September 11, 2026 might sound like just another date on a compliance calendar, but if you buy or sell connected hardware in the EU, it's the day a new set of rules actually starts to bite. That's when the Cyber Resilience Act's reporting rules become legally binding — more than a year before the law's bigger deadlines arrive.
Why the Reporting Rules Come First
The CRA became law on 10 December 2024, but it doesn't all apply at once. Reporting duties come first, in September 2026, because regulators want early warning about active attacks and serious incidents before the bigger CE-marking rules land in December 2027.
If you buy LoRaWAN gateways, sensors, or other connected hardware, this matters: how a vendor handles reporting today tells you a lot about how seriously they're taking the rest of the law.
| Date | What happens |
|---|---|
| 10 Dec 2024 | The Cyber Resilience Act enters into force |
| 11 Sep 2026 | Reporting obligations become binding; the CRA Single Reporting Platform is meant to go live |
| 11 Dec 2027 | Full CRA obligations apply, including CE marking of connected products |
What Manufacturers Must Report, and How Fast
Once the rule kicks in, manufacturers must report actively exploited vulnerabilities and serious incidents on a tight schedule.
| Step | Vulnerabilities | Serious incidents |
|---|---|---|
| Early warning | Within 24 hours | Within 24 hours |
| Full report | Within 72 hours | Within 72 hours |
| Final report | Within 14 days | Within 1 month |
These reports go through the CRA Single Reporting Platform, set up under Article 16 and run by ENISA together with the EU's national CSIRT teams. That platform is also meant to be up and running by 11 September 2026 — the same day the reporting rules start — with a testing period before that.
Why This Matters Even Before Your Own Deadline
If you buy IoT hardware, you're not directly bound by CRA reporting rules — manufacturers are. But your procurement team still carries risk, the same way NIS2 compliance questions already shape purchases for critical infrastructure. Asking about reporting now costs you nothing and lowers your risk before the real deadline hits.
What Good Vendor Practice Looks Like Today
Before September 2026 arrives, ask vendors simple questions.
shopioT doesn't claim to be CRA-certified — no such certification exists yet — but we stay in close contact with our gateway and sensor manufacturers about firmware advisories, and our team can walk B2B buyers through what we know about a product's security. Read more on our about page, check our FAQ page, or contact us directly with security questions. For more on how EU rules affect IoT buyers, see our industry insights blog.
Preparing Your Own Procurement Process
Whatever stage your current vendors are at, you can get ahead on your own: keep a list of every connected device you use and who makes it, ask new vendors directly about their CRA reporting plans, and get in the habit of checking for firmware security advisories instead of assuming everything's fine.
September 2026 is a manufacturer deadline, but it's also a good moment for you to check your own supply chain before the much bigger December 2027 deadline arrives.
Frequently Asked Questions
What actually happens on 11 September 2026?
Manufacturers must start reporting actively exploited vulnerabilities and serious incidents, and the CRA Single Reporting Platform is meant to go live.
What are the mandatory reporting deadlines once an issue is detected?
A first warning within 24 hours, a full report within 72 hours, and a final report within 14 days for vulnerabilities or one month for serious incidents.
Who receives these reports?
Reports go through the CRA Single Reporting Platform under Article 16, run by ENISA with the EU's CSIRT network.
Is this the same as the CRA's main compliance deadline?
No. The main CRA rules and CE marking start on 11 December 2027. September 2026 only covers reporting.
Is shopioT or CyRIC “CRA-certified”?
There's no formal CRA certification to hold yet. Ask any vendor directly about their plan for the 2027 deadline instead.
An Early Test Worth Taking Seriously
The September 2026 deadline is easy to overlook next to the bigger 2027 milestone, but it's a useful early test of how ready your vendors really are. Ask the right questions now, and December 2027 will be a lot less stressful.
Questions About a Product's Security Posture?
The shopioT engineering team helps B2B buyers assess firmware advisories and vendor readiness before they order — and ships hardware pre-configured for your network.