Vigil

EU Cyber Resilience Act — reporting obligations start September 11, 2026

EU Cyber Resilience Act · reporting starts Sept 11, 2026

The EU’s 24-hour reporting clock starts September 11.

Ship hardware or software into the EU? The Cyber Resilience Act now requires a working vulnerability-reporting process. Vigil delivers the whole setup — disclosure policy, SOPs, SBOM, and the step-by-step 24h/72h/14-day runbook — for one flat fee.

Icon

24h early warning

Icon

72h notification

Icon

14-day final report

About us

Vigil is a flat-fee documentation service for the EU Cyber Resilience Act. We build your vulnerability-reporting setup  disclosure policy, SOP, SBOM, and the 24-hour runbook  ready in days.

what changes

What changes on September 11

Three things become true for products with digital elements sold in the EU

01

Report in 24 hours — the cascade is law

Find an actively exploited vulnerability and you owe ENISA and your national CSIRT an early warning within 24 hours

Already shipping? Still applies

Fines up to €10M or 2% of turnover

Reporting clock

24h

24h

Image

02

Sept 11, 2026

03

Retroactive

04

€10M / 2%

deliverables

What Vigil delivers

Ready to publish, ready to file — built from the regulation’s text and ENISA guidance

CVD policy & security.txt

A coordinated vulnerability disclosure policy plus a published security.txt, so reporters can reach you

Vulnerability-handling SOP

The written procedure: who triages a report, who fixes, who files — and on what clock

SBOM (CycloneDX)

A machine-readable bill of materials from your repo, regenerated on every release

24h/72h/14-day runbook

The step-by-step reporting runbook with pre-drafted notification templates.

the pack

What’s in the pack

Reporting readiness

Sept 11, 2026

Image
Image

Six documents, one working process

Everything arrives filled in for your product and company — ready to publish, ready to file

Documents in the pack

6

6

Feature Image

CVD policy + security.txt

Vulnerability-handling SOP

image

SBOM from your repo

CycloneDX from your manifests — so a dependency CVE takes minutes to answer, not days

Reporting cascade

24h early warning

72h notification

14-day final report

The 24h / 72h / 14-day cascade

Provides real-time visibility into open, in-progress, and resolved threats, helping security teams track progress instantly

Days to final report

14

14

the deadline

Built for September 11, 2026

Scope memo

CVD policy

Handling SOP

SBOM

Runbook

Scope check

Shape
Shape

In scope

Edge case

Out of scope

Know where you stand

Six questions, two minutes, free. The scope checker gives you a straight answer — in scope, out, or edge case — plus your exact obligation dates

Reporting starts September 11

2026

Max penalty — 2% of turnover

€10M

pricing

One flat fee, three sizes

No subscriptions, no scope creep. The pack covers the September 2026 reporting obligations — the 2027 CE-conformity work is mapped out plainly in the included gap checklist.

$349

Readiness Pack

One product

Scope-determination memo

CVD policy + security.txt

Vulnerability-handling SOP

SBOM from your repo (CycloneDX)

24h/72h/14-day runbook + templates

Dec 2027 conformity gap checklist

Delivered in 3 business days

Get this pack

Get this pack

$649

Readiness Plus

Up to 5 products or repos

Everything in Readiness

Per-product scope memos

CI snippet — SBOM regenerated on every release

One written Q&A round with your pack

Get this pack

Get this pack

$899

Readiness + Retainer

Everything in Plus

12 months on call

Exploited vulnerability or severe incident?

We draft your 24h, 72h, and final filings with you

Get this pack

Get this pack

FAQ

Straight answers

Legal

Is this legal advice?

No. Vigil is a documentation and readiness service. We build your process artifacts from the regulation’s published text and ENISA guidance. For legal questions about your specific exposure, talk to counsel — our scope memo gives them a running start.

CE marking

Does this make my product CE-compliant?

No, and be wary of anyone who says a document pack can. Full conformity (Annex I, CE marking) lands December 11, 2027 and involves real security engineering. This pack covers the September 11, 2026 reporting obligations completely, and the included gap checklist shows exactly what 2027 will ask of you.

Deadlines

I already sell in the EU. Does the deadline still apply to me?

Yes. The reporting obligations are retroactive — they cover products already on the market, not just new launches. If your product is still sold or supported on September 11, 2026, the clock applies to you.

Reporting

What exactly do I have to report?

Two things: actively exploited vulnerabilities in your product, and severe incidents affecting its security. Each triggers the cascade — early warning in 24 hours, notification in 72, final report in 14 days (vulnerabilities) or a month (incidents) — filed to ENISA’s reporting platform and your national CSIRT. The runbook walks each step with the forms pre-drafted.

SBOM

What’s an SBOM and why do I need one?

A software bill of materials — a machine-readable list of every component and dependency in your product. It’s how you answer “are we affected?” in minutes instead of days when a dependency CVE drops, and it’s expected under the CRA’s vulnerability-handling requirements.

Open source

My product is mostly open source. Am I exempt?

Only if it’s outside commercial activity. The moment you charge for the product, support, or hosting, you’re a manufacturer under the CRA. Open-source stewards get a lighter regime — the scope checker walks that edge case.