CRA just days away: Are you ready?
- August 25, 2026
- Steve Rogerson
- Finite State

The biggest obstacle to ensuring compliance to the EU Cyber Resilience Act (CRA) is knowing what third-party software is embedded inside a product, according to Doc McConnell, head of policy and compliance at Finite State.
Effective worldwide and starting 11 September 2026, all manufacturers of goods shipped into the EU must notify the European Union’s ENISA agency for cyber security within 24 hours of any actively exploited vulnerability.
Most have focused on the CRA ultimate December 2027 deadline, but from next month manufacturers become newly accountable for digital resilience throughout the entire product lifecycle.
Within 24 hours of discovering any actively exploited vulnerability, they must notify ENISA and a designated computer incident response team. Within 72 hours, they owe a detailed follow-up notification, including a description of corrective action. Within 14 days, once a mitigation is available, they must submit a final report detailing the vulnerability and any exploitation of it.
“For many companies, the challenge isn’t simply reporting, it’s determining within a few hours whether a vulnerability exists inside their products, whether it’s being actively exploited, and who might be affected,” said McConnell, a former CISA branch chief and a former senior advisor for cyber-security policy with the US Office of Management & Budget.
He said the biggest obstacle was not paperwork but visibility.
“Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products,” he said. “Even more lack an in-place internal decision process to meet that 24-hour reporting mandate. The CRA readiness gap persists across sectors: ICS, automotive, medical devices, consumer electronics, IoT, IT gear, mobile applications distributed to EU end users, embedded software and more. And are their legal and compliance departments ready to assess cyber resilience?”
For more on Finite State, visit finitestate.io.









