localproblems.orgvol. 2026 · no. 33
P-0016

Czech hardware, IoT and software vendors must report actively exploited vulnerabilities within 24 hours from 11 Sep 2026, and small ISVs have no product-security function to do it

Category
Legal
Locality
Czechia · national
Updated
Created
Sources
03
Proof0/3UNPROVEN

no foreign analog.

Money0/2UNFUNDED

no budget attached.

Urgency3/3FORCING

compliance date <18mo (forcing function live) (2/2); newest source < 90 days (1/1).

S1 · reg-cra-reporting · reg-scan · EU · 2026-09-11Cyber Resilience Act — 24-hour vulnerability reporting

Cyber Resilience Act (Reg. 2024/2847) requires manufacturers of products with digital elements (incl. software) to report actively exploited vulnerabilities and severe incidents to ENISA/CSIRTs within 24h from 11 Sep 2026, with full security-by-design and CE-marking obligations from 11 Dec 2027; creates demand for vulnerability-handling processes, SBOM tooling, secure-development audits and reporting automation.

reg-cra-reporting: Cyber Resilience Act (Reg. 2024/2847) — manufacturers of products with digital elements (incl. software) must report actively exploited vulnerabilities and severe incidents to ENISA/CSIRT within 24h from 11 Sep 2026; full security-by-design and CE-marking obligations 11 Dec 2027. Fines up to EUR 15m or 2.5% of global turnover. Deadline <1 month at record creation.

S3 · reg-pld-software-liability · reg-scan · EU · 2026-12-09Product Liability Directive — software strict liability

New Product Liability Directive (EU) 2024/2853: transposition by 9 Dec 2026; software, SaaS and AI systems become 'products' under strict no-fault liability, and defectiveness explicitly includes missing security updates. Every CZ software vendor placing products on the market after that date carries liability exposure that current T&Cs don't address.

reg-pld-software-liability: new Product Liability Directive (2024/2853), transposition by 9 Dec 2026 — software/SaaS/AI become 'products' under strict no-fault liability and defectiveness explicitly includes missing security updates. The same small ISVs now carry liability exposure on top of the CRA reporting duty; CRA artifacts (SBOMs, update policies) double as liability defense.

Demand0/2ASSUMED

pain assumed, not documented.

S2 · news · 2026-06-03news — crowell.com

Law-firm countdown alert confirming the 11 Sep 2026 reporting deadline; EC CRA reporting page (digital-strategy.ec.europa.eu/en/policies/cra-reporting) confirms Art 14 timing.

Gap0/2UNCHECKED

CZ incumbent check not done.

Total03/12FAINT

score = proof + money + urgency + demand + gap · every point is justified by a source on file · bands: PRIME 10–12 · STRONG 8–9 · FAIR 5–7 · FAINT 0–4

The problem

From 11 September 2026 — weeks away at record creation — every Czech manufacturer of products with digital elements sold in the EU, explicitly including software vendors, must report actively exploited vulnerabilities and severe incidents to ENISA/CSIRT within 24 hours under the Cyber Resilience Act. The signal notes this hits every CZ hardware, IoT and software vendor, including small ISVs that have no product-security function, no PSIRT, and no process capable of a 24-hour regulatory clock. Fines reach EUR 15m or 2.5% of global turnover.

Why now: the Article 14 reporting obligation lands more than a year before the CRA's full security-by-design and CE-marking regime (11 December 2027), so firms that assume they have until end-2027 are exposed next month. The December 2027 wall then requires SBOMs, secure development evidence and conformity assessment — a much larger lift with scarce assessment capacity.

Who pays: product companies — from IoT device makers to B2B software houses — buying CRA readiness assessments, SBOM/VEX generation tooling, PSIRT-as-a-service and reporting workflow automation. For small ISVs, an outsourced PSIRT retainer is the realistic form factor.

Existing non-solutions: general security consultancies without product-regulatory depth; nothing CZ-specific was verified this cycle (no gap check, gap 0), and no demand receipt documents Czech vendors complaining yet — awareness is likely the first product.

The low score reflects strict scoring (only the deadline is receipted), not low stakes; a demand probe among Czech IoT/ISV firms and a gap check on CZ PSIRT-as-a-service offerings are the obvious next steps.

Added 2026-08-13: the new Product Liability Directive (transposition 9 Dec 2026) makes software a product under strict no-fault liability, with missing security updates an explicit defect. For the same small-ISV audience this converts CRA compliance from a regulatory checkbox into liability defense material — two legal regimes now point at the identical missing product-security function.

Sources

  1. Cyber Resilience Act — 24-hour vulnerability reporting
  2. news — crowell.com
  3. Product Liability Directive — software strict liability