The EU Cyber Resilience Act puts a clock on you the moment you become aware of an actively exploited vulnerability or a severe incident. 24 hours for the first report. 72 hours for the second. No grace period for finding out who's supposed to file it.
Legally binding from 11 September 2026, retroactive to products already on the market. Both triggers — an actively exploited vulnerability, or a severe incident — route through ENISA's Single Reporting Platform to your CSIRT coordinator, simultaneously.
| Stage | Deadline | What's Required |
|---|---|---|
| Early Warning | 24 hours | From the moment you become aware. Which Member States the product reaches; for incidents, whether malicious or unlawful cause is suspected. |
| Detailed Notification | 72 hours | Product info, nature of the exploit or vulnerability, mitigating measures taken and available to users, and how sensitive you consider the information. |
| Final Report | 14 days after fix / 1 month after resolution | Root cause, corrective measures, preventive measures. |
Most companies find out during a tabletop exercise, not before one, whether they can actually answer these.
Each builds on the last. TTX1 is open — read the full structure below. TTX2 and TTX3 go deeper into execution and crisis, and are built for organizations ready to move past discussion.
Audience: Compliance, legal, product security lead, one executive sponsor. ~90 minutes, discussion-based, no real-time pressure.
Goal: Surface governance and awareness gaps before they surface during a real incident.
What gets discussed in the room:
It closes with a single soft inject — a one-paragraph vulnerability report from an outside researcher. The only question that matters: is this reportable, who decides, and what's the first thing that actually happens in your building?
Audience: Cross-functional — security ops, legal, comms, engineering, your SRP submitter, exec sponsor. Half-day.
One realistic scenario, played across the full lifecycle: an ambiguous signal, confirmed exploitation, the 24-hour warning drafted under real time pressure, new facts landing right at the 72-hour deadline, and the 14-day final-report clock that resets when your fix ships — not when you first noticed.
Audience: Full incident command, executives, legal, comms, possibly board-level observers. Full day, high pressure.
Everything TTX2 doesn't cover: a reporting platform outage mid-window, a shared component that puts an OEM partner's clock on the line too, a parallel GDPR or NIS2 notification running on a different timeline, and a press leak that beats your own user notification out the door.
That's what TTX1 is for. Most organizations don't know until they're in the room.
Schedule a TTX TableTop@CranialThunder.com