← All resources

Cyber Resilience Act: ANSSI briefs manufacturers (23/09/2026)

Published September 30, 2026 · 7 min read · CyberNovaLabs.io

One official event, two deadlines and a reporting platform that is already live. Here is what the Cyber Resilience Act changes for an SME that sells software, resells hardware under its own brand, or simply buys both.

The short version

On 23 September 2026, France's cybersecurity agency ANSSI, the national frequency agency ANFR and the Directorate General for Enterprise brought manufacturers of digital products and conformity assessment bodies together in Paris around the Cyber Resilience Act[1]. Two dates now frame the calendar: since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents; by 11 December 2027 every product with digital elements placed on the EU market must meet the essential requirements of the regulation[1][2]. The head of ANSSI described the text as the digital equivalent of basic public health precautions[1].

The Cyber Resilience Act is not only about large vendors

Many directors read the name and move on, convinced it targets smartphone makers. The regulation covers products with digital elements: software, applications, connected devices, hardware that receives updates[2]. You are a manufacturer if you place such a product on the EU market under your own name or brand.

In practice: a ten-person software vendor, an integrator reselling a gateway under its own label, a machine builder shipping a control app, a studio publishing a mobile app for its clients. No revenue threshold removes the status of manufacturer. On 27 July 2026 the Commission published practical guidance to help manufacturers, developers and businesses of all sizes meet their obligations[2]. Read that before you buy consultancy.

The two deadlines, and what they impose

DateWhat appliesWho is concerned
10 December 2024Regulation entered into forceEveryone
11 September 2026Reporting of actively exploited vulnerabilities and severe incidentsManufacturers
11 December 2027Essential requirements of the regulation; reporting duties for open-source software stewards (Article 24(3))Manufacturers and open-source stewards

Sources: European Commission[2][3] and ANSSI[1]. The first deadline has already passed. It does not wait for the second.

Reporting a vulnerability: one single desk since 11 September

Reporting goes through a single place: the Single Reporting Platform set up by ENISA under Article 16 of the regulation, operational since 11 September 2026[3]. Three clocks govern the procedure: an early warning within 24 hours of becoming aware, a full notification within 72 hours, then a final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability, and within a month of the 72-hour notification for a severe incident[3].

The notification is addressed to the CSIRT of the country where you have your main establishment and is made available to ENISA at the same time; that CSIRT shares it without delay with the other CSIRTs in countries where the product is available[3]. Operational translation: 24 hours means a lost Friday evening if nobody is on call and nobody internally knows who is allowed to file. The weak point in an SME is almost never the technology, it is the decision chain.

Who enforces, in the four countries

Market surveillance is national, and national authorities will enforce the rules; CE marking will indicate compliance with the regulation[2]. France made its split public on 23 September: ANFR supervises digital products made available on the national market, analyses products, and can require corrections, go as far as withdrawing a product, or impose high financial penalties; ANSSI acts as notifying authority, assessing, monitoring and notifying conformity assessment bodies, and as national CSIRT under the regulation[1].

For Belgium, the Netherlands and Luxembourg, assume nothing: the split between product surveillance authority and coordinating CSIRT does not necessarily match the names you know from NIS2. Ask in writing before you need it, to the CCB in Belgium, to RDI and NCSC-NL in the Netherlands, to ILR in Luxembourg, and file the answer in your compliance folder. If NIS2 is already on your desk, our sector notes on NIS2 in Belgium for healthcare, hospitals and labs and on NIS2 in the Netherlands for transport and logistics set out two separate regimes with two separate desks. Our wider cybersecurity pages and the country overview for NIS2 in the Netherlands follow the same logic.

What if you buy software rather than sell it?

Then the regulation works for you, provided you turn it into a purchasing criterion rather than a forgotten contract clause. Three questions are enough to sort your suppliers today: for how many years will you ship security fixes for this product? Through which channel, and within what delay, will you tell me about an actively exploited vulnerability? Where do you stand on the 11 December 2027 deadline?

A supplier who answers in writing on one page costs you less than an audit. A supplier who does not answer has already told you something. And if your core tool is custom built, the answer sits with your development partner: this is settled in the contract, not after the incident. See our approach to custom software development for the criteria to put in the specification.

To do this week

  • List the products you sell under your own brand that contain software or connect to a network. That list decides whether you are a manufacturer.
  • Name the person who files a report, plus a deputy, and record where the access to ENISA's reporting platform is kept[3].
  • Write the procedure on one page: who qualifies a vulnerability as actively exploited, who drafts the 24-hour early warning, who signs off the 72-hour notification.
  • Read the guidance published by the Commission on 27 July 2026 before spending on consultancy[2].
  • Write to your national authority to obtain, in writing, the applicable desk and coordinating CSIRT.
  • Add the three supplier questions above to your next contract renewals.

At CyberNovaLabs.io

We work in the Netherlands, Belgium, France and Luxembourg, and we see the same blind spot in SMEs across the four: product compliance is treated as a technical topic when it is first an organisational and contractual one. If you sell a digital product, or have your core tool built for you, we map the products in scope, the reporting procedure and the supplier clauses with you, without selling you an audit you do not need. Book thirty minutes with us.

Sources

  1. ANSSI — CRA : l'ANSSI, l'ANFR et la DGE accompagnent les fabricants dans la conformité des produits numériques (publié le 23/09/2026)
  2. Commission européenne — Cyber Resilience Act (page mise à jour le 07/09/2026)
  3. Commission européenne — Cyber Resilience Act : obligations de signalement et plateforme unique de l'ENISA (consulté le 30/09/2026)
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked