If you ship software, this starts in September
The Cyber Resilience Act makes reporting a live vulnerability a 24 hour job from 11 September 2026, and it covers what you have already shipped. Five questions and this page says whether it reaches you. The answers stay in this tab unless you ask us to email you the result, and an account is never needed.
FourWinds Digital · fourwindsdigital.com
Cyber Resilience Act check
Regulation (EU) 2024/2847
A scoping result produced from the answers given on the page. It says which conversation you are in. It is not legal advice, and it is current as at the date it was printed.
This is a scoping result worked out from your own answers. It tells you which conversation you are in. It is not legal advice, and it is not a determination that you comply.
What was answered
Optional, and nothing in the answer depends on it. It goes onto the result if you print it, so the document says which product it was run for.
Answer all five and the answer appears here.
Keep this result
Save it as a PDF or print it. It carries your own answers, the duties that follow from them and the article each one comes from, so it is something you can hand to a board, a client or a procurement team. Printing sends nothing anywhere and we never see it.
Why this one catches people out
Two reasons. The scope test does not match how anybody describes their own business: browser-only software is outside the Act, but ship a mobile app and the backend it talks to comes in with it. And the September date is fifteen months ahead of the requirements it relates to, so a product built long before any of this applied is still one whose vulnerabilities have to be reported on a clock.
Ireland has not yet named a market surveillance authority for it. That changes who chases you, not what is due.
Running AI rather than shipping software? The AI Act transparency check is the other one with a date on it.
Talk to us about the reporting process