
By Thomas Cohen, founder of Maestro
Cyber Resilience Act: reporting obligations from September 11, 2026, explained
Tomorrow, the European cyber resilience regulation opens its first binding chapter: reporting exploited vulnerabilities. What the text requires, whom it applies to, and why the question changes when your software is an internal tool.
Cyber Resilience Act reporting obligations apply from September 11, 2026, according to the European Commission's official regulation page. The same page recalls that the text entered into force on December 10, 2024, while its main obligations apply from December 11, 2027.
What the regulation covers
The Commission describes a broad scope: baby monitors to smartwatches, applications to computer programs, connectable hardware and software. The regulation imposes cybersecurity requirements on manufacturers across planning, design, development and maintenance, and provides CE marking to attest compliance. Free and open-source software receives particular treatment because of its place in the chain, without the page detailing exemptions. Whether your product falls within scope is decided with legal counsel, and the answer often depends on a contractual detail rather than the software's nature.
Who bears the obligation
The text targets whoever places a product on the market, not whoever uses it. The obligation targets the software vendor, not the practice buying and using it. The distinction becomes interesting when a business owner commissions a tool and wonders which side they are on. An internal tool, never sold or distributed, follows a different logic from a product offered to customers. Between them lies a grey area only legal advice resolves: an application made available to franchisees, a module resold with a service, access offered to customers within a subscription. Many owners discover they publish software when they charge for it.
What the Commission's page does not say
Specialist press cites reporting deadlines of 24 hours, 72 hours and 14 days. The Commission's page does not mention them, and we could not read the regulation as a direct source. We therefore leave them out rather than repeat them, even if that means fewer details than other articles this week. What is established fits in one sentence: from September 11, 2026, a manufacturer within scope must report exploited vulnerabilities in its product, including products delivered before that date. The rest, including the precise countdown, should be checked in the regulation with your adviser.
The real issue for a business owner
Reporting requires two capabilities few small organisations possess: knowing a vulnerability is exploited and knowing who fixes it. An application built over a few evenings with a generator, published and forgotten provides neither. Nobody monitors, nobody maintains the list of bundled components, and code ownership arises at the worst moment. We detailed it in what remains in your hands when a tool closes: without code and the document describing it, an urgent fix becomes weeks of work, and the person capable of doing it is not always reachable in August.
A more elementary version of the problem can be checked in two minutes: a database left open will not wait until 2027 to cost you dearly. Access rules are also the wall most rapid-generation tools hit, as this morning's comparison shows across two very different platforms. A product that never had requirements also never had a written list of who accesses what.
In practice, this week
Three lines establish where you stand. One: write whether your software leaves the business, sold, distributed or made available, or remains internal. Two: name the person who alerts you when a vulnerability is reported in a bundled component, with a first name rather than a department. Three: state where the code lives and how you would apply a fix without awaiting a platform's agreement. Take the answers and the scope question to your adviser. At Maestro, code and documents stay on your Mac, answering the third line and that line alone: product compliance remains the responsibility of whoever places it on the market, and no tool assumes it for you.