Czech hardware, IoT and software vendors must report actively exploited vulnerabilities within 24 hours from 11 Sep 2026, and small ISVs have no product-security function to do it
- Category
- Legal
- Locality
- Czechia · national
- Updated
- Created
- Sources
- 03
no foreign analog.
no budget attached.
compliance date <18mo (forcing function live) (2/2); newest source < 90 days (1/1).
Cyber Resilience Act (Reg. 2024/2847) requires manufacturers of products with digital elements (incl. software) to report actively exploited vulnerabilities and severe incidents to ENISA/CSIRTs within 24h from 11 Sep 2026, with full security-by-design and CE-marking obligations from 11 Dec 2027; creates demand for vulnerability-handling processes, SBOM tooling, secure-development audits and reporting automation.
reg-cra-reporting: Cyber Resilience Act (Reg. 2024/2847) — manufacturers of products with digital elements (incl. software) must report actively exploited vulnerabilities and severe incidents to ENISA/CSIRT within 24h from 11 Sep 2026; full security-by-design and CE-marking obligations 11 Dec 2027. Fines up to EUR 15m or 2.5% of global turnover. Deadline <1 month at record creation.
New Product Liability Directive (EU) 2024/2853: transposition by 9 Dec 2026; software, SaaS and AI systems become 'products' under strict no-fault liability, and defectiveness explicitly includes missing security updates. Every CZ software vendor placing products on the market after that date carries liability exposure that current T&Cs don't address.
reg-pld-software-liability: new Product Liability Directive (2024/2853), transposition by 9 Dec 2026 — software/SaaS/AI become 'products' under strict no-fault liability and defectiveness explicitly includes missing security updates. The same small ISVs now carry liability exposure on top of the CRA reporting duty; CRA artifacts (SBOMs, update policies) double as liability defense.
pain assumed, not documented.
Law-firm countdown alert confirming the 11 Sep 2026 reporting deadline; EC CRA reporting page (digital-strategy.ec.europa.eu/en/policies/cra-reporting) confirms Art 14 timing.
CZ incumbent check not done.
score = proof + money + urgency + demand + gap · every point is justified by a source on file · bands: PRIME 10–12 · STRONG 8–9 · FAIR 5–7 · FAINT 0–4
The problem
From 11 September 2026 — weeks away at record creation — every Czech manufacturer of products with digital elements sold in the EU, explicitly including software vendors, must report actively exploited vulnerabilities and severe incidents to ENISA/CSIRT within 24 hours under the Cyber Resilience Act. The signal notes this hits every CZ hardware, IoT and software vendor, including small ISVs that have no product-security function, no PSIRT, and no process capable of a 24-hour regulatory clock. Fines reach EUR 15m or 2.5% of global turnover.
Why now: the Article 14 reporting obligation lands more than a year before the CRA's full security-by-design and CE-marking regime (11 December 2027), so firms that assume they have until end-2027 are exposed next month. The December 2027 wall then requires SBOMs, secure development evidence and conformity assessment — a much larger lift with scarce assessment capacity.
Who pays: product companies — from IoT device makers to B2B software houses — buying CRA readiness assessments, SBOM/VEX generation tooling, PSIRT-as-a-service and reporting workflow automation. For small ISVs, an outsourced PSIRT retainer is the realistic form factor.
Existing non-solutions: general security consultancies without product-regulatory depth; nothing CZ-specific was verified this cycle (no gap check, gap 0), and no demand receipt documents Czech vendors complaining yet — awareness is likely the first product.
The low score reflects strict scoring (only the deadline is receipted), not low stakes; a demand probe among Czech IoT/ISV firms and a gap check on CZ PSIRT-as-a-service offerings are the obvious next steps.
Added 2026-08-13: the new Product Liability Directive (transposition 9 Dec 2026) makes software a product under strict no-fault liability, with missing security updates an explicit defect. For the same small-ISV audience this converts CRA compliance from a regulatory checkbox into liability defense material — two legal regimes now point at the identical missing product-security function.