GCS Threat Briefing
Regulation & Product Security

Aware Is Now A Legal Term

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
9 September 2026 · 7 min read
GCS Threat Briefing cover: Aware Is Now A Legal Term. Dark brand panel with the headline in white and red, a standfirst explaining that from Thursday 11 September 2026 any manufacturer selling software or connected products into the EU has 24 hours from becoming aware of an actively exploited vulnerability to file an early warning with ENISA, and four stat chips: 11 Sep Article 14 applies, 24 hours to early warning, 72 hours to notification, up to 15 million euros or 2.5% of turnover.

From Thursday 11 September, any company that sells software or connected products into the EU, including UK companies, has 24 hours from becoming aware of an actively exploited vulnerability in one of those products to file an early warning with ENISA and a national CSIRT. The portal it must use had no published web address as of Monday. The list of which national team receives the report was published on 4 September, one week before go-live. And the incidents of the past fortnight show that "becoming aware" is the part most vendors have never measured.

The Cyber Resilience Act has been read as a December 2027 problem, because that is when the design and CE-marking requirements apply. Article 14 does not wait. It applies from Thursday, to products already on the market, to manufacturers established outside the EU, and to a top-tier penalty band of up to €15m or 2.5% of worldwide turnover. The obligation is not to be secure. It is to know, quickly, and to say so.

24 hrsFrom awareness to the early warning under Article 14, weekends included
7 daysBetween ENISA publishing the coordinating CSIRT list and the obligation applying
15 daysAttackers were inside JetBrains Cadence before the vendor became aware
€15m / 2.5%Maximum fine for breaching Article 14, whichever is higher

What happened

Three developments converge this week. One is regulatory and dated. The other two are live incidents that show what the regulation is about to measure.

  • 27 July 2026The European Commission publishes implementation guidance on the CRA. Section 9.1 covers reporting. Freshfields' reading of it is that a manufacturer becomes aware when an initial assessment gives a "reasonable degree of certainty" that a vulnerability is being actively exploited or a severe incident has occurred.
  • 8 to 24 August 2026Attackers exploit CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution flaw in TeamCity, against JetBrains' own Cadence cloud service. JetBrains had patched the flaw in its product in July and added it to its own advisory. The Cadence server was not patched. JetBrains discovers the intrusion on 23 August, takes the server offline on 24 August and publishes on 28 August: "The server should have been patched as part of our response to the vulnerability, but it was not."
  • 4 to 7 September 2026The StyleSmuggler zero-day in Adobe Commerce and Magento is exploited against fully patched stores from 22:20 UTC on 4 September. Sansec publishes on 5 September. Adobe assigns CVE-2026-75650, confirms exploitation and ships a hotfix on the evening of 7 September.
  • 4 September 2026ENISA publishes the list of CSIRTs designated as coordinators for all 27 Member States and rewrites the Single Reporting Platform FAQ. It confirms: no API at launch, no voluntary reporting at launch, EU Login with multi-factor authentication required, and a public URL to be published "before the platform goes live".
  • 8 September 2026BleepingComputer reports Sophos' analysis of PoisonedRefresh, a Linux rootkit found on F5 BIG-IP APM devices. It injects a web shell into memory and leaves files on disk unchanged; its installer persists across BIG-IP upgrade images. Sophos assesses it as a second-stage payload, and F5 associates the related activity with systems affected by CVE-2025-53521, a flaw F5 reclassified from denial of service to remote code execution in March. Shadowserver counted 795 exposed endpoints still vulnerable to that flaw on 7 September.
  • 11 September 2026Article 14 applies. The Single Reporting Platform is scheduled to open the same day.
GCS infographic titled The Clock Starts At Awareness. A horizontal dark brand timeline with red markers. Awareness: the manufacturer reaches a reasonable degree of certainty of active exploitation, timestamp recorded. 24 hours: early warning filed through the ENISA Single Reporting Platform to the coordinating CSIRT and ENISA. 72 hours: notification with general information and an initial assessment. 14 days after a fix is available: final report for an actively exploited vulnerability; one month after the 72-hour notification for a severe incident. Below, six things ENISA confirmed on 4 September 2026: public URL published before go-live, no API in the initial release, no voluntary reporting at launch, EU Login with MFA for one Primary and up to 20 Secondary representatives, a 72-hour counter that currently starts 48 hours after the early warning is submitted, and outage guidance that nothing pauses the legal clock.
Article 14 deadlines run from awareness, weekends included, and the platform that receives them opens the same day the duty applies. Sources: Regulation (EU) 2024/2847, European Commission, ENISA FAQ updated 4 September 2026.

Why this one is different

Most regulatory deadlines ask a company to produce evidence of something it controls: a policy, a certificate, a control. Article 14 asks for something different. It puts a clock on a state of mind, and this week produced three examples of how long that state of mind takes to arrive.

The clock starts at awareness, and awareness is now a defined moment. The regulation counts from when the manufacturer becomes aware. The Commission guidance narrows that to the point where an initial assessment gives reasonable certainty of active exploitation. That is a judgement a named person has to make, on evidence, at a recorded time, and ENISA's field table lists that time as a required entry on the 24-hour form. JetBrains' own timeline shows the gap this measures: activity from 8 August, discovery on 23 August, offline on 24 August, public on 28 August. Fifteen days undetected is an engineering problem. Five days from awareness to disclosure is the interval the CRA now caps at 24 hours for the early warning, though the regulation is silent on when the public must be told. The obligation to inform impacted users is "without undue delay".

Patch status is not the test. Knowledge is. JetBrains had the fix for CVE-2026-63077 in July. The flaw was in its own product and it had shipped the patch to customers. The server that ran its own cloud service missed it. Under Article 14, whether the vendor had a patch is irrelevant to the reporting duty. What matters is whether it knew the flaw was being exploited, and when. That will be uncomfortable for any manufacturer whose vulnerability management and incident response run as separate functions, because the CRA treats them as one clock.

GCS infographic titled What Aware Looked Like This Week. Three dark brand cards. JetBrains Cadence: exploited from 8 August via CVE-2026-63077, discovered 23 August, offline 24 August, public 28 August; 15 days undetected, 5 days from awareness to disclosure; the vendor had patched the flaw in its product in July but not on its own server. Adobe StyleSmuggler: first exploitation 22:20 UTC on 4 September, researcher publishes 5 September, Adobe CVE and hotfix on the evening of 7 September; roughly 3 days from first exploitation to a vendor fix. F5 BIG-IP APM PoisonedRefresh: CVE-2025-53521 reclassified to remote code execution in March, Sophos analysis reported 8 September, second stage per Sophos with F5 linking the activity to that flaw, installer persists across upgrade images, 795 endpoints still vulnerable on 7 September. A callout reads: from 11 September, awareness starts a 24-hour clock.
Three incidents, three different intervals between exploitation, awareness and disclosure. From Thursday the middle interval carries a legal deadline. Sources: JetBrains, Sansec, Adobe, Sophos, Shadowserver.

The infrastructure for compliance arrived in the final week. ENISA's FAQ, updated on 4 September, says the platform's public URL will be published before it goes live, that there will be no API in the initial release, that voluntary reports under Article 15 cannot be filed at launch, and that the on-screen 72-hour counter currently starts 48 hours after the 24-hour report is submitted rather than at awareness, so a compliant filing can display as overdue. If the platform is unavailable, the guidance is to wait and file when it returns, contacting the CSIRT directly only where immediate communication is necessary. Nothing in that pauses the legal clock. A manufacturer that files quickly, which is what the law wants, will find the platform's timer stricter than the statute. The right response is to keep an internal record of the awareness timestamp and treat the portal's counter as a reminder, not a ruling.

The commercial exposure for UK organisations

Regulatory. The UK is outside the CRA, and that is where the misunderstanding starts. The regulation applies to products made available on the EU market regardless of where the manufacturer sits. A UK software vendor, device maker or SaaS company with an EU customer base is a manufacturer under Article 14 from Thursday. With no EU establishment, its coordinating CSIRT is determined by where its authorised representative acts, failing that where its importer or distributor places the most product, and failing that where it has the most users. Fines for breaching Article 14 sit in the top band with the essential security requirements: up to €15m or 2.5% of worldwide annual turnover, whichever is higher. Micro and small enterprises are exempt from fines for missing the 24-hour deadline itself, though not from the duty. Separately, the UK's own Cyber Security and Resilience Bill is bringing a 24-hour initial notification for regulated entities, which we covered in The 24-Hour Clock. A UK firm selling into the EU will in due course be running two clocks with different triggers.

Financial. The cost of compliance is modest: two EU Login accounts, a decision on the coordinating CSIRT with the reasoning written down, a product classification, and a drafted 24-hour form. The cost of non-compliance is asymmetric. Beyond the fine, a late or absent CRA notification becomes discoverable evidence in every downstream negotiation, from the enterprise customer's breach clause to the cyber insurer's renewal.

Contractual. This is the exposure for buyers rather than vendors, and it is the larger population. From Thursday, every EU-market supplier of software and connected products owes a regulator an early warning within 24 hours of awareness and owes impacted users notice without undue delay. Most UK supplier contracts still say "promptly" or "within a reasonable time". A buyer who lets the regulator hear before it does has accepted a worse position than the law now gives away for free. Contract notice terms should be rewritten to match Article 14: 24 hours, from awareness, weekends included.

Governance. The board question is not "are we CRA compliant", which is a 2027 question. It is "who in this company decides that we are aware, on what evidence, and can that person be reached at 02:00 on a Sunday". Article 14 has turned a security operations judgement into a regulatory event with a timestamp, and a company that has not named the person who makes it has not started.

What leaders should do now

  1. Decide whether you are a manufacturer, in writing, by Thursday. If the company places software, firmware, devices or connected products on the EU market, directly or through a distributor, it is in scope. Record the conclusion and the reasoning. Uncertainty is not a defence and the classification tools are public.
  2. Name the person who declares awareness. One accountable owner, with a deputy, empowered to conclude that active exploitation is established to a reasonable degree of certainty and to start the clock. Write the threshold down, with the evidence that meets it. Log the timestamp every time, including for events that turn out not to qualify.
  3. Stand up the reporting mechanics this week. Identify the coordinating CSIRT under Article 14(7) and record why. Create EU Login accounts with multi-factor authentication for a Primary and at least one Secondary assigned representative. Draft the 24-hour early warning in a shared location. Assume no API, and plan for the portal being unavailable.
  4. Rewrite supplier notice terms to the CRA standard. For every EU-market software and device supplier: notification of actively exploited vulnerabilities within 24 hours of the supplier's awareness, weekends included, plus a copy of any early warning filed with a CSIRT. The regulator should never know before the customer does.
  5. Join vulnerability management and incident response under one clock. JetBrains had the patch and missed its own server. The CRA does not care which team owned that failure. Run a timed exercise this month: a credible exploitation report arrives on a Friday evening, and the measure is hours to a declared awareness decision.
GCS infographic titled Five Decisions Before Thursday. A numbered dark brand checklist. One, Decide if you are a manufacturer: software, firmware, devices or connected products on the EU market, directly or via a distributor, record the reasoning. Two, Name who declares awareness: one accountable owner and a deputy, a written threshold, a logged timestamp every time. Three, Stand up the mechanics: identify the coordinating CSIRT, create EU Login accounts with MFA, draft the 24-hour form, assume no API. Four, Rewrite supplier notice terms: 24 hours from the supplier's awareness, weekends included, copy of any CSIRT filing. Five, One clock for vulnerabilities and incidents: run a timed Friday-evening exercise this month, measure hours to a declared awareness decision.
Five decisions an executive can take before Article 14 applies. None of them requires the portal to be open. Garzon Cyber Solutions, September 2026.

Three questions for the board

  1. Do we place any software, firmware or connected product on the EU market, and if so, who has concluded in writing that we are, or are not, a manufacturer under the Cyber Resilience Act?
  2. Who in this company is authorised to declare that we are aware of active exploitation, what evidence do they need, and how quickly could they be reached on a weekend?
  3. Which of our critical suppliers are now under a 24-hour reporting duty to a European regulator, and does our contract with them give us the same or better?

The strategic takeaway

The CRA's design requirements will make products safer in 2027. Article 14 changes something more immediate: from Thursday, the interval between a vendor learning it is being exploited and a regulator knowing is capped at 24 hours, and the moment of learning has a definition, an owner and a timestamp. That is a governance capability, not a compliance artefact. The companies that build it now will find it is also the thing their enterprise customers, insurers and, from the UK Bill onward, their own regulator start asking to see. The ones that treat it as a portal registration will discover the portal was never the hard part.

Confidence note

Confirmed. The 11 September 2026 application date, the 24-hour, 72-hour, 14-day and one-month deadlines, the Single Reporting Platform's launch scope (mandatory notifications only, no API, no voluntary reporting), the EU Login and multi-factor authentication requirement, the Primary and Secondary assigned representative structure, the 72-hour counter behaviour and the outage guidance are from the European Commission's CRA reporting page and ENISA's SRP FAQ updated 4 September 2026. The coordinating CSIRT rules for non-EU manufacturers are ENISA's statement of Article 14(7). The JetBrains Cadence timeline, the unpatched server admission and the affected data are from JetBrains' incident post, last updated 3 September 2026. The StyleSmuggler dates are from Sansec and Adobe, as set out in our briefing of 8 September. The penalty band of €15m or 2.5% of worldwide turnover for Article 14 breaches is Article 64(2) of Regulation (EU) 2024/2847.

Reported. The "reasonable degree of certainty" formulation is Freshfields' reading of the Commission's 27 July guidance; we have not independently reviewed section 9.1. The statement that the CSIRT list was published on 4 September and that the SRP URL was still unpublished on 7 September is from the independent tracker cyberresilienceact.eu, consistent with ENISA's own FAQ wording. The 795 F5 BIG-IP APM endpoints still vulnerable to CVE-2025-53521 is Shadowserver's count for 7 September as cited by BleepingComputer.

Assessment. Sophos assesses PoisonedRefresh as a second-stage payload; the association with CVE-2025-53521 is F5's, relayed by Sophos and BleepingComputer, and is not a confirmed initial-access finding. The Sophos analysis carries no visible publication date; we date it by BleepingComputer's report of 8 September. No source names a victim count for the F5 campaign. Whether Article 14 would have applied to JetBrains or Adobe in these specific scenarios is our illustration of the mechanism; neither incident falls under the obligation, which applies only to exploitation a manufacturer becomes aware of on or after 11 September 2026. This briefing is not legal advice; scope questions under the CRA should be taken to counsel.

Who declares awareness in your company, and by when?

Garzon Cyber Solutions is built to put product and supplier regulation on the risk register, map what regulators and enterprise customers will actually ask for, and place the people who own the answer. Cybersecurity, compliance and talent, delivered in that order, as one capability.

Start the Conversation →
Subscribe to GCS Insights
Cyber Resilience Act Regulation Product Security Third Party Risk Governance

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification and specialist technology recruitment as one integrated capability for organisations in the UK, EU and Americas. We are a young firm and we publish our own research. Founded by Jonathan Garzon, whose career was spent selling cybersecurity, compliance and technology to security and technology buyers.