Cyber Resilience Act: What changes this week and how Element is preparing
On 11 September 2026, the first substantive deadline under the Cyber Resilience Act (Regulation (EU) 2024/2847, "the CRA") will come into effect. This Regulation entered into force on 10 December 2024, but it applies in stages, and this week’s date is the second of three stages.
As from 11 September, manufacturers of products with digital elements placed on the EU market become subject to the reporting obligations set out in Article 14. Essentially, an actively exploited vulnerability, or an incident that severely affects the security of a product, now has to be notified to the relevant Computer Security Incident Response Team (CSIRT) and to the European Union Agency for Cybersecurity (ENISA) within a strict timetable:
- An early warning, within 24 hours of becoming aware of the incident or actively exploited vulnerability
- A more detailed follow-up notification, within 72 hours
- A final report once the matter is resolved, within 14 days to 1 month, depending on the type of issue.
This post sets out what this means for Element, why it applies differently depending on which product is involved, and what is still ahead of the CRA’s fuller application in December 2027.
Element as original manufacturer
We have previously discussed the distinction the CRA makes between an open source project without commercial intentions, and the entity that first places a product on the market with commercial intent – the "original manufacturer," in the regulation’s own terminology.
This distinction is key to understanding what kind of compliance support you might expect to receive from Element when it comes to your own CRA obligations. Element develops and stewards open source software including the Community Edition of the Element Server Suite. On the other hand, where Element packages, sells and supports a product commercially, we are the manufacturer of that product, and take on the CRA’s obligations for it directly. This is the case for Element Server Suite Pro (ESS Pro).
As a product placed on the market for commercial purposes, ESS Pro sits inside the CRA’s scope in full; the essential requirements in Annex I once those apply from December 2027, and, from this week, the Article 14 reporting timetable for actively exploited vulnerabilities and severe incidents.
Meeting that timetable depends on having a working path from disclosure to notification; a single point where security disclosures are received, an internal escalation route from that inbox to whoever can assess exploitation and severity quickly enough to meet a 24-hour clock, and a defined interface into the CSIRT and ENISA reporting channels themselves.
As a security minded organisation, these requirements are already largely in line with our existing procedures. Much of the groundwork required for CRA compliance is something we have been working towards for a while, embedding best practice into our organisational modus operandi. This includes, but is not limited to, a maintained Software Bill of Materials for ESS Pro, a record of the components it depends on, and change control over the code that ships in it.
By contrast, Element X and the Community Edition of the Element Server Suite are made available by Element without being placed on the market, and therefore do not come with manufacturer obligations. This is important to consider, and one of the reasons why we do not recommend using ESS Community for professional deployments. We won’t be able to support your organisation’s compliance obligations if you’re not using the Pro products.
What comes next
This week marks an early milestone, but it’s not the end of the journey. The main obligations (i.e. the essential requirements in Annex I, covering secure-by-design development, documented vulnerability assessment processes and conformity assessments) become enforceable in full from 11 December 2027.
On our side the work continues towards our CE marking and evaluating the need for third-party certification. Our recommendation to our customers and partners is very simple. Start engaging with the process now, ensure that any changes required are incremental and embedded with your company’s culture, and find trusted suppliers and partners, such as Element, that can help simplify your journey through this and other regulations.