The reporting clock
The reporting clock: 24h early warning, 72h notification, 14-day/1-month final reports — live since Sep 11, 2026.
Free field guide · PDF
The reporting clock, the device exclusion, and the boundary cases — with the cybersecurity practice you need.
Sourced from verified 2026 publications.
Enter your work email and we'll send the PDF straight to your inbox.
What's inside
Every figure in this guide traces to a named source — verified 2026 publications.
The reporting clock: 24h early warning, 72h notification, 14-day/1-month final reports — live since Sep 11, 2026.
The device exclusion: medical devices sit under MDR/IVDR — your MDR cybersecurity program is your EU regime.
The boundary cases: separately marketed software components and open-source stacks can fall in scope.
This guide is market-access intelligence, not regulatory or legal advice. The CRA's scope boundaries, reporting procedures, and enforcement practice change — professional review is required before business use.
Market Access Strategy Session
A Market Access Strategy Session maps your cybersecurity route — CRA boundary analysis, MDR security obligations, and disclosure planning.
Professional review is required before business use.
Back to ghmap.io Questions? Talk to our team