Manufacturers who ship anything with a digital component inside it now face one of the tightest reporting deadlines in European product regulation. Since 11 September 2026, the Cyber Resilience Act (CRA) obliges them to flag actively exploited vulnerabilities and serious security incidents to authorities within a single day.
The two-step process gives firms 24 hours to file an early warning, followed by a full report at the 72-hour mark. Submissions run through the Single Reporting Platform (CRA-SRP) operated by ENISA, the EU’s cybersecurity agency. In Germany, the national recipient is CERT-Bund, part of the Federal Office for Information Security (BSI). Which member state a company answers to depends on where its EU headquarters sits.
The price of getting it wrong is steep. Software vendor JFrog warns that CRA breaches can draw fines of up to €15 million or 2.5% of worldwide annual turnover. Under the separate NIS2 directive, managers can be held personally liable — a risk that extends as far as temporary bans from
Compliance tools multiply as pressure builds
Against that regulatory squeeze, a wave of vendors is positioning software to help smaller businesses keep up. Munich-based neonotu GmbH has launched Sightadel, a platform built specifically for the regulatory needs of small and medium-sized enterprises. The company employs 25 people across sites in Munich, Tarifa and Tallinn, and says the software was developed in the EU and runs exclusively on German infrastructure.
Sightadel’s selling point is cross-framework mapping. A single security measure — rolling out multi-factor authentication, for instance — can simultaneously serve as evidence of compliance with ISO 27001, NIS2, SOC 2 and the GDPR. The platform manages ISO 27001, ISO 9001, NIS2, DORA, GDPR, C5, NIST CSF 2.0 and SOC 2 side by side, and bundles an ISO 27001 information security management system (ISMS) complete with a central Statement of Applicability (SoA). A real-time security score and a trust centre give customers an ongoing read on their own security posture.
JFrog has taken a different route, extending its AppTrust product with what it calls “DevGovOps” features that push governance rules and controls automatically into the release pipeline.
Practitioners warn that paperwork alone won’t hold
At a specialist panel in Berlin, industry figures sketched out what the new duties mean in practice. Luise Werner of secuvera described the reporting obligations as a genuine stress test for corporate security organisations, one that forces risk analysis, development and vulnerability management to work in close lockstep. Eric Clausing of AV-TEST pointed out that a product can look secure on paper yet prove attackable in daily use — which is why independent testing offers a valuable extra perspective.
Partnerships are forming elsewhere in the market too. Kertos GmbH, with offices in Munich and Berlin, and Belgium’s Aikido Security agreed a strategic tie-up in September 2026. Joint sales mean vulnerability findings from Aikido can be fed directly into Kertos as compliance evidence for ISO 27001, SOC 2 and NIS2. Kertos covers standards including the EU AI Act, TISAX, GDPR and C5, while Aikido Security says more than 150,000 teams already use its tools.
Help for suppliers caught in the slipstream
Firms that are only indirectly affected — suppliers, for example — can turn to a free tool. Deutschland sicher im Netz (DsiN) and the University of Paderborn have added a supply-chain check to the FitNIS2 Navigator at fitnis2.de, designed to make it clear whether a company falls in scope. The project is funded under the Federal Ministry for Economic Affairs and Energy’s “IT Security in Business” initiative.
Two further dates sit on the autumn calendar. On 23 September 2026, SBC Systems will present LEGANTA, an integrated platform that merges contracts and risks into a single model — useful, for example, for assessing whether a given contract carries NIS2 relevance. Then on 17 November 2026, IBF Solutions hosts an online conference on the Cyber Resilience Act in mechanical engineering, with a VDMA representative explaining how harmonised standards interact. Attendance costs €790 plus VAT.
