If you ship software: CRA and NIS2

Cyber Resilience Act

If you ship software, a 24 hour reporting clock starts in September 2026

Most coverage points at December 2027. The duty that bites first arrives fifteen months earlier, and it reaches backwards over everything already in customers' hands.

By Oscar CobbeCurrent as at 9 minute read4 sources

The date that matters is September, not December

Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. Article 71 then staggers it across three dates, and almost every summary written for Irish businesses quotes only the last one.

The essential requirements, conformity assessment and CE marking do arrive on 11 December 2027. That is the date worth planning a product roadmap around. It is not the date that creates your first legal obligation.

Article 14, the reporting duty, applies from 11 September 2026. From that morning, an actively exploited vulnerability in a product you manufacture has to be reported to your coordinating CSIRT and to ENISA within 24 hours.

WhatApplies fromArticle
The notified body framework11 June 2026Chapter IV
Reporting exploited vulnerabilities and severe incidents11 September 2026Article 14
Essential requirements, conformity assessment, CE marking11 December 2027Article 71

It applies to what you have already shipped

Article 69(2) grandfathers products placed on the market before 11 December 2027 out of the product requirements. Article 69(3) then expressly takes the reporting duty out of that grandfathering. Every version already in a customer's hands is in scope from September, whatever it was built against, and whether or not you still sell it.

Whether it reaches you is not the question you think

The scope test catches people out in both directions, so it is worth doing properly rather than assuming.

Article 2(1) covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Article 3(1) defines that as a software or hardware product and its remote data processing solutions.

Recital 12 puts standalone cloud services outside it: cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within scope. Regulation (EU) 2025/327 later says the same thing in enacted text rather than in a recital, stating that the Act does not cover Software as a Service directly as such.

So if everything you run lives on your servers and your customer only ever opens a browser, the Cyber Resilience Act is not your regime. NIS2 may well be, if you are medium sized or larger, but that is a different set of duties with a different regulator.

Then Article 3(2) pulls a backend back in. A remote data processing solution means software designed and developed by or under the responsibility of the manufacturer, the absence of which would prevent the product from performing one of its functions. Recital 11 gives the example outright: a mobile application requiring access to an API or a database provided by a service the manufacturer developed.

The practical consequence is the part worth writing down. Ship a mobile app, a desktop client, a browser extension, an on-premise agent, firmware or a separately distributed library, and you are in. The backend that app depends on comes in with you, even though the same backend on its own would have been outside.

There is no small company exemption

This is the assumption that costs people the most time. Article 2 contains no turnover threshold and no headcount exemption. A four-person company in Galway shipping a desktop application is a manufacturer under this Regulation on exactly the same terms as a multinational.

The relief that does exist for smaller manufacturers is procedural rather than substantive, and it is worth knowing precisely because it is narrower than people hope.

  1. 1Article 33(5) allows micro and small enterprises to provide simplified technical documentation.
  2. 2Article 32(6) provides for a reduction in conformity assessment fees.
  3. 3Article 64(10)(a) carves microenterprises and small enterprises out of fines for the 24 hour early warning, and for that filing alone. The 72 hour notification and the final report carry no such relief.

The carve-out is one filing, not the duty

Article 64(10)(a) is frequently read as meaning small companies do not have to report. It means a microenterprise or small enterprise cannot be fined for missing the 24 hour early warning specifically. The obligation to file it still exists, and everything after it is enforceable in the normal way.

What the clocks actually are

There are two of them and they are not the same. Both start on 11 September 2026, both require three filings rather than one, and the final report runs from a different point in each.

An actively exploited vulnerability means one being exploited in the wild, not one you found in review. A severe incident means one affecting the product's ability to protect sensitive data or functions, or one that led to malicious code running in the product or in a user's systems.

Filings go to the coordinating CSIRT and to ENISA simultaneously, through the single reporting platform. In Ireland the coordinating CSIRT is the National Cyber Security Centre.

StageExploited vulnerabilitySevere incident
Early warning24 hours from becoming aware24 hours, saying whether it looks malicious
Notification72 hours, with what it is and what has been done72 hours
Final report14 days after a fix is availableOne month from the notification

What to do before September

The duty is a reporting duty, so what it needs from you is not a security programme. It needs somebody who knows the clock has started, a way of finding out that a vulnerability is being exploited, and a filing route that already exists before it is needed at three in the morning.

The honest version of the preparation is short, and it is short on purpose: a company that spends six months on this before September has misread what applies in September.

  1. 1Establish whether you are in scope at all. If you ship nothing and your customers only use a browser, you are outside the Act and the rest of this does not apply to you.
  2. 2Write down which of your products are in scope, including versions you no longer sell. Article 69(3) reaches those too.
  3. 3Name the person who owns the 24 hour clock, and a deputy. A duty with a named owner is a duty that gets filed.
  4. 4Register with the single reporting platform and read the form before you need it.
  5. 5Have a way of learning that something of yours is being exploited: a monitored security contact address at minimum, and a route for a researcher to reach a human.

This is scoping, not a security audit

The question September asks is which conversation you are in. Deciding that takes an afternoon, and for a good number of Irish software companies the answer is that the Act does not reach them at all, which is worth knowing with certainty rather than assuming in either direction.

Sources

  1. 1.Regulation (EU) 2024/2847, the Cyber Resilience Act: Articles 14, 69 and 71 · Official Journal of the European Union
  2. 2.Regulation (EU) 2025/327 on the European Health Data Space, recitals on CRA scope · Official Journal of the European Union
  3. 3.The Cyber Resilience Act, overview and timeline · European Commission
  4. 4.National Cyber Security Centre · Government of Ireland

Five questions and this page says whether it reaches you

The free Cyber Resilience Act check runs the scope test in the order the Regulation does, tells you which duties follow and which article each one comes from, and prints as a document you can hand to a board or a customer. The answers stay in this tab, and an account is never needed.

Run the free check

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on If you ship software: CRA and NIS2

Written on 27 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.