As the EU’s Cyber Resilience Act takes effect this week, manufacturers are racing to establish evidence of their cybersecurity measures, with Finite State’s technology providing crucial support for rapid reporting of vulnerabilities and incidents.
The European Union’s Cyber Resilience Act is moving from policy to practice this week, with its first reporting duty taking effect on 11 September 2026. For manufacturers selling connected products into the bloc, that means the question is no longer whether the law applies, but whether they can prove quickly enough if a product in the field contains an actively exploited weakness and whether it is safe to disclose it within the required window. According to Finite State, firms using its platform already have the evidence needed to respond at speed.
The reporting regime is strict. The European Commission says manufacturers must file an early warning within 24 hours of becoming aware of an actively exploited vulnerability or serious incident, followed by a fuller notification within 72 hours and a final report within 14 days of a corrective measure becoming available. Submissions go through the CRA Single Reporting Platform to ENISA and the relevant national CSIRT. Legal alerts from Jones Day and Crowell & Moring have both noted that the duty reaches a wide range of products with digital elements, from consumer devices to industrial systems.
Finite State argues that the hardest part is not completing the form, but establishing whether the flaw is truly present in a shipped product and whether the vulnerable code path can actually execute. The company’s system analyses compiled firmware rather than relying only on source code or design documents, building an inventory of third-party components and tracing whether a function is reachable in a release already in circulation. In practice, that is intended to turn the first hours of the reporting window into drafting time rather than forensic work.
The company points to Quectel Wireless Solutions as an early example of why that preparation matters. Omar Aamer, Quectel’s Cybersecurity Compliance Manager, said the firm began building its evidence base before any regulator demanded it, which he said left it ready for the September deadline. He said the company can now provide documentation showing what is inside a module and how it assessed the risk, rather than depending on assurances alone.
September’s deadline is only the start. The CRA’s wider cybersecurity requirements and technical documentation obligations are due to apply from 11 December 2027, and Finite State says the same underlying records should support both phases. Similar evidence is also increasingly important outside Europe, including in automotive, industrial and medical-device compliance programmes, where regulators expect manufacturers to show what is in a product, what is known to be wrong with it and what was done about it.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





