# From 11 September the clock is running. And it runs for 24 hours.

> Gap analysis, cyber risk assessment, incident response team and process for a machinery and plant manufacturer — including a tabletop exercise for the real thing.

- URL: https://www.radigsol.at/en/references/eu-cra-incident-reporting
- Language: en
- Publisher: RaDigSol e.U., Neustift im Stubaital, Tirol, Österreich
- Client: anonymised
- Industry: Machinery and plant engineering, DACH region
- Period: April to September 2026
- Framework: Regulation (EU) 2024/2847, aligned with IEC 62443
- Services: Gap analysis · Cyber risk assessment · Incident response team · SecDev/SecDevOps · Tabletop exercise
- Published: 2026-09-04

Machine-readable Markdown version of this page. The HTML version is available at the URL above.

## Starting point

Anyone placing connected products on the market falls under the Cyber Resilience Act. From 11 September 2026 the reporting obligations of Article 14 apply: actively exploited vulnerabilities and severe security incidents must be reported to the responsible CSIRT and to ENISA at the same time — in stages, with very short deadlines.

- **24 h** — Early warning to the CSIRT and ENISA via the Single Reporting Platform
- **72 h** — Detailed report: product affected, nature of the exploitation, measures taken
- **14 days** — Final report once the fix is available; one month in the case of security incidents

## Approach

First a gap analysis against the requirements of the regulation: which products are affected, what is missing in terms of structures, processes and evidence. On top of that a cyber risk assessment on a real plant project rather than a textbook example — risks, impacts, measures, documented and repeatable. The gaps became an action plan with owners and deadlines.

### Able to report within 24 hours

Setting up an incident response team with named roles, availability and decision-making authority — plus the process behind it: from the incoming report through assessment to reporting on time. The initial assessment of whether a report is relevant at all can be supported by AI — around the clock, without an on-call rota at first contact.

### Security in development

SecDev and SecDevOps: security requirements from the risk assessment move into development, dependencies and the supply chain become traceable, vulnerability management runs across the entire support period instead of stopping at delivery.

## The real thing, rehearsed once

To conclude, a tabletop exercise: an actively exploited vulnerability, reported on a Friday afternoon. That is exactly where a process on paper shows what it cannot show otherwise — who is reachable, who is allowed to decide, when the clock starts running and how customers are informed while no fix is available yet. The gaps from the exercise went back into the process before they would have surfaced in a real incident.

> Whether an incoming report is relevant at all can be pre-assessed by AI today — around the clock, without an on-call rota. The team still has to respond: deciding, reporting and fixing stay with people who have the authority.
>
> — Christoph Ranalter, RaDigSol e.U.

## Contact

- E-mail: contact@radigsol.at
- Phone: +43 5226 39851
- Address: Obergasse 49/2, 6167 Neustift im Stubaital, Austria
- LinkedIn: https://www.linkedin.com/company/radigsol/

## This page in other languages

- Deutsch: https://www.radigsol.at/referenzen/eu-cra-meldefaehigkeit
- Italiano: https://www.radigsol.at/it/referenze/eu-cra-capacita-di-notifica

## All pages

- [RaDigSol](https://www.radigsol.at/en)
- [AI Literacy Training](https://www.radigsol.at/en/ai-literacy-training)
- [AI Solutions & Automation](https://www.radigsol.at/en/ai-solutions-automation)
- [AI Consulting & Software Consulting from Tyrol](https://www.radigsol.at/en/ai-consulting-software-consulting-tyrol)
- [AI Officer as a Service](https://www.radigsol.at/en/ai-officer-as-a-service)
- [AI Governance & EU AI Act Consulting](https://www.radigsol.at/en/ai-governance-eu-ai-act)
- [Software Development](https://www.radigsol.at/en/software-development)
- [Product Security, Compliance & EU CRA](https://www.radigsol.at/en/product-security-eu-cra)
- [Your partner for digital AI transformation from the Tyrolean Alps](https://www.radigsol.at/en/about)
- [References](https://www.radigsol.at/en/references)
- [Imprint](https://www.radigsol.at/en/imprint)
- [Privacy policy](https://www.radigsol.at/en/privacy)
- [General Terms and Conditions - RaDigSol e.U.](https://www.radigsol.at/en/terms)
