A staggered deadline, not a cliff
On September 11, 2026, the EU's Cyber Resilience Act (CRA) switches on its first binding obligation: manufacturers of "products with digital elements" sold into the EU must report actively exploited vulnerabilities and severe security incidents to ENISA and the relevant national CSIRT through the Single Reporting Platform — an early warning within 24 hours of becoming aware, a fuller technical notification within 72 hours, and a final report within 14 days (for exploited vulnerabilities) or one month (for severe incidents). Crucially, per Article 69(3), this applies to products already on the market, not just new ones — a smart TV or industrial sensor sold in 2019 is in scope if it's still shipping today.
The CRA's heavier lift — CE-marking, security-by-design, a five-year default support-and-patching window — doesn't bind until December 11, 2027. That fifteen-month gap between reporting duties and full essential-requirements enforcement is itself a proportionality choice: it lets manufacturers build incident-response muscle before they're asked to redesign products. Regulators rarely get credit for staggering deadlines sensibly; this is a case where they did.
What the July 27 guidance actually adds
Six weeks before that first deadline, on July 27, 2026, the European Commission published its first official interpretive guidance on applying the CRA — an 80-page document built around 67 practical examples, plus flowcharts and use-case diagrams, with microenterprises and SMEs explicitly named as the priority audience. It works through the questions manufacturers actually ask: when does a "remote data processing solution" (cloud backends, companion apps) pull a hardware product into scope; when is free and open-source software caught versus exempt; what counts as a "substantial modification" that resets conformity assessment; and how the default five-year support period should be read against a product's realistic use life. MLex reported the guidance is explicitly framed around "practical examples intended to ease compliance, particularly for small and medium-sized businesses."
That SME framing matters because the CRA, unlike GDPR, offers no revenue-based carve-out — a two-person Tallinn IoT startup faces the same reporting clock as Siemens. The guidance is non-binding, so it creates no legal safe harbor, but it does substantially narrow the interpretive risk that a small manufacturer misreads scope and either over- or under-reports.
Estonia's compliance-retrofit economy
That interpretive gap has already become a business line. Proekspert, a Tallinn-based industrial software engineering firm, sells CRA-retrofit services to European manufacturers — bringing legacy connected products up to the CRA's and IEC 62443's security bar entirely through software, without touching hardware. It's a plausible niche for Estonia: a country that built its entire state-services model on centralized digital identity and mandatory incident-reporting discipline has a comparative advantage in explaining reporting obligations to manufacturers who have never had one. Estonia's Information System Authority (RIA) — the same body that runs the national CSIRT under NIS2 — describes the CRA as extending baseline cybersecurity requirements across the entire product lifecycle for IoT and other connected devices, consistent with the domestic security posture Estonia has run since its early 2000s digital government build-out. Tallinn also hosts NATO's Cooperative Cyber Defence Centre of Excellence, which has long made cyber hygiene a matter of national identity as much as commercial compliance — the CRA compliance-services market is a natural, if modest, extension of that posture.
The steelman, and why it still holds up
The case for mandatory reporting is genuinely strong and shouldn't be waved away as bureaucratic overreach. Connected-device vendors have historically had no consistent legal duty to disclose exploited vulnerabilities to anyone but their own customers, and often not even that; the information asymmetry falls entirely on downstream users and national CSIRTs who can't see incidents they aren't told about. A harmonized, EU-wide 24-hour clock closes that gap and gives ENISA and member-state CSIRTs a single early-warning channel instead of 27 fragmented ones. That's a legitimate public-safety rationale, not a make-work rule.
Where proportionality still gets tested is timing and readiness, not the underlying duty. Guidance landing six weeks before a hard deadline is workable but tight for the SMEs it's aimed at — reading an 80-page interpretive document, mapping it against your own product line, and standing up a reporting workflow in six weeks is a real compliance sprint, even with 67 worked examples to shortcut it. The Commission deserves credit for front-loading interpretive clarity rather than leaving manufacturers to guess; the better long-term fix is publishing this kind of guidance a full compliance cycle ahead of each milestone, not a matter of weeks — a cadence worth locking in before the heavier December 2027 essential-requirements deadline arrives. Estonia's compliance-services sector is, in effect, privately absorbing some of that timing risk on the Commission's behalf; that's a sign the law is workable, not that it's broken.