Not legal or tax advice. This is process tooling. Whether your product is in scope, and which class it falls into, is your call with your own counsel.

EU Cyber Resilience Act · reporting starts 11 September 2026

SBOM in CI, a working vulnerability intake, and the 24 and 72 hour runbook, installed in one session.

From 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents. The clock is 24 hours for an early warning, 72 hours for the notification, and 14 days after a fix is available for the final vulnerability report. Reports go through one platform run by ENISA, with your national CSIRT as the coordinator. Most five to thirty person teams have no SBOM, no intake channel, and no named on-call. This kit is the two page process such a team can actually run at 3 a.m.

Reading the runbook first is a valid answer. The repo is MIT licensed and free: github.com/omarnagy91/cra-reporting-starter, public on 11 September 2026.

The clock

Five deadlines, counted from one moment.

Nothing here is hard to understand. It is hard to execute at 3 a.m. with nobody named and no channel that anyone watches.

T + 0
You become aware

Someone tells you, or your own monitoring does. This is the moment every other deadline counts from, which is why the intake channel matters more than the form.

24 hours
Early warning

A first notification, before anyone has the full picture. The point is speed, not completeness.

72 hours
Full notification

The fuller account of what is happening and what is being done about it.

14 days
Final vulnerability report

No later than 14 days after a corrective measure is available.

1 month
Final incident report

Within one month of the 72 hour notification, for a severe incident.

Deadlines as published by the European Commission and ENISA, read 6 September 2026, and checked against the official text of Regulation (EU) 2024/2847. Sources in the table below.

The two final reports are not the same clock

For a vulnerability it is no later than 14 days after a corrective or mitigating measure is available. For an incident it is within one month after the incident notification was submitted. Most summaries collapse the two into one number.

Your class does not get you out of September

Annex III (important, Class I and II) and Annex IV (critical) change the conformity assessment route under Articles 7, 8 and 32. Article 14, the reporting duty, applies regardless. Being a default product does not move the date.

The articles

Read out of the official text, not out of a summary.

Titles as they appear in Regulation (EU) 2024/2847, retrieved 6 September 2026 from the EU Publications Office.

Article 14Reporting obligations of manufacturers
Article 15Voluntary reporting
Article 16Establishment of a single reporting platform
Article 24Obligations of open-source software stewards
Article 71Entry into force and application

"This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."

Article 71(2), Regulation (EU) 2024/2847.
Facts and where they came from

Every claim on this page has a link.

Main CRA obligations apply from 11 December 2027. Reporting obligations apply as of 11 September 2026.
European Commission, CRA policy page (updated 27 July 2026)
What gets reported: actively exploited vulnerabilities, and severe incidents impacting product security.
European Commission, CRA reporting page (updated 31 July 2026)
Reporting runs through the Single Reporting Platform operated by ENISA. ENISA and the coordinating CSIRT receive the notification.
ENISA, Single Reporting Platform
Reporting is exclusively through the Single Reporting Platform, with no API at launch. Plan for a human to submit it.
ENISA SRP FAQ (updated 4 September 2026)
Your coordinating CSIRT is the one in the Member State of your main establishment, where cybersecurity decisions are predominantly made.
ENISA SRP FAQ (updated 4 September 2026)
Which team that is, is published. ENISA maintains the List of CSIRTs Designated as Coordinators for all 27 Member States.
ENISA, List of CSIRTs Designated as Coordinators (updated 4 September 2026)
Assigned Representatives need an EU Login account with multi-factor authentication. The primary representative registers, then invites up to 20 secondary ones.
ENISA SRP FAQ
The regulation is Regulation (EU) 2024/2847.
European Commission, CRA policy page

ENISA has not published a public URL for the Single Reporting Platform as of 6 September 2026, so this page links the ENISA platform page rather than guessing an address.

Free scope check

Six questions, about ten minutes of thinking.

It runs in your browser and nothing is sent anywhere. It will not tell you whether you are in scope. It will tell you which question to take to counsel first.

Scope check · 6 questions · nothing leaves this page0 / 6
01Do you place a product on the EU market, or sell to EU customers who do?
02Does anything you ship run on the customer's device or hardware, rather than only on your servers?
03Is any of it firmware, an operating system, a browser, a password manager, a VPN, an identity or access product, or a security product?
04Do you publish it as open source, and does a foundation or steward stand behind it?
05How many people are on the team?
06Do you have an SBOM produced automatically on release today?
What it costs

Free if you want to do it yourself.

The whole process is public. You pay to have it working in your repositories by the end of an afternoon instead of the end of a quarter.

Free
EUR 0
MIT licensed, public repo

The whole process, in writing, for teams who would rather do it themselves.

  • SBOM workflow for GitHub Actions (CycloneDX and SPDX)
  • security.txt and /.well-known templates
  • A vulnerability intake form in three variants
  • The reporting runbook
  • The scope decision tree
  • The tabletop script
Kit plus install
EUR 690
one off, 90-minute session
Most teams start here

The same kit, running in your repos and on your site before the session ends.

  • The SBOM workflow running on your release pipeline
  • Intake form wired to your queue or table, with email alerts
  • The runbook filled in with your CSIRT, your named roles and your product list
  • One tabletop exercise run end to end, with timings
Kit plus install plus retainer
EUR 690 then EUR 120
one off, then per month

For teams who want the runbook to still be true in six months.

  • Everything in the install
  • Quarterly runbook review
  • Dependency vulnerability digest from your SBOM against OSV
  • Template review when a real report is needed
Agency licence
EUR 1,900
flat

For agencies who ship products for other people and keep getting asked the same question.

  • Use the installed kit across your client projects
  • Co-branded runbook
  • One onboarding session for your team

Payment: Install and agency licence by Wise or bank transfer. Retainer by bank transfer. No card checkout on this offer yet.

The 90 minutes

What actually happens in the session.

Remote, screen shared, one sitting. Cairo (GMT+2), so EU mornings and afternoons both work.

0 to 10
Scope pass

Walk the decision tree against your actual shipped artefacts. Which are in scope, which are not, and why.

A dated scope decision document, signed off by you.
10 to 30
SBOM in CI

Install the workflow, run it by hand on the default branch, then on a real tag. Inspect the CycloneDX and SPDX output.

Two SBOM artefacts attached to a release, and a green workflow run.
30 to 50
Intake channel

Deploy security.txt with a real expiry. Stand up the intake form in whichever of the three variants fits. Send one test report through it.

A live security.txt that validates, and one test report in the queue with the alert received.
50 to 70
Runbook fill

Roles, escalation path, the coordinating CSIRT, the EU Login and Assigned Representative step, the severity triage table, and the three communication templates. The runbook answers "which CSIRT is mine" in two steps: your Member State under Article 14(7), then your team read off ENISA's published list of designated coordinators. No phone calls, no guessing.

A runbook with zero remaining placeholders, version stamped.
70 to 90
Tabletop

One simulated actively exploited vulnerability, run end to end against the clock.

Real timings written down, and the gaps found.
Your 15 minutes, before it starts
  • Name one person who owns security reports, and one backup. Names, not roles.
  • Give write access to the repository or repositories that produce the shipped artefact.
  • Decide where the intake lands: an existing ticket queue, a Supabase table, or an email inbox.
  • Name the Member State of your main establishment, which decides your coordinating CSIRT.
  • List the products or artefacts that ship to customers, with the version scheme for each.
  • Create a security@ address or alias that at least two people read.

Registration on the ENISA platform itself stays your action, under your own Assigned Representative account. Nobody should be registering as you.

Never offered

What is not on the table.

  • Legal advice on classification
  • Filing reports on your behalf
  • Penetration testing
  • Conformity assessment for important or critical products
  • NIS2 compliance work
Three things people say

The honest answers.

"We are pure SaaS, this is not us."

If you ship a client, an agent, a desktop app, firmware or an SDK into the EU, the shipped artefact is the thing to look at. The free decision tree walks the question in about ten minutes. It does not answer it for you.

"We already have Dependabot."

Dependency alerts are not an SBOM, not an intake channel, and not a 24 hour process with a named person. The kit adds the three parts that are missing.

"We will do it when the platform opens."

The platform opens on 11 September 2026. The work that takes time is the intake channel and the named roles, not the form.

FAQ

What people ask before booking.

Screen share, your repos open. The SBOM workflow goes into your release pipeline and produces a CycloneDX file on a real tag. The intake form is wired to whatever queue or table you already use, with an email alert. The runbook gets filled in with your coordinating CSIRT, your named roles and your product list. Then one tabletop: a simulated report walked end to end, timed, so the 24 hour clock is something your team has already done once.
Book the install

Tell me what you ship and where it runs.

Two or three sentences: what the product is, which repositories build it, and whether anything today produces an SBOM. You get back a yes or a no on fit, a session slot, and the price you already read on this page.

Not legal or tax advice. This is process tooling. Whether your product is in scope, and which class it falls into, is your call with your own counsel.

By submitting, you agree to be contacted about your inquiry. No sales calls, no spam. 18-24h typical reply.

Prefer email or WhatsApp? omar@neurascale.org or +20 150 047 7334. Cairo (GMT+2), which covers EU mornings and afternoons.

Next step

The form is not the hard part. The channel and the named person are.

An SBOM on every release, an intake channel someone actually watches, and a runbook with your CSIRT and your roles filled in. One session.

18–24h reply · Cairo + EU hours · honest scoping