The EU Cyber Resilience Act puts a clock on you the moment you become aware of an actively exploited vulnerability or a severe incident. 24 hours for the first report. 72 hours for the second. No grace period for finding out who's supposed to file it.
Legally binding from 11 September 2026, retroactive to products already on the market. Both triggers, an actively exploited vulnerability, or a severe incident, route through ENISA's Single Reporting Platform to your CSIRT coordinator, simultaneously.
| Stage | Deadline | What's Required |
|---|---|---|
| Early Warning | 24 hours | From the moment you become aware of the incident or the vulnerability the clock starts ticking. Vulnerability: which EU Member States the product is available in. Incident: the same, plus whether a malicious or unlawful cause is suspected. |
| Detailed Notification | 72 hours | Product info, nature of the exploit or vulnerability (or an initial severity assessment for incidents), corrective/mitigating measures taken and available to users, and how sensitive you consider the information. |
| Final Report | 14 days after fix / 1 month after resolution | Root cause, corrective measures, preventive measures. |
The prepared and resilient companies find out during a tabletop exercise, not during an incident, whether they can actually answer these. When do you want to find out?
Each builds on the last. TTX ONE (below) is free so you can read the full structure and run it on your own if you'd like. TTX TWO and TTX THREE go deeper into execution and crisis, and are built for organizations ready to move past discussion. ONE, TWO or THREE, Cranial Thunder is ready to put your team's processes to the test. Except for a real world incident or vulnerability... It's the only way to know if you are actually prepared.
Audience: Compliance, legal, product security lead, one executive sponsor. ~90 minutes, discussion-based, no real-time pressure.
Goal: Surface governance and awareness gaps before they surface during a real incident.
Discussion Points:
It closes with a single soft inject: a one-paragraph vulnerability report from an outside researcher. The only question that matters: is this reportable, who decides, and what's the first thing that actually happens in your building?
Audience: Cross-functional across security ops, legal, comms, engineering, your SRP submitter, exec sponsor. Half-day.
One realistic scenario, played across the full lifecycle: an ambiguous signal, confirmed exploitation, the 24-hour warning drafted under real time pressure, new facts landing right at the 72-hour deadline, and the 14-day final-report clock that resets when your fix ships... not when you first noticed.
Audience: Full incident command, executives, legal, comms, possibly board-level observers. Full day, high pressure.
Everything TTX TWO doesn't cover: platform outages, shared components with OEM partners, a parallel GDPR or NIS2 notification running on a different timeline, and a press leak that beats your own user notification out the door. You can run TTX ONE on your own for free, or Cranial Thunder can facilitate to ensure you don't just "assume" the answers. Let's make sure you have them documented, agreed upon, and get the questions about the process answered before the incident, not during it.
That's what TTX ONE is for. Most organizations don't know until they're in the room.
Schedule a TTX TableTop@CranialThunder.com