Could You File an Incident Report in 24 Hours? Test It This Month
From 11 September 2026, Article 14 of the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours, a final report within 14 days. The financial sector has worked to a similar rhythm since DORA. The question for August is simple: could your team file within 24 hours, on a weekend, in English?
Three regimes, one clock
The CRA deadlines run from the moment the manufacturer becomes aware. Reports go through the single reporting platform operated by the CSIRTs and ENISA, and the reporting duty arrives more than a year before the rest of the regulation, which applies from 11 December 2027.
Financial entities know the discipline already. DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and requires an initial notification, an intermediate report and a final report for major ICT-related incidents. In Poland, essential and important entities under the amended National Cybersecurity System Act (KSC) have their own incident reporting duties, which must be operational, together with the connection to the S46 system, by 3 April 2027. Three regimes, three forms, one shared feature: the clock starts before anyone feels ready.
Friday, 22:00
Picture the test case. On Friday at 22:00 a researcher writes to your support inbox: a vulnerability in your device firmware is being exploited in the wild. Twenty-four hours from awareness means Saturday evening. Who decides whether this is reportable under the CRA? Who drafts the early warning? Who approves it while the head of legal sits on a plane? Where are the contact details and access data for the reporting platform stored, and does the person on call know that location?
Teams that run this exercise hit the same walls. The lawyer is unreachable. The template exists only in Polish, and nobody trusts their legal English at midnight. Nobody has defined where “severe” begins, so the debate about whether to report at all consumes the first twelve hours.
A drill that fits one afternoon
Finding these gaps takes three hours and a one-page scenario. Bring engineering, legal, communications and the duty manager to one table. Walk through the sequence: who declares the incident reportable, who writes, who approves, where the platform contacts sit, which fields the form requires. One person logs every question that gets no answer. That log is the deliverable.
Then close the gaps and repeat the run before 11 September.
What we recommend now
- Book a three-hour fire drill within the next two weeks and invite engineering, legal, communications and the on-call manager.
- Write a one-page decision card: what triggers a CRA, DORA or KSC report in your organisation, and who decides when the first choice is unreachable.
- Prepare early warning and 72-hour notification templates in English and Polish, with the factual fields pre-structured.
- Store platform contacts, access data and a deputy list where the on-call team can reach them at 22:00 on a Friday.
- After the drill, fix the three worst gaps first, then put the repeat run in the calendar.
Sources: European Commission: CRA reporting · Regulation (EU) 2024/2847 (CRA) · gov.pl: amended KSC Act