A plain-language walkthrough for a solo founder or small software vendor who just found out this applies to them and has no compliance team to hand it to.
The Cyber Resilience Act (Regulation (EU) 2024/2847) covers "products with digital elements" placed on the EU market — which in practice means almost any software or connected hardware sold to EU customers, not just critical infrastructure or big enterprise vendors. If you have even one paying EU customer for a SaaS product, a plugin, a mobile app, or a device with firmware, you're in scope. There's no small- business carve-out for the reporting obligation itself, though enforcement priorities in the first year are widely expected to focus on larger or higher-risk vendors first. This is not legal advice — see the disclaimer below — but the plain text of the Regulation does not exempt small vendors from Article 14.
Two separate triggers exist under Article 14, and they're easy to conflate:
Most small vendors will encounter the first case: a dependency they ship (a library, a framework, an OS package) gets a CVE added to a known-exploited list, and now the clock is running on their product, even though they didn't write the vulnerable code.
| Report | Deadline | What it contains |
|---|---|---|
| Early warning | 24 hours from awareness | Basic facts: what's affected, that it's being exploited, cross-border relevance if known |
| Follow-up notification | 72 hours from awareness | Updated assessment, initial indicators of compromise, corrective measures taken/planned |
| Final report | 14 days after a fix is available | Full description, severity, impact, and remediation details |
"Awareness" is the operative word for the clock start — not when the CVE was published, but when you became aware it applies to your product. That's exactly the gap a monitoring tool closes: most small vendors aren't watching CISA's or ENISA's feeds daily, so "awareness" can arrive days late purely from not checking.
It's not the reporting itself — ENISA's forms are short. It's missing the clock entirely because nobody on a two-person team is checking a government vulnerability feed every day on top of shipping product. Penalties for non-compliance run up to €15M or 2.5% of global annual turnover, though realistically first-year enforcement focus and proportionality provisions matter — this piece isn't legal advice on your specific exposure.
ExploitWatch checks CISA's KEV catalog against a plain-text list of your dependencies, free, with no signup. If you want it checked daily going forward — so you find out the moment something matches instead of finding out when it's already a problem — that's the $19/mo version below.
Try the free check →