From 11 September the clock is running. And it runs for 24 hours.

- Client
- anonymised
- Industry
- Machinery and plant engineering, DACH region
- Period
- April to September 2026
- Framework
- Regulation (EU) 2024/2847, aligned with IEC 62443
Starting point
Anyone placing connected products on the market falls under the Cyber Resilience Act. From 11 September 2026 the reporting obligations of Article 14 apply: actively exploited vulnerabilities and severe security incidents must be reported to the responsible CSIRT and to ENISA at the same time — in stages, with very short deadlines.
- 24 h Early warning to the CSIRT and ENISA via the Single Reporting Platform
- 72 h Detailed report: product affected, nature of the exploitation, measures taken
- 14 days Final report once the fix is available; one month in the case of security incidents
Approach
First a gap analysis against the requirements of the regulation: which products are affected, what is missing in terms of structures, processes and evidence. On top of that a cyber risk assessment on a real plant project rather than a textbook example — risks, impacts, measures, documented and repeatable. The gaps became an action plan with owners and deadlines.
Able to report within 24 hours
Setting up an incident response team with named roles, availability and decision-making authority — plus the process behind it: from the incoming report through assessment to reporting on time. The initial assessment of whether a report is relevant at all can be supported by AI — around the clock, without an on-call rota at first contact.
Security in development
SecDev and SecDevOps: security requirements from the risk assessment move into development, dependencies and the supply chain become traceable, vulnerability management runs across the entire support period instead of stopping at delivery.
The real thing, rehearsed once
To conclude, a tabletop exercise: an actively exploited vulnerability, reported on a Friday afternoon. That is exactly where a process on paper shows what it cannot show otherwise — who is reachable, who is allowed to decide, when the clock starts running and how customers are informed while no fix is available yet. The gaps from the exercise went back into the process before they would have surfaced in a real incident.
Whether an incoming report is relevant at all can be pre-assessed by AI today — around the clock, without an on-call rota. The team still has to respond: deciding, reporting and fixing stay with people who have the authority.