The Cyber Resilience Act at Two Weeks: What’s Actually Ready, and What Isn’t

Two weeks before Article 14 reporting becomes mandatory, the infrastructure behind it is still under construction. The Commission’s guidance is approved but not yet formally in force. The reporting platform is in testing, not live. Not one harmonised standard has a citation in the Official Journal.
Each of those gaps puts more weight on the one control that’s fully in your hands regardless of what Brussels, ENISA, or the standards bodies do next: knowing what’s actually running in your environment, and whether it’s being exploited. That’s what OPENVAS is built to answer.
Not sure where your CRA reporting readiness stands?
Talk to Greenbone about your specific timeline and evidence trail.
The Commission’s guidance is out
On 27 July 2026, the European Commission approved its first formal guidance on applying the CRA: Communication C(2026) 5252 final, with a full Annex covering scope, free and open-source software, substantial modifications, support periods, and reporting obligations. Article 26 of the Regulation requires exactly this: guidance aimed squarely at helping microenterprises and SMEs comply, and the Annex delivers, with 67 worked examples.
Formal adoption follows once every EU-language version is ready. Here’s the Commission’s own language on that point: the guidance “will be formally adopted by the Commission at a later date, when all language versions are available. It is only from that moment that it will apply.” The content is locked in. The paperwork catches up.
Classification depends on your product’s actual core functionality, not its name or its marketing copy. The FOSS carve-outs work the way the draft guidance signalled earlier this year. We’ve covered the open-source provisions in detail in a separate post, since what counts as a “steward” and what that role obligates you to do deserves its own treatment.
The guidance existing removes any excuse for treating CRA compliance as theoretical. The Commission has said, in writing, what the rules mean, on a timeline that runs alongside the Regulation’s own staged applicability: Chapter IV since 11 June 2026, Article 14 reporting from 11 September 2026, full application from 11 December 2027.
Summary: Guidance
Approved — pending translation
Adopted in substance 27 July 2026. Formally applies once every EU-language version is ready.
The reporting platform is still being tested
Article 14 reporting obligations become legally binding on 11 September 2026, two weeks from now. ENISA’s Single Reporting Platform is scheduled to be operational by that date, ENISA’s own wording, not necessarily before it. The European Commission’s reporting-obligations page confirms functional and security testing are under way right now. ENISA will publish the platform’s dedicated URL once it’s ready, not before.
Onboarding guidance for registering as an “Assigned Representative” has been rolling out since 31 July, with updates continuing into late August. CSIRT validation of your registered representative runs in parallel with reporting, not as a gate. Cross-border information sharing between CSIRTs is automatic once a report lands. ENISA’s own advice is to register when you have an actual notification to file, not before.
A platform scheduled to be operational by the day it becomes mandatory, still in testing two weeks out, leaves little to no buffer for onboarding friction. Read the registration steps now. Know the notification process before you ever need to run it under a 24-hour clock.
Summary: Reporting platform
In testing
Functional and security testing under way now. Scheduled to be operational by 11 September 2026, not necessarily before.
The standards manufacturers were counting on aren’t published yet
As of late August 2026, no CRA harmonised standard has a reference in the Official Journal, for any product category. The underlying mandate is clear: standardisation request M/606, 41 standards across horizontal and vertical categories, accepted by CEN, CENELEC and ETSI under Commission Implementing Decision C(2025) 618 final of 3 February 2025.
The original deadlines split into three tracks. Type A, the framework principles that don’t carry presumption of conformity on their own, and the vulnerability-handling half of Type B were due 30 August 2026. Type C, the vertical, product-specific standards for Annex III and IV categories, was due 30 October 2026. A third date sits further out: 30 October 2027, for the other half of Type B, the cross-product standard meant to concretise the 13 essential requirements in Annex I, Part 1, the one most manufacturers outside Annex III and IV would actually rely on for presumption of conformity. That date comes from the CRA Expert Group’s own planning, as described by a member of the CRA Expert Group. It has not appeared in a published Commission decision.
The Commission published a draft amendment to the 2026 deadlines in early July 2026, pushing the Type A, vulnerability-handling, and Type C dates back roughly two months: 31 October 2026 and 31 December 2026. Whether the 2027 date for the other half of Type B shifts too is not confirmed either way. That amendment has not been formally adopted, and it is not yet in the Official Journal (draft Implementing Decision; CRA Evidence).
On the ground: 17 ETSI vertical drafts are under public enquiry, with comment periods closing between mid-September and mid-November. CEN and CENELEC’s horizontal standards are still in development.
For manufacturers of “important” class I products (VPNs, password managers, browsers, and similar categories) planning to self-assess against a published harmonised standard, there is nothing to point to yet, and the standard most of them would actually reach for, the cross-product Type B standard covering all 13 Annex I essential requirements, is not due until 2027 regardless of how the 2026 delay resolves.
Chapter IV opened the door for member states to formally designate conformity assessment bodies on 11 June 2026. The Commission’s own target for sufficient notified-body capacity is December 2026, and it describes that target explicitly as best-efforts, not a guarantee. Designation started three months ago. Build your assessment timeline around that.
The standards shortcut is delayed. The notified-body route is a system still ramping up. Plan for both.
Neither gap has to freeze your own preparation. The documentation, risk assessment, and vulnerability management work that any self-assessment or third-party audit will eventually check doesn’t wait on either route opening. OPENVAS builds that groundwork now: a daily-updated feed, CVSS-based prioritisation, and exportable, timestamped scan history, the same evidence trail a notified body or a future harmonised standard will expect to see.
Summary: Standards
Not yet published
No harmonised standard has a citation in the Official Journal yet. The 2026 deadlines may still slip by roughly two months.
What this means for you
None of the above is a reason to wait. It’s the opposite. The parts of the CRA that depend on the Commission, ENISA, or the European standards bodies are still in motion. The parts that depend on you, knowing what’s in your product estate, detecting active exploitation, producing a dated evidence trail on demand, are entirely in your hands today.
The Commission’s guidance defines “becoming aware,” the trigger for your 24-hour reporting clock, precisely: a manufacturer is deemed aware once, after assessing a suspicious event, it reaches a reasonable degree of certainty that a vulnerability is being actively exploited. That standard is explicitly modeled on the GDPR’s breach-notification threshold. You reach that certainty through active monitoring. There’s no retroactive reporting duty for vulnerabilities you already knew about before 11 September.
Raise this with whoever owns budget: continuous vulnerability management is the one part of this compliance picture fully within your control today. It’s what turns “we think we’re fine” into a dated evidence trail a regulator or notified body can actually check. OPENVAS delivers exactly that: scheduled scanning against a daily-updated feed, CVSS-based prioritisation, and exportable, timestamped reports that stand on their own, independent of any government platform’s launch schedule.
There’s a faster layer on top of that baseline, too. OPENVAS SECURITY INTELLIGENCE ingests CSAF advisories from trusted sources, vendors and national security bodies, for exactly the products in your estate, and correlates them against your software inventory to flag which advisories actually apply to you. When a 24-hour reporting clock starts, that’s the difference between checking a dozen vendor advisory pages by hand and having the analysis already sitting in one place.
Summary
The Commission’s guidance is approved in substance and will formally apply once translation is complete. The reporting platform manufacturers are supposed to use is still in testing, two weeks before it becomes mandatory. The harmonised standards that were meant to give manufacturers a self-assessment shortcut aren’t in the Official Journal yet, and neither the delay nor the notified-body capacity picture is fully settled. None of that changes what’s due on 11 September, or what “becoming aware” requires of you starting that day.
OPENVAS gives you the part of this you don’t have to wait on: a daily-updated vulnerability feed, CVSS-based prioritisation, and exportable, timestamped scan reports that document your detection posture regardless of what the regulatory infrastructure looks like on day one.
Not sure where your CRA reporting readiness stands?
Talk to Greenbone about your specific timeline and evidence trail.
Read the full guide: The Complete Guide to the EU Cyber Resilience Act — all requirements, timelines, and penalties in one place.



