Two Triggers. Three Deadlines. One Platform.

Legally binding from 11 September 2026, retroactive to products already on the market. Both triggers — an actively exploited vulnerability, or a severe incident — route through ENISA's Single Reporting Platform to your CSIRT coordinator, simultaneously.

StageDeadlineWhat's Required
Early Warning 24 hours From the moment you become aware. Which Member States the product reaches; for incidents, whether malicious or unlawful cause is suspected.
Detailed Notification 72 hours Product info, nature of the exploit or vulnerability, mitigating measures taken and available to users, and how sensitive you consider the information.
Final Report 14 days after fix / 1 month after resolution Root cause, corrective measures, preventive measures.

The Questions That Matter

Most companies find out during a tabletop exercise, not before one, whether they can actually answer these.

Three Exercises, One Escalating Track

Each builds on the last. TTX1 is open — read the full structure below. TTX2 and TTX3 go deeper into execution and crisis, and are built for organizations ready to move past discussion.

TTX1 — "Are You Ready?"

Orientation • Governance

Audience: Compliance, legal, product security lead, one executive sponsor. ~90 minutes, discussion-based, no real-time pressure.
Goal: Surface governance and awareness gaps before they surface during a real incident.

What gets discussed in the room:

  • Whether you're the manufacturer of record for each in-scope product line
  • Whether you know your CSIRT coordinator and have (or plan to have) SRP access
  • Whether a named decision-owner exists for the reportability call
  • A cold read of three hypothetical scenarios — reportable or not?
  • Whether your Sept 2026 scoping is accidentally pulled toward the December 2027 Article 13 requirements, or missing them entirely where it shouldn't

It closes with a single soft inject — a one-paragraph vulnerability report from an outside researcher. The only question that matters: is this reportable, who decides, and what's the first thing that actually happens in your building?

TTX2 — "Can You Actually Do It?"

Functional • Process Test

Audience: Cross-functional — security ops, legal, comms, engineering, your SRP submitter, exec sponsor. Half-day.

One realistic scenario, played across the full lifecycle: an ambiguous signal, confirmed exploitation, the 24-hour warning drafted under real time pressure, new facts landing right at the 72-hour deadline, and the 14-day final-report clock that resets when your fix ships — not when you first noticed.

Full inject sequence and facilitator materials shared during scoping.

TTX3 — "When It's Really Going Wrong"

Crisis • Cascading

Audience: Full incident command, executives, legal, comms, possibly board-level observers. Full day, high pressure.

Everything TTX2 doesn't cover: a reporting platform outage mid-window, a shared component that puts an OEM partner's clock on the line too, a parallel GDPR or NIS2 notification running on a different timeline, and a press leak that beats your own user notification out the door.

Scenario design is built around your product, your geography, and your actual partners.

Not Sure Which One You Need?

That's what TTX1 is for. Most organizations don't know until they're in the room.

Schedule a TTX TableTop@CranialThunder.com
No phone. No sales team. One expert. Direct access.