Operational notes Regulation

Chapter IV has applied since June, the Italian authority has not

7 min read

Corridor of a public building with a closed double door at the far end, black-and-white photograph
The office exists in the law. The nameplate on the door does not, yet.

If, in a month, you had to report an actively exploited vulnerability on a product you sell — or have integrated into your own plant — could you say who owns the 24-hour early warning, who owns the 72-hour notification, who writes the report at fourteen days after the fix, and on which platform? And what if the product is not in this year’s catalogue, but one sold three years ago and still under support?

That is not a hypothetical question: it answers to a calendar already written, part of which has already passed with almost nobody noticing.

Europe is not waiting for Italy

Regulation (EU) 2024/2847 — the Cyber Resilience Act — applies in full only from 11 December 2027. But Article 71(2) carves out two exceptions landing much sooner: “Chapter IV (Articles 35 to 51) shall apply from 11 June 2026” — two months ago — and “Article 14 shall apply from 11 September 2026” — in a month. Recital 126 explains why: operators need time to adjust, but not at the same pace for everything.

Chapter IV contains Article 36, the notifying authority. Paragraph 1 is explicit: “Each Member State shall designate a notifying authority that shall be responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and their monitoring, including compliance with Article 41.” Paragraph 4 adds that the authority “shall assume full responsibility” even when it delegates the task, and Article 37 requires it to be free of “conflicts of interest” with the bodies it oversees. It is the door through which a product obtains — or fails to obtain — the conformity it needs to stay on the European market. And in Europe that door has been open since June.

Italy’s delegation: six months expiring on 9 October

In Italy, that door has no nameplate yet. Law No. 36 of 17 March 2026 — the European delegation law, in force since 9 April 2026 — delegates the Government, under Article 15(1), to adopt within six months of entry into force one or more legislative decrees implementing Regulation (EU) 2024/2847. Six months from April give a date that is our own calculation, not one written into the law: 9 October 2026, less than two months away.

Paragraph 2 sets out who does what: letter b), ACN — Italy’s national cybersecurity agency — as “the notifying authority under Article 36”; letter c), the same Agency as the market surveillance authority under Article 52. Letter a): coordination with Decree-Law 105/2019 (Italy’s cyber security perimeter) and Legislative Decree 138/2024 (the NIS transposition decree). Letter d): coordination with the authorities under Legislative Decree 157/2022. Letter e): repeal of incompatible national rules. Letter f): penalties that are “effective, dissuasive and proportionate”, even by derogation from Article 32(1)(d) of Law 234/2012, coordinated — as to procedure — with Article 17(4-quater) of Decree-Law 82/2021, revenue reassigned to ACN’s budget; letter g), adequate “human, instrumental and financial resources”. Paragraph 3 puts figures behind that letter: €2,100,000 for 2026, €5,875,000 for 2027, €9,125,000 for 2028 and €6,925,000 a year from 2029, drawn from the fund for transposing EU legislation.

The decree is not there, for now

As things stand, no implementing legislative decree has been published in the Official Gazette. This is a check on the primary source, with a window still open: the Official Gazette’s General Series summaries can be read up to issue No. 183 of 8 August; 9 August was a Sunday, with no Gazette; issue No. 184 of 10 August had not yet been published as of the afternoon; the last legislative decree issued remains No. 141 of 5 August, unrelated to cyber resilience. This is not proof the decree will not arrive soon: it is a snapshot of what can be checked today — as with the NIS2 Directive’s 12 October deadline, where the real deadline is read in a document too, not a headline. And the missing ACN designation, to be clear, suspends none of your obligations towards Europe: it only suspends the Italian part — who assesses your certification bodies, who inspects you, under which procedure.

See the service · Talk to an engineer

Article 14’s three windows are running regardless

From 11 September, Article 14 requires the manufacturer to notify simultaneously the coordinating CSIRT and ENISA, through the single reporting platform under Article 16:

  • point (a): an early warning within 24 hours of the manufacturer becoming aware of the actively exploited vulnerability;
  • point (b): a notification within 72 hours, with the information available on the product and the exploitation;
  • point (c): a final report within 14 days of the corrective measure being made available, with severity, impact and, if known, the malicious actor.

The same scheme applies to severe incidentswe have already broken down the clock. What matters here is the scope of products covered, and it is not what you would expect: Article 69(3) expressly derogates from the rule that would exempt products already sold — “the obligations under Article 14 shall apply to all products with digital elements falling within the scope of this Regulation which have been placed on the market before 11 December 2027.” It does not matter when you sold it: it matters whether you still support it — the same movement already seen for hardware components.

An economy, not a general shortcut

A point worth repeating, since it invites misreading: Article 31(3) allows a single technical documentation for products also subject to other EU acts, but only “for the products with digital elements referred to in Article 12” — those that are also high-risk AI systems. It is not a horizontal rule: for the rest of the market, the overlap between the CRA and other regimes — SBOM included — remains an economy to build, not an obligation already written.

Whoever waits for the decree arrives late twice

Whoever waits for the decree before organising is betting on two things at once: that Italy will meet the 9 October deadline — our own calculation, not a certainty — and that Europe will ask nothing of them meanwhile. Neither bet is reasonable. The question every reader should answer straight away is simple: if we discovered today that one of our products — even one we no longer make — has an actively exploited vulnerability, would we know who opens the early warning within 24 hours, and with what evidence we would prove the exact time we found out? For most organisations, the honest answer is no. This is a regulatory reading based on primary sources, not legal advice: your specific case needs a proper conversation.

Complying, in practice, means the three windows of Article 14 become a check running on your systems and documents: who detects the vulnerability, who classifies it as actively exploited, who opens the early warning, and where the exact moment of first awareness is logged — the 24 hours start from there, not the meeting the next day. With a dated trail ready for inspection, by ACN or by a CSIRT meanwhile. And the scope to cover, under Article 69(3), is not today’s catalogue: it is everything placed on the market before 11 December 2027, including product lines closed long ago.

Deciding is the next step: the same system holds together your product inventory, software bills of materials, supply contracts and archives in a single operating model, on which AI agents execute decisions with a human operator in command — for large enterprises, defence, public administration and healthcare. When an advisory hits a library used in one of your products, “who needs to be told within 24 hours” arrives in hours, not weeks. Always two modes: on-premises, without deep network integration, or dedicated cloud with a data centre in Italy, with shared management.

The first session, at no cost, produces a deliverable that stays yours even if you go no further: the dated list of your products still on the market or under support, with, for each one, who the manufacturer is, who opens the early warning within 24 hours, and where first awareness is logged — including the boxes left empty. Keep it ready for 9 October: if the delegation slips, the calendar remains yours — kept current in our deadlines tool too.

Half an hour with one of our engineers, at no cost, to find out whether your 24 hours are really 24 hours.

Sources