24 hours: early warning to ENISA for actively exploited vulnerabilities: 24 hours (Source: Help Net Security, summarising CRA Article 14 (September 30, 2026))
Release day becomes the start of a clock
For most software teams, shipping has meant the end of a project. The EU Cyber Resilience Act (CRA) changes that for products it covers. In our view, the heaviest burden may be keeping old versions fixable for years, not the paperwork.
Help Net Security summarised how the CRA, regulation EU 2024/2847, applies to container and Kubernetes work. The article dates the regulation's start to Dec. 10, 2024. Reporting duties begin on Sept. 11, 2026. Full enforcement follows on Dec. 11, 2027.
The reporting date has already passed. On the source's timetable, the 24-hour reporting clock is live today. Only full enforcement is still ahead.
What the law reaches, and what it may not
Help Net Security lists the items in scope. They are container images that are distributed publicly, commercial Kubernetes operators, and Helm charts sold with support.
A container image is a packaged application. A Kubernetes operator is software that runs other software inside a cluster. A Helm chart is a bundle of settings used to install an application.
Where the vendor is based does not matter if the product is offered to EU customers. Open source is a grey area. The summary says such projects may be affected, mainly when a company stands behind them or sells support.
Buyers are touched too. A team that deploys a third-party operator may inherit some of the same duties. Help Net Security says teams must understand how each dependency is secured and updated.
One caution applies. This is a trade-press summary, not legal advice. Whether a given product counts is a question for counsel.
Why containers make a long duty hard
Under Article 14, a maker that learns of an actively exploited flaw has 24 hours to send a first alert to ENISA, the EU cybersecurity agency. A fuller notification is due within 72 hours.
Article 13 sets the second clock. Products need security updates for at least five years after they reach the market. If the expected product lifetime is shorter, that shorter period applies.
Containers make this hard because of how they are built. Every image sits on a base image. Any flaw in the base comes along into each image built on top of it. Fixing the base means rebuilding every image that uses it.
Older versions add a second problem. Customers keep running them. So the team needs to know which versions run where. It must keep rebuild pipelines working for old releases. And each patch must stay compatible with what customers already run.
Kubernetes multiplies the effort. The summary notes that one production system may mix applications, sidecars, monitoring agents and operators from many sources. Each has its own update habits. The 24-hour alert only works if detection covers every cluster.
What a runtime bill of materials adds
A Software Bill of Materials (SBOM) is a list of every component packaged in a product. The CRA expects organisations to keep one. The summary also points to a runtime bill of materials (RBOM).
An SBOM shows what is installed. An RBOM shows what actually runs. That gap matters. A flaw in code that executes is a different urgency from a flaw in a package that sits unused. With both lists, a team can sort its patching queue with more confidence.
Four questions for your team
The summary names four starting areas from the cloud native community: minimal containers, SBOM with RBOM, image distribution, and supply chain visibility. The questions below are WebPulse's own, one for each area.
First, do our images start from a stripped-down base, and can we show what was removed? Second, does our build pipeline produce both an SBOM and an RBOM automatically?
Third, can we say which version runs at which customer, and how a fix reaches them? Fourth, do we know who maintains each image we depend on, and how fast they patch? If a key dependency is slow, the summary says an alternative may be needed.
Two further steps are our own advice. Ask counsel which of your products are covered. Then name one person who owns the decision to send a 24-hour alert.
Time to adapt, but not for everything
Help Net Security says organisations distributing containerised products to the EU have time to adapt. It adds that the practices involved often take time to build.
Our view is that the reporting date changes that framing. Enforcement is still ahead, but the reporting duties are not. Teams that settle ownership and tooling early will face fewer rushed choices when a real alert arrives.
A release used to mark the end of the work. Under the CRA, for covered products, it marks the day the clock starts.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





