Library Header Image Library Header Image

The 24-Hour Test: Is Cybersecurity Ready for the Cyber Resilience Act?


Posted on by Tuhin Banerjee

Key Takeaways
  • September 11, 2026, is an operating-speed test, not a paperwork deadline. The Cyber Resilience Act’s (CRA's) 24-hour early warning and 72-hour main notification requirements test how fast an organization can decide, not just what it eventually reports.
  • Vulnerability management alone no longer cuts it. Organizations need vulnerability intelligence, the ability to contextualize a CVE against affected products, versions, customers, and exposure in real time.
  • AI can accelerate the decision, but it cannot own it. AI can correlate signals faster than any analyst, but accountability for a reporting decision must remain with accountable humans.

The Deadline Is Not the Real Story

The Cyber Resilience Act entered into force in December 2024 and establishes cybersecurity requirements for hardware and software products with digital elements made available on the EU market. Its broader requirements become applicable in December 2027, but the reporting obligations under Article 14 begin much earlier, on September 11, 2026.

Under those obligations, manufacturers must notify the appropriate CSIRT and ENISA about actively exploited vulnerabilities and severe incidents affecting the security of their products. The timelines are intentionally aggressive:

  • Within 24 hours: early warning
  • Within 72 hours: main notification
  • Within 14 days after a corrective or mitigating measure becomes available: final report for actively exploited vulnerabilities
  • Within one month of the 72-hour notification: final report on severe incidents

That is not simply compliance. That is an operating model.

An Uncomfortable Question: How Fast Can Your Organization Actually Decide?

Most organizations have invested heavily in vulnerability management. They scan, prioritize, patch, and monitor. They run security operations centers and maintain product security and incident response teams. Yet many still struggle with a deceptively simple question: when a critical vulnerability appears, who actually has the authority to decide what happens next? The problem isn't that ecosystem teams lack expertise. The problem is coordination. A 24-hour reporting requirement does not leave much room for organizational ambiguity.

What Happens When AI Enters the Picture?

AI can help compress the time between discovery and decision. That is powerful. But it raises a new governance question: what happens when the AI gets it wrong?

It may misjudge reportability, incorrectly correlate vulnerability with a product, misjudge exploitability, or generate a perfectly convincing explanation for an incorrect conclusion.

That creates an important principle for the AI-enabled CRA era. Because AI can accelerate cybersecurity decisions. It cannot transfer accountability to the AI, Marina Bregkou, Principal Research Analyst, Cloud Security Alliance stated "build in human supervision, especially for the moments when the model fails silently or gets tricked." Human oversight remains essential for consequential regulatory decisions. The objective should be intelligent, evidence-driven decision support with accountable human governance.

Three Questions Every Security Leader Should Ask Now

1, Can we identify an affected product quickly enough?

If the answer requires several spreadsheets, email chains, and meetings, the organization probably has a visibility problem.

2. Can we make a defensible reporting decision within 24 hours?

May not eventually. That requires clear ownership, decision rights, escalation paths, and evidence.

3. Can we prove what happened six months later?

If the answer is no, the organization may have a compliance problem, but more importantly, it has a resilience problem. 

the Reporting Obligations Deadline Should Be Treated

There is one practical exercise every organization should run before the deadline: take a realistic scenario, an actively exploited vulnerability discovered in a component used by one of your products and start the timer.

  • Hour 0: Vulnerability identified
  • Hour 1: Security begins assessment
  • Hour 4: Product exposure identified
  • Hour 8: Exploitation confirmed
  • Hour 12: Business impact assessed
  • Hour 16: Reporting decision made
  • Hour 20: Notification reviewed
  • Hour 24: Early warning submitted

That exercise will probably reveal more than another compliance checklist, because resilience is not something you declare. It is something you test.

The Cyber Resilience Act is not simply raising the bar for compliance. It is raising the bar for operational cyber resilience. Organizations that prepare only to meet the reporting deadline may achieve compliance. Organizations that build the ability to discover, contextualize, decide, report, remediate, and prove will be better prepared for the next vulnerability, the next incident, and the next generation of cybersecurity regulation. Compliance gets you to the deadline. Resilience prepares you for what happens next.

Contributors
Tuhin Banerjee

Senior Director, Saviynt Inc.

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs