A five-person software company in Cork sells a scheduling tool to builders' merchants. At twenty to seven on a Friday evening a customer forwards a screenshot: a stranger is reading other people's job sheets. From 11 September 2026 the clock starts the moment the firm becomes aware, and it runs 24 hours.
Awareness is the trigger, and a Friday evening counts.
What Article 14 asks for
Article 14 of the Cyber Resilience Act, Regulation (EU) 2024/2847, applies from 11 September 2026 to any manufacturer of a product with digital elements. Software counts, including software given away free of charge. An actively exploited vulnerability takes an early warning inside 24 hours, a notification inside 72, then a final report 14 days after a fix exists, under Article 14(2). A severe incident takes the same two steps, then a final report a month later, under Article 14(4). Both go simultaneously to the coordinating CSIRT and to ENISA, and both go through one platform.
Article 69(3) applies Article 14 to products already on the market before 11 December 2027. The installed base counts. Article 64(2) puts an Article 14 breach in the top tier, up to 15 million euro or 2.5 per cent of worldwide turnover.
Article 64(10) exempts microenterprises and small enterprises from the fines in paragraphs 3 to 9 for missing the early warning deadline. The Article 14 fine sits in paragraph 2, so how far that exemption reaches is a question for counsel.
The duty itself binds them either way, fine or no fine.
Reports travel through the single reporting platform ENISA builds under Article 16. It is not open yet. ENISA says it is scheduled to be operational by 11 September, reached through an EU Login account, and its guidance answers the automation question: no application programming interfaces at this stage. Ireland's National Cyber Security Centre states that only a notification through the platform satisfies the obligation.
One incident, three regimes
Francesco Capparelli set out the pinch in Agenda Digitale on 2 September. One event can produce three independent notifications from a single technical file. NIS2 gives an essential or important entity 24 hours, then 72, then a month, under Article 23(4), and GDPR Article 33(1) gives a controller 72 hours where personal data is involved. That moment of knowledge has to be settled once, in advance of the first alert.
Which body receives a NIS2 report depends on the country. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026. Dutch law is now in force. Elsewhere the national dates run: Poland's register closes on 3 October, Italy's basic security measures on 31 October.
The Cyber Resilience Act needs no transposition, so its date lands everywhere on the same day.
Before the eleventh
ComplianceSME publishes a Cyber Resilience Act system, A-006, at GBP 1,500, and a NIS2 system, A-003, at GBP 3,000.
In both systems the shape is the same.
Each trains the person who holds the duty, then interviews them against the verbatim text. The report states where the business stands article by article, produced inside the firm's own Claude account, with progress on the dashboard and the connector serving the same material.
Behind them sits the register: 115 toolkits featuring 3,262 compliance agents covering 9,904 catalogued obligations. Four things off it cost nothing: the free assessment, which returns only the obligations already reaching a business of that size and sector; the company law agents and the GDPR agents, both free for the United Kingdom and all 27 member states; and the free EU AI Act checker, which builds a duty card in about a minute.
Membership at GBP 500 a month keeps owned toolkits current as the law moves, and carries the Policy Shift briefing. It includes three Cross Border B2B Compliance Agent screenings. The Cork firm has one job before the eleventh: open an EU Login account, and write down who can file at two in the morning.
ComplianceSME research articles are available for republication in full, free of charge, with attribution. Requests to toolkit@compliancesme.com.
More from ComplianceSME
- What a cross-border deal costs an SME before anyone signs
- Europe Blamed the AI Act. The Delays Were Data Protection Law.
- The Two Rulebooks, the One Person, and the Answer That Is Already Out of Date
- The Delay Trap: EU AI Act Rules That Apply Now, and Every EU and UK Compliance Deadline Left in 2026
- Finally, compliance is not complicated
- ComplianceSME Completes the Free Business Compliance Libraries of All Twenty-Eight Nations
- Seven builders for every governor: Europe's compliance shortage has an answer already
- The policy moved. The archive did not.
- The Digital Omnibus deferral: what moved, what did not, and what applies now
Every claim and its source
The application date of 11 September 2026 for Article 14, 11 June 2026 for Chapter IV and 11 December 2027 for the remainder: Regulation (EU) 2024/2847, Article 71(2), Official Journal text. The two reporting streams, actively exploited vulnerabilities and severe incidents affecting the security of the product, and the duty to notify the CSIRT designated as coordinator and ENISA simultaneously via the single reporting platform: Regulation (EU) 2024/2847, Article 14(1), 14(3) and 14(7). The clocks of 24 hours, 72 hours and 14 days after a corrective or mitigating measure is available for the vulnerability stream, and 24 hours, 72 hours and one month after the notification for the incident stream: Regulation (EU) 2024/2847, Article 14(2)(a) to (c) and Article 14(4)(a) to (c). The definition of manufacturer covering products marketed under an operator's own name whether for payment, monetisation or free of charge, and of a product with digital elements covering software: Regulation (EU) 2024/2847, Article 3(13) and Article 3(1). Article 14 applying to products with digital elements placed on the market before 11 December 2027: Regulation (EU) 2024/2847, Article 69(3). Administrative fines of up to 15,000,000 euro or 2.5 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher, for non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14: Regulation (EU) 2024/2847, Article 64(2). The exemption as written, that by way of derogation from paragraphs 3 to 9 the administrative fines referred to in those paragraphs shall not apply to manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a): Regulation (EU) 2024/2847, Article 64(10)(a). The single reporting platform established and operated by ENISA, scheduled to be operational by 11 September 2026, reached through an EU Login account, with no application programming interfaces provided at this stage: Regulation (EU) 2024/2847, Article 16(1); ENISA single reporting platform pages and frequently asked questions, read 3 September 2026. Only a notification submitted through the single reporting platform satisfying the statutory reporting obligation: National Cyber Security Centre Ireland, Cyber Resilience Act reporting guidance, read 3 September 2026. The NIS2 clocks of 24 hours, 72 hours and one month under Article 23(4) of Directive (EU) 2022/2555, and the 72 hour notification to the supervisory authority under Article 33(1) of Regulation (EU) 2016/679; the referral of Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 for failure to notify complete transposition, the Dutch Cyberbeveiligingswet entering into force on 15 August 2026, the Polish register of key and important entities closing to applications on 3 October 2026 and the Italian basic security measures falling due on 31 October 2026: the two instruments; European Commission infringement decision of 8 July 2026; NCSC Netherlands; ComplianceSME compliance dates register, read 3 September 2026. One incident capable of starting three independent notification regimes, one technical file and three separate legal decisions: Francesco Capparelli, Agenda Digitale, 2 September 2026. The register of 115 toolkits featuring 3,262 compliance agents covering 9,904 catalogued obligations, the Cyber Resilience Act system at 1,500 pounds and the NIS2 system at 3,000 pounds, membership at 500 pounds a month with owned toolkits kept current, the Policy Shift briefing and three Cross Border B2B Compliance Agent screenings, the free assessment, the free EU AI Act checker, and the free company law and GDPR agents for the United Kingdom and each of the 27 member states: ComplianceSME published pages and catalogue of 1 September 2026, read 3 September 2026. Every claim above verified 3 September 2026, with the full claims register held on file.