What applies from September 2026?
If a vulnerability in your product is actively exploited (or a severe security incident occurs), you must submit an early warning to ENISA and the responsible national CSIRT within 24 hours, including for products already shipped and in the field.
The deadline cascade
Early warning within 24 hours, full notification within 72 hours, final report within 14 days of a fix (or one month after an incident). KONFORMA detects actively exploited vulnerabilities automatically (via CISA KEV) and prepares a pre-filled draft.
Who submits the report?
You do, as the manufacturer, always. KONFORMA prepares the draft but never submits anything on your behalf; sign-off and responsibility stay with you.