Skip to content
folhas.io
secure by design for connected products· Logbook

Logbook· entry 004

004 · The day the countdown reached zero

The reporting obligations of Article 14 became applicable today. What changes for those who already have products on the market, what we did with the advance notice, and why the OTA entry waits one more round.

Published

Entry 003 promised that this one would be about OTA updates over rural connectivity. That will be the next one. Today is 11 September 2026, and the calendar that has been on this site’s homepage since day one reached the milestone it always highlighted: the reporting obligations of Article 14 of the CRA became applicable. A logbook documenting the preparation for a regulation could not walk past the day its first part started to count.

What changed today

From today, a manufacturer that becomes aware of an actively exploited vulnerability in one of its products with digital elements, or of a severe incident with an impact on that product’s security, has deadlines: early warning within 24 hours, notification within 72, final report at closure. Notification goes through the single reporting platform, to the CSIRT designated as coordinator and to ENISA. Anyone wanting the detail of who notifies, through which channel and with what content has the article we published on this — it was written precisely with this day in mind.

The milestone should be seen at its true size. Full application remains set for 11 December 2027, and only then do the essential cybersecurity requirements of Annex I become enforceable. What began today is narrower: the obligation to tell, quickly and through the right channel, when something goes wrong.

CRA timeline with the 11 September 2026 milestone highlighted and the today marker coinciding with it: on the left, the 640 days of preparation since entry into force in December 2024; on the right, the stretch where the reporting obligation is already applicable, up to full application in December 2027, 456 days away.
The calendar axis on the day the today marker caught up with the milestone: the preparation is behind us, the reporting deadlines have started to run.

What this means for us

Nothing, in the legal sense: Aeromate is not on the market and none of these deadlines touches us. It is the note of rigour we have kept on the homepage since day one, and it remains exact.

But the date served as an internal deadline. Decision 4 of entry 001 said the reporting process gets built before there is anything to report, and decision 5 promised a PGP key and a formal disclosure policy. The key is now published, referenced in this site’s security.txt. The templates for the three notifications belong to Phase 3 of the entry 003 plan, and rehearsing them with no product on the market is the only time the exercise can be done without a clock running.

For those who already have a product on the market

If you manufacture a product with digital elements that is already on sale, today matters to you more than the 2027 date everyone talks about. The question for the team this week is not “are we compliant?”, it is “if we learnt right now of an active exploitation, who would do what in the first 24 hours?”. If the answer is slow to appear, article 02 has the list of what to prepare.

The countdown that starts again

The homepage calendar changed target today without anyone touching it: the next milestone is now full application, 456 days away. For us that is the deadline that counts, because it is the world Aeromate intends to be born into.

Entry 005 returns to the technical work: the secure OTA update over rural, intermittent connectivity, the first of the three open questions from entry 001. If the first attempt fails, that too gets written down.