24 hours to the CSIRT designated as coordinator and to ENISA. A fuller notification follows within 72 hours, then a final report. Breaching these obligations sits in the regulation’s top sanctions band, up to €15 million or 2.5% of worldwide annual turnover, the same band reserved for the essential security requirements.

The detail that decides everything is where the clock starts. The 24 hours are not measured from the fix, nor from technical confirmation: they are measured from awareness. And awareness is an organisational fact before it is a technical one. It happens in a customer ticket, in an email that landed on the wrong channel, in a thread somebody reads twelve hours late. A company that hasn’t decided who, internally, has the authority to declare “we know” doesn’t have a paperwork problem: it has a clock that starts without anyone hearing it tick.

The regulation’s full regime arrives on December 11, 2027, and I have already argued that those months are not a grace period. The part starting now is the one with the shortest clock in all of European product law.

The platform that opens on opening night

The July 31 guides describe a reasonable flow. Registration through EU Login. Two seats per manufacturer: a primary Assigned Representative and a secondary one, who joins by email invitation, and the invitation expires after seven days. The coordinating CSIRT is picked from a drop-down menu. The early warning’s minimum fields are few and sensible: notification type, level, manufacturer name, product, a title, and for incidents whether an unlawful or malicious act is suspected. So far, ordinary and even well-designed bureaucracy.

Then there is the FAQ, the most informative of the three documents because it speaks in negatives. “No Application Programming Interfaces will be provided at this stage”: no API, in the era when every compliance conference says the word automation on every slide. The report with the tightest deadline in European law will be a person filling in a web form, quite possibly at three in the morning. The public URL “will be communicated and published in due course”, which is to say it doesn’t exist. The list of CSIRTs designated as coordinators, the drop-down that determines who you are talking to, will be provided later. And the platform’s testing is internal, between ENISA and the CSIRTs: no rehearsal is foreseen for manufacturers. The first real report will also be the first load test performed by outside hands.

This is not a piece of administrative trivia. It is the difference between an obligation and a service: the obligation has been ready for months, the service opens on opening night.

Onboarding is an unwritten requirement

The regulation says what to report and how fast. It does not say, because it is not its job to, that doing it within 24 hours requires having registered beforehand: having the EU Login accounts, having chosen the two names, knowing which CSIRT to select in the menu. None of these preconditions is a legal obligation. Together they are the difference between complying with Article 14 and breaching it.

This is a category you meet constantly in compliance work and that has no name: the unwritten requirement, the operational precondition without which the written requirement cannot be met. Whoever reaches September 12 unregistered won’t be fined for it, because registration is not owed. They have simply turned the first exploited vulnerability in their product into a race against two clocks, the reporting one and the onboarding one, and the second was in nobody’s plan. With a calendar aggravation on top: the secondary representative’s invitation expires in seven days, and September is the month when primaries have just come back from holiday with other things to do.

Obligations don’t slip. Instruments do

On July 27 the Commission published the practical guidance foreseen by Article 26 of the regulation: scope, remote data processing, open source, substantial modification, support period. Compared with the consultation draft, the industry requests that made it in all sit on the product side, the one that falls due in December 2027: minor security fixes don’t restart the support period, the conformity reassessment of a modified product covers the components touched, not the entire system. On the reporting side, due in four weeks, nothing was conceded. Not out of severity: there was no margin, Article 14’s dates sit in the regulation and no guidance can move them.

Meanwhile the harmonised standards, the only instrument that will grant presumption of conformity, have gone the other way: the Commission has proposed pushing the standardisation request’s deadlines back by two months, with the first horizontal standards now expected by the end of October 2026 and the vertical ones by the end of December. Not one harmonised CRA standard has been cited in the Official Journal to date, so presumption of conformity currently exists for no product category at all. The pattern is the one ENISA’s maturity model had already made visible in July: Europe keeps the dates of its obligations and misses the dates of its instruments. Whoever waits for the standards “to avoid doing the work twice” isn’t saving anything: they are betting on the leniency of market surveillance authorities. A legitimate strategy, provided it is presented to the board for what it is, a bet and not a plan.

What happens when an obligation switches on

To know what happens after September 11 you don’t need imagination: it already happened, in Italy, over the past six months. On July 24 ACN, the national cybersecurity agency, published its operational report on the first half of 2026, the first with NIS2 notification duties fully in force: 2,171 cyber events handled, up 47% on the same period of 2025; 1,160 notifications received, 953 mandatory and 207 voluntary, from 890 entities, of which 690 had never notified anything before. Over the same semester ransomware fell by 12% and DDoS by 32%. The agency itself, with an honesty that deserves credit, attributes the growth to the widening of its observation perimeter, not to a proportional increase in the threat.

Two lessons come out of those numbers. First: when CRA reporting volumes explode, and they will, someone will read them as proof that Europe is under attack. They will be proof that Europe switched the lights on. The second lesson sits in the number 690: six hundred and ninety organisations spoke to their authority for the first time in their existence because an obligation forced them to. A first contact with a regulator under a 24-hour deadline is the worst possible first contact, and ACN, which will also be Italy’s coordinating CSIRT on the European platform, is about to receive a second wave of debutants.

The registry nobody tested in public

There is one last aspect, and it needs handling with care. A platform that collects, in real time, the actively exploited and not yet patched vulnerabilities of the products on the European market is, by construction, one of the most coveted archives on the continent. The regulation knows it: Article 16 allows CSIRTs to delay the dissemination of a notification on cybersecurity grounds, and the delegated act governing those cases was adopted in December. I am not claiming the platform is insecure, I have no elements for that. I am observing an asymmetry: those who report are asked to trust a system they have never been allowed to see, while those who collect have not had to demonstrate anything in public. For an infrastructure that will hold the list of Europe’s open doors, a visible period of operation before the obligation was not a luxury: it was the bare minimum of the trust that is now being taken for granted.

The four weeks

The useful part of all this is that almost everything preceding the form can be rehearsed now, without waiting for ENISA. EU Login accounts are created today, not on September 11. The two names are chosen with September’s calendar in hand, because an invitation that expires in seven days does not forgive staggered holidays. The decision about who declares awareness, and through which channel, fits on one page: it is the line where the clock starts, and it is an organisational fact, not a technical one. And the rehearsal nobody offers happens in-house: take last year’s worst incident and fill in, on any plain document, the six fields of the early warning, timing how long it takes not to write the answers but to know them. I have already argued that compliance fails for lack of inventory: if naming the product, the version and the component takes more than 24 hours, ENISA’s form is not the problem.

On September 11 the curtain rises anyway, for everyone. The difference between those who rehearsed and those who didn’t won’t show that day. It will show the first night a clock starts at three in the morning, and in one of the two companies somebody already knows which form to open, with which credentials, and what to write in it.

Key takeaways

  • The Single Reporting Platform goes operational on September 11, 2026, the same day the Article 14 reporting obligation becomes binding. There is no test environment for manufacturers, ENISA’s FAQ rules out any API “at this stage” and the public address hasn’t been announced: the first real report will also be the platform’s first outside trial.

  • The obligation is written in the regulation, its preconditions are not: an EU Login account, two Assigned Representatives per manufacturer with an invitation that expires in seven days, a coordinating CSIRT to pick from a list that hasn’t been published yet. Whoever reaches September 12 unregistered has turned their first exploited vulnerability into a race against two clocks.

  • The Commission’s July 27 guidance concedes ground only on the product side, which falls due in 2027: minor security fixes don’t restart the support period, reassessment covers the modified components. On the reporting side, due in four weeks, nothing was conceded. And the harmonised standards slip by two months while the obligation dates stay put.

  • Italy’s first NIS2 semester is the empirical preview: 2,171 cyber events handled by ACN, up 47%, while ransomware and DDoS declined. When CRA reporting volumes explode after September 11, it won’t be proof that Europe is under attack: it will be proof that Europe switched the lights on.

  • The 24-hour clock starts at awareness, and awareness is an organisational fact before it is a technical one. The rehearsal nobody offers happens in-house: take last year’s worst incident, fill in the early warning fields on a plain document and measure how long it takes just to know the answers. If it takes more than 24 hours, the form is not the problem.

Questions & answers

What does Article 14 of the Cyber Resilience Act require from September 11, 2026?

A manufacturer that becomes aware of an actively exploited vulnerability in one of its products with digital elements, or of a severe incident affecting the product’s security, must submit an early warning within 24 hours to the CSIRT designated as coordinator and to ENISA, followed by a fuller notification within 72 hours and a final report. The clock starts at the moment of awareness, not at the moment of the fix, and breaching these obligations sits in the regulation’s top sanctions band: up to €15 million or 2.5% of worldwide annual turnover.

What is the Single Reporting Platform and why can't it be tried in advance?

It is the single platform, established by Article 16 of the CRA and run by ENISA, through which all Article 14 reports must pass. It goes operational on September 11, 2026, the same day the obligation becomes binding. Testing has been internal, between ENISA and the national CSIRTs: no trial environment is foreseen for manufacturers, the official FAQ rules out any API “at this stage” and the public URL will only be announced shortly before go-live.

How does registration on the platform work?

You need an EU Login account. Each manufacturer gets two seats: a primary Assigned Representative and a secondary one, who joins through an email invitation valid for seven days. During registration you pick your designated coordinating CSIRT from a drop-down menu, but the list of designated CSIRTs hasn’t been published yet. Validation by the CSIRT happens after first access and runs in parallel with any report: you can notify before validation completes, but nobody wants to discover how the flow works during their first exploited vulnerability.

Reporting numbers will explode after September 11: does that mean attacks are increasing?

No, and Italy’s first NIS2 semester proves it. On July 24, 2026, ACN reported 2,171 cyber events handled, up 47% on the same period of 2025, with 1,160 notifications received from 890 entities, 690 of them filing for the first time ever. Over the same semester ransomware fell by 12% and DDoS by 32%. The agency itself attributes the growth to the widening of the observation perimeter, not to a proportional increase in the threat: when a notification duty switches on, visibility rises, not the attack.

What can a manufacturer do in the four weeks that remain?

Everything that precedes the form can be rehearsed now: create the EU Login accounts today, choose the two representatives with September’s calendar in hand, since the secondary’s invitation expires in seven days, and decide in writing who in the company declares awareness of an exploited vulnerability and through which channel, because that is where the clock starts. Then run the dress rehearsal ENISA doesn’t offer: take last year’s worst incident and fill in the early warning fields on a plain document, timing how long it takes just to know the answers.

The author

Andrea Margiovanni

Andrea Margiovanni

I help public bodies and private organizations read their own infrastructure dependencies. Digital sovereignty is a lattice, not a flag; and it is measured more on contracts than on speeches.

See the guide
© 2026 Andrea Margiovanni Made with care, by hand