An open maintenance register on an electronics workbench beside an open enclosure and screwdriver

September 10, 2026 · 5 min read

By Thomas Cohen, founder of Maestro

Cyber Resilience Act: reporting obligations from September 11, 2026, explained

Tomorrow, the European cyber resilience regulation opens its first binding chapter: reporting exploited vulnerabilities. What the text requires, whom it applies to, and why the question changes when your software is an internal tool.

Cyber Resilience Act reporting obligations apply from September 11, 2026, according to the European Commission's official regulation page. The same page recalls that the text entered into force on December 10, 2024, while its main obligations apply from December 11, 2027.

December 10, 2024the regulation enters into force (European Commission)
September 11, 2026reporting obligations apply
December 11, 2027main obligations apply

What the regulation covers

The Commission describes a broad scope: baby monitors to smartwatches, applications to computer programs, connectable hardware and software. The regulation imposes cybersecurity requirements on manufacturers across planning, design, development and maintenance, and provides CE marking to attest compliance. Free and open-source software receives particular treatment because of its place in the chain, without the page detailing exemptions. Whether your product falls within scope is decided with legal counsel, and the answer often depends on a contractual detail rather than the software's nature.

Who bears the obligation

The text targets whoever places a product on the market, not whoever uses it. The obligation targets the software vendor, not the practice buying and using it. The distinction becomes interesting when a business owner commissions a tool and wonders which side they are on. An internal tool, never sold or distributed, follows a different logic from a product offered to customers. Between them lies a grey area only legal advice resolves: an application made available to franchisees, a module resold with a service, access offered to customers within a subscription. Many owners discover they publish software when they charge for it.

What the Commission's page does not say

Specialist press cites reporting deadlines of 24 hours, 72 hours and 14 days. The Commission's page does not mention them, and we could not read the regulation as a direct source. We therefore leave them out rather than repeat them, even if that means fewer details than other articles this week. What is established fits in one sentence: from September 11, 2026, a manufacturer within scope must report exploited vulnerabilities in its product, including products delivered before that date. The rest, including the precise countdown, should be checked in the regulation with your adviser.

The real issue for a business owner

Reporting requires two capabilities few small organisations possess: knowing a vulnerability is exploited and knowing who fixes it. An application built over a few evenings with a generator, published and forgotten provides neither. Nobody monitors, nobody maintains the list of bundled components, and code ownership arises at the worst moment. We detailed it in what remains in your hands when a tool closes: without code and the document describing it, an urgent fix becomes weeks of work, and the person capable of doing it is not always reachable in August.

A more elementary version of the problem can be checked in two minutes: a database left open will not wait until 2027 to cost you dearly. Access rules are also the wall most rapid-generation tools hit, as this morning's comparison shows across two very different platforms. A product that never had requirements also never had a written list of who accesses what.

In practice, this week

Three lines establish where you stand. One: write whether your software leaves the business, sold, distributed or made available, or remains internal. Two: name the person who alerts you when a vulnerability is reported in a bundled component, with a first name rather than a department. Three: state where the code lives and how you would apply a fix without awaiting a platform's agreement. Take the answers and the scope question to your adviser. At Maestro, code and documents stay on your Mac, answering the third line and that line alone: product compliance remains the responsibility of whoever places it on the market, and no tool assumes it for you.

Back to the journal

Take the baton.

Leave your email to try Maestro in the first waves.

The beta opens in waves. People on the list try it first, and Maestro stays free throughout the beta.

The beta is currently available on macOS 13 or later. Your answer helps us plan other versions.

Your email is only used to let you know when access opens. Nothing else, we promise.