CRA reporting has been live since 11 September: who in your company owns the 24-hour report?

Evotalents
Evotalents October 2, 2026

Friday evening. A security researcher emails a SaaS company to say there's a vulnerability in the app its customers install on their computers. Attackers are already using it to get into users' machines. Until this summer, that stayed between the company and the researcher. Since 11 September 2026, the Cyber Resilience Act has changed the rules: if the product is sold in the EU, the manufacturer has 24 hours to report it officially through an ENISA platform. The report is filed by a named person who registered on the platform in advance and has the authority to decide, on their own, that a report is needed. For most companies, that makes the CRA a hiring problem, because nobody on the team holds that role yet.

At IT recruiting agency EvoTalents, we fill roles in cybersecurity, embedded and defense tech, so we look at the CRA from the recruiting side. We want to know who owns the report, which roles it takes and how long those people take to hire. Below we cover what the law actually requires, why your SOC won't catch this, and which specialists to start looking for now.

1. What changed on 11 September

Article 14 of the Cyber Resilience Act has applied since 11 September 2026. Any manufacturer of a product with digital elements sold on the EU market must notify the authorities in two situations.

First: the product has a vulnerability and attackers are already using it. This means there is reliable evidence of an attack on a real system, for example a customer's device. A vulnerability found in internal testing that nobody has exploited doesn't count.

Second: a severe incident has hit the security of the product itself. For example, an attack has knocked customers' devices offline, data has leaked from them, or malicious code has made it into an update.

For the first two stages, the deadlines are the same in both cases:

  • early warning: within 24 hours of the company becoming aware of the attack or incident;
  • notification: within 72 hours, with general information on how the vulnerability was exploited and an initial assessment;
  • final report: for a vulnerability, no later than 14 days after a patch or other mitigation becomes available; for a severe incident, within one month of the 72-hour notification.

Every stage goes through ENISA's Single Reporting Platform (SRP), which went live the same day. The manufacturer also has to tell affected users and, where it makes sense, explain how they can protect themselves.

The duty also covers products that were already on the market. If a company knew about attacks before 11 September, it doesn't have to report them retroactively. If attacks started or came to light after that date, a report is required, even if the vulnerability itself was found long ago.

Most of the CRA, including the product security requirements, SBOMs and vulnerability handling, applies from 11 December 2027. Breaching Article 14 can cost up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Micro and small companies get one concession: they can't be fined for missing the 24-hour early warning. The 72-hour notification and the final report are just as binding for them as for everyone else.

2. Who reports, and to whom

The CRA attaches obligations to the market where the product is sold. A UK, US or Asian manufacturer selling into the EU reports under the same rules as a German one.

The report goes to the coordinating CSIRT of the country where the company has its main establishment, meaning the place where decisions on the product's cybersecurity are mostly taken. For companies with no such establishment in the EU, Article 14(7) sets a fallback order. Pick the wrong CSIRT and the notification can be treated as invalid, so you have to file again. ENISA published the list of coordinating CSIRTs for all 27 Member States on 4 September.

One vulnerability or incident means one notification for the whole corporate group. Even if there are several subsidiaries in the EU and the parent company sits outside it, coordinating inside the group is the manufacturer's job. That is why the owner of the process has to sit at group level, not inside a single legal entity.

Third-party components need a separate note. A vulnerability in a library or module has to be reported too if that component is in your product and it's your product that's being attacked. Contracts with your supplier don't change the deadlines.

3. When the clock starts and what filing looks like

The European Commission's guidance of 27 July 2026 describes the moment of awareness this way: an initial assessment gives a reasonable degree of certainty that a vulnerability is being actively exploited or a severe incident has happened. "Actively exploited" means there is reliable evidence that a malicious actor has used the vulnerability in someone's system without the owner's permission.

Someone in the company has to make that call and document it. That person decides when the 24 hours start and whether the company can later walk the regulator through its timeline.

How the platform works in practice

  • Access is through EU Login with MFA. A manufacturer registers one Primary Assigned Representative (AR) and up to 20 Secondary ARs.
  • Only the AR who created a draft can see it. If you have one AR and they're on holiday, the report is stuck.
  • There's no API and the interface is English-only, so reports are filled in by hand. If the platform is down, the report still has to go through it once it's back up.

4. The UK angle: PSTI is already in force, CSRB is on its way

The UK's PSTI regime for consumer connected products has been in force since 29 April 2024. It bans universal default passwords, requires a published contact point for reporting security issues with response timelines, and requires a stated minimum period of security updates. Fines reach £10 million or 4% of worldwide revenue.

So a PSTI-compliant company already has an address a security researcher can write to. PSTI doesn't say who handles those emails, reproduces the exploit and reports to a regulator within 24 and 72 hours. The CRA adds those duties, along with SBOMs and a full vulnerability handling process.

The Cyber Security and Resilience Bill completed Lords Committee stage on 7 September 2026. Report Stage is provisionally scheduled for 26 October, and that date may still move. The Bill covers managed service providers (MSPs) regulated by the ICO, data centres, large load controllers and designated critical suppliers. It sets an initial notification to the regulator and the NCSC within 24 hours and a full report within 72 hours. Fines for serious breaches reach £17 million or 4% of worldwide turnover. Royal Assent is expected between late 2026 and spring 2027, with most duties arriving through secondary legislation.

A UK software or device vendor that also provides managed services could end up with two 24-hour clocks: one under the CRA for its products and one under the CSRB for its services.

5. Why this is a job for a PSIRT

A SOC watches the company's own infrastructure: its network, endpoints and accounts. CRA signals often come from outside. It might be an email from a security researcher, a message from a customer's CERT, a new CISA KEV entry, or an attack on an embedded component in devices that have been running at customer sites for years. A SOC usually never sees any of that.

A PSIRT (Product Security Incident Response Team) is responsible for the company's products and the people who use them. FIRST has a separate framework for PSIRTs, distinct from the one for CSIRTs, with six service areas: stakeholder management, vulnerability discovery, triage and analysis, remediation, disclosure, and training. Job specs in this space reference ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling), CVSS v3.1/v4 and CNA procedures.

Large manufacturers have had this function for a long time: Cisco's PSIRT dates back to 1995, Ericsson's to 2004 and Bosch's to 2016. Mid-sized companies selling devices or software into the EU will mostly have to build one from scratch.

Here's how we recommend splitting responsibility. Legal and compliance own the wording of reports and customer notices. The decision to file belongs to the PSIRT lead, whose right to file without further sign-off is written down.

6. How ready companies are

October is European Cybersecurity Month, and this year ENISA is focusing it on people's skills. The 2026 numbers show that people and processes are where companies are furthest behind on the CRA:

  • 66% of 843 organisations surveyed are unfamiliar or only slightly familiar with the CRA, up from 62% a year earlier. Among US and Canadian companies the figure is 72%.
  • 41% of those who know about the CRA haven't worked out whether it applies to them. Only 41% expect to be fully compliant by December 2027.
  • 57% of micro companies have nobody responsible for cybersecurity. 41% of small and medium-sized companies run vulnerability management processes, and 35% use SBOMs.
  • 59.47% of consumer IoT manufacturers worldwide have no vulnerability disclosure policy. Among new market entrants, only 16 out of 68 have one.

Meanwhile, demand in the job market is growing. Core cyber security job postings in the UK rose 7% in 2025, and the share of businesses lacking basic technical skills went up from 49% to 57%. London leads on the number of vacancies. Over the last six months, UK application security job ads came to 392, against 159 a year earlier, and vulnerability management contracts to 790, against 329. Some of that growth may come from changes in the data sources, but the trend is clear.

7. Which roles to open now

PSIRT lead (Head of Product Security / PSIRT Manager)

Owns the whole process. Decides on the moment of awareness, runs triage, files reports in the SRP and owns the coordinated vulnerability disclosure (CVD) policy. The rarest candidates are those who combine technical triage with a grasp of regulatory requirements and can talk calmly to security researchers, CSIRTs and customers.

Product security / embedded security engineer

Reproduces the exploit, assesses the impact on a specific firmware or product version and works with developers on the fix. For devices and industrial products, IEC 62443 and embedded engineering experience are often required.

Vulnerability management lead

Keeps the vulnerability register, CVSS scores and remediation deadlines, and matches CISA KEV and threat intel against product SBOMs. This is the easiest role to fill with a contractor for the transition period.

SBOM / supply-chain security engineer

Produces and maintains SBOMs for every product, sets up SCA in the CI/CD pipeline and tracks third-party components, which run on the same 24-hour clock.

Where candidates come from

When we work as a headhunter on these roles, candidates usually come from three directions. SOC and CSIRT engineers bring speed and triage experience. Penetration testers and embedded/IoT security specialists know how to reproduce exploits. AppSec and DevSecOps engineers know SBOMs, SCA and the pipeline. Job specs now ask for CVSS, CVE/CNA workflows, ISO/IEC 29147/30111, SBOM tooling, threat modelling/TARA and working knowledge of the CRA's Annex I and Article 14.

Salaries and timelines

Role and market Pay
Application Security, London (permanent) median £100,000; 25th percentile £80,000; 90th £115,000
Application Security, UK (permanent) median £75,000
Vulnerability Management, UK (contract) median £550 per day
Vulnerability Management Lead, London (contract) £550-610 per day
CSIRT, UK (closest proxy for PSIRT) median £90,000, small sample
Security Engineer, Amsterdam €92,000
Security Engineer, Dublin, 5+ years €80,000-100,000

There's no salary series for PSIRT roles specifically in the UK, so we benchmark against adjacent roles. Senior cybersecurity vacancies in London stay open 46 days longer on average than other IT roles, and hiring often takes three to six months. If you open the search in 2027, you'll be competing with every manufacturer who remembers the deadline at the same time.

For the transition period, you can bring in PSIRT-as-a-service or a vulnerability management contractor. They cover monitoring and drafting. The legal duty and the awareness decision stay with the manufacturer.

All four roles share the same difficulty: the profile is very narrow. A candidate needs to understand embedded systems down to the code and know how a product behaves after years in the field. Each country has only a handful of these people, so the search usually runs across several countries and through specialist communities. Our case with a company the CRA hits directly, a maker of AI cameras and IoT security systems, shows what that looks like in practice. We filled embedded, backend and AI roles for them. None of those were PSIRT positions, but we were searching the same narrow talent pools.

EVOTALENTS CASE STUDY: FIVE TECHNICAL DIRECTIONS FOR AN IoT SECURITY MANUFACTURER

Client: security technology company building AI-powered smart cameras and IoT surveillance systems, Ukraine and Poland, 50-100 employees. Level: senior engineers. Format: long-term partnership since 2023.

Situation

The company needed to scale its team in five directions at once: Python/Go backend, embedded C/C++, video streaming infrastructure, LLM/AI research and hardware engineering. Every role called for an autonomous senior engineer, and candidate pools in these niches are tiny. Hardware roles required people on site in a Kyiv lab. Limits on military service deferrals for staff and expansion into Poland made it harder still.

EvoTalents approach

  • A dedicated recruiter team ran all five directions in parallel.
  • Each direction had its own sourcing strategy: direct outreach to passive candidates for senior backend, academic networks for AI/LLM research, and hardware job boards and engineering meetups for embedded.
  • Searches through Python, Go, embedded and AI/ML communities in Ukraine and Poland.
  • Hiring market intelligence on Poland to support the client's expansion.

Result

  • 7+ positions filled, partnership ongoing.
  • Partnership length: 2.5+ years, since 2023.
  • Pipeline: 100-200+ candidates per role.
  • Search geography: Ukraine and Poland.

Client feedback: "When EvoTalents faces difficulties, they never give up. They take the challenge, try different approaches, communicate all their concerns, get feedback. At the end of the day, we got the best candidates."

For a camera and IoT device maker, the CRA adds a few more roles: PSIRT lead, embedded security engineer and vulnerability management. Candidates for them sit in the same narrow pools as embedded C/C++ engineers, so the search has to go through specialist communities, across several countries, with its own sourcing strategy for each role. Below is what a company can do on its own in the first three months.

The first 90 days: a plan for CTOs and CISOs

Days 1-30: name an owner

Appoint a PSIRT lead or an interim owner and put their right to file in writing. Register a Primary AR and at least two Secondary ARs on EU Login with MFA. Identify your coordinating CSIRT. Publish a security.txt and a CVD policy aligned with ISO/IEC 29147.

Days 31-60: build the process

Write your awareness criteria into the triage playbook. Build SBOMs for the products you sell in the EU and match them against CISA KEV. Prepare templates for each SRP stage and for user notifications. Draw up an escalation map that shows parallel deadlines under NIS2, DORA, GDPR and, later, the CSRB.

Days 61-90: test it with people

Set up a 24/7 on-call rota of at least three or four people, because one person can't cover a 24-hour clock over the weekend. Run your first tabletop exercise and check whether you can get the right people together within 24 hours. Open the permanent roles and, for the transition period, bring in a contractor or PSIRT-as-a-service.

The most common mistakes

Handing reporting to the SOC by default. The SOC doesn't receive emails from security researchers and can't see what's happening to devices at customer sites.

Registering a single AR. Nobody else can see their drafts, so a holiday or sick day stops the filing.

Waiting for legal sign-off before filing. The 24 hours run from the moment of awareness, not from when the legal team reads the email.

Assuming the CRA doesn't apply to a UK company. If the product is sold in the EU, the obligations apply, and a company with no main establishment in the EU picks its CSIRT through the fallback procedure.

Forgetting products already on the market and third-party components. The deadlines cover both.

Outsourcing accountability along with the work. A provider can draft reports and monitor feeds, but the manufacturer is the one who reports.

Putting off hiring until 2027. A senior search takes three to six months, and the company will reach the December deadline without a team.

FAQ

Does the CRA apply to a UK company selling devices or software into the EU?

Yes. The CRA attaches obligations to the market where the product is sold. A UK manufacturer picks its coordinating CSIRT using the fallback order in Article 14(7), registers an AR on EU Login and reports through the SRP on the same 24- and 72-hour deadlines. If the company also provides managed services, 24-hour reporting under the UK's CSRB may be added later.

When does the 24-hour CRA reporting clock start?

At the moment of awareness. The European Commission defines it as the point when an initial assessment gives a reasonable degree of certainty that a vulnerability is being actively exploited or a severe incident has happened. Companies should write down their awareness criteria and who makes that call. That record is how the company will explain its timeline to the regulator.

Are CRA fines for a missed report already in force?

The duty to report has applied since 11 September 2026. Article 64 provides for fines of up to €15 million or 2.5% of worldwide turnover for breaching Article 14. Some lawyers read the fine regime itself as formally applying only from 11 December 2027, but no authority has confirmed that reading. Micro and small companies are exempt from fines only for a missed 24-hour early warning.

How long does it take to hire a PSIRT lead in London, and what does it cost?

Senior cybersecurity hires in the UK often take three to six months. There's no dedicated salary data for PSIRT roles. The closest benchmarks are a £100,000 median for application security in London and around £90,000 for CSIRT roles across the UK. Leads who combine technical triage with regulatory experience usually cost more than the median.

Can you cover PSIRT through outsourcing or staffing?

Partly. PSIRT-as-a-service and vulnerability management contractors can handle monitoring, triage and drafting for the transition period. The awareness decision and legal responsibility for the report stay with the manufacturer, so you still need an in-house PSIRT lead. Cybersecurity recruitment agencies can help with both: a fast contractor now and a permanent lead within a few months.

Build the team that files on time

EvoTalents fills cybersecurity and information security roles: PSIRT leads, product security and embedded security engineers, and vulnerability management specialists. Tell us which products you sell in the EU and who currently owns reporting, and we'll put together a hiring plan that fits your deadlines.

Discuss hiring