For most companies preparing for the EU Cyber Resilience Act (CRA), December 11, 2027 has been the date circled on the calendar. That is when the CRA’s broad product cybersecurity requirements (including vulnerability handling, security testing, and security updates) generally start to apply. But one important part of the CRA has become effective much earlier. Since September 11, 2026, manufacturers have been required to report certain actively exploited vulnerabilities and severe security incidents affecting products with digital elements (PDEs). And the reach of that obligation may be broader than many companies expect.