Cybersecurity BlogCyber Resilience Act (CRA): Who’s Affected – and What You Must Deliver by September 2026
In exactly one month, the first binding stage of the Cyber Resilience Act goes live. From 11 September 2026, as a manufacturer you must be able to report an actively exploited vulnerability in your product within 24 hours. Not „my company was attacked” – but „a vulnerability in the product I shipped is being exploited...



