EU Cyber Resilience Act · reporting starts Sept 11, 2026
The EU’s 24-hour reporting clock starts September 11.
Ship hardware or software into the EU? The Cyber Resilience Act now requires a working vulnerability-reporting process. Vigil delivers the whole setup — disclosure policy, SOPs, SBOM, and the step-by-step 24h/72h/14-day runbook — for one flat fee.

About us
Vigil is a flat-fee documentation service for the EU Cyber Resilience Act. We build your vulnerability-reporting setup — disclosure policy, SOP, SBOM, and the 24-hour runbook — ready in days.
what changes
What changes on September 11
Three things become true for products with digital elements sold in the EU
01
Report in 24 hours — the cascade is law
Find an actively exploited vulnerability and you owe ENISA and your national CSIRT an early warning within 24 hours
Already shipping? Still applies
Fines up to €10M or 2% of turnover
Reporting clock
24h
24h

02
Sept 11, 2026
03
Retroactive
04
€10M / 2%
deliverables
What Vigil delivers
Ready to publish, ready to file — built from the regulation’s text and ENISA guidance
CVD policy & security.txt
A coordinated vulnerability disclosure policy plus a published security.txt, so reporters can reach you
Vulnerability-handling SOP
The written procedure: who triages a report, who fixes, who files — and on what clock
SBOM (CycloneDX)
A machine-readable bill of materials from your repo, regenerated on every release
24h/72h/14-day runbook
The step-by-step reporting runbook with pre-drafted notification templates.
the pack
What’s in the pack
Reporting readiness
Sept 11, 2026

Six documents, one working process
Everything arrives filled in for your product and company — ready to publish, ready to file
Documents in the pack
6
6

CVD policy + security.txt
Vulnerability-handling SOP

SBOM from your repo
CycloneDX from your manifests — so a dependency CVE takes minutes to answer, not days
Reporting cascade

24h early warning
72h notification
14-day final report
The 24h / 72h / 14-day cascade
Provides real-time visibility into open, in-progress, and resolved threats, helping security teams track progress instantly
Days to final report
14
14
the deadline
Built for September 11, 2026
Scope memo
CVD policy
Handling SOP
SBOM
Runbook
Scope check
In scope
Edge case
Out of scope
Know where you stand
Six questions, two minutes, free. The scope checker gives you a straight answer — in scope, out, or edge case — plus your exact obligation dates
Reporting starts September 11
2026
Max penalty — 2% of turnover
€10M
pricing
One flat fee, three sizes
No subscriptions, no scope creep. The pack covers the September 2026 reporting obligations — the 2027 CE-conformity work is mapped out plainly in the included gap checklist.
$349
Readiness Pack
One product
Scope-determination memo
CVD policy + security.txt
Vulnerability-handling SOP
SBOM from your repo (CycloneDX)
24h/72h/14-day runbook + templates
Dec 2027 conformity gap checklist
Delivered in 3 business days
Get this pack
Get this pack
$649
Readiness Plus
Up to 5 products or repos
Everything in Readiness
Per-product scope memos
CI snippet — SBOM regenerated on every release
One written Q&A round with your pack
Get this pack
Get this pack
$899
Readiness + Retainer
Everything in Plus
12 months on call
Exploited vulnerability or severe incident?
We draft your 24h, 72h, and final filings with you
Get this pack
Get this pack
FAQ
Straight answers
Legal
Is this legal advice?
No. Vigil is a documentation and readiness service. We build your process artifacts from the regulation’s published text and ENISA guidance. For legal questions about your specific exposure, talk to counsel — our scope memo gives them a running start.
CE marking
Does this make my product CE-compliant?
No, and be wary of anyone who says a document pack can. Full conformity (Annex I, CE marking) lands December 11, 2027 and involves real security engineering. This pack covers the September 11, 2026 reporting obligations completely, and the included gap checklist shows exactly what 2027 will ask of you.
Deadlines
I already sell in the EU. Does the deadline still apply to me?
Yes. The reporting obligations are retroactive — they cover products already on the market, not just new launches. If your product is still sold or supported on September 11, 2026, the clock applies to you.
Reporting
What exactly do I have to report?
Two things: actively exploited vulnerabilities in your product, and severe incidents affecting its security. Each triggers the cascade — early warning in 24 hours, notification in 72, final report in 14 days (vulnerabilities) or a month (incidents) — filed to ENISA’s reporting platform and your national CSIRT. The runbook walks each step with the forms pre-drafted.
SBOM
What’s an SBOM and why do I need one?
A software bill of materials — a machine-readable list of every component and dependency in your product. It’s how you answer “are we affected?” in minutes instead of days when a dependency CVE drops, and it’s expected under the CRA’s vulnerability-handling requirements.
Open source
My product is mostly open source. Am I exempt?
Only if it’s outside commercial activity. The moment you charge for the product, support, or hosting, you’re a manufacturer under the CRA. Open-source stewards get a lighter regime — the scope checker walks that edge case.