The Cyber Resilience Act started asking something of your software suppliers on 11 September 2026, and few English firms will have noticed. I have read a fair number of supplier agreements across fourteen years of running a practice, and almost none of them promised to tell me when the software went wrong. This regulation does not rewrite those agreements and it is not English law. It gives the company that built your case management system a legal duty to tell somebody, quickly, when a fault in its product is being exploited.
The instrument is European, Regulation (EU) 2024/2847. It came into force in December 2024 and most of it waits until 11 December 2027. The reporting part arrived early and is running now. A manufacturer of a product with digital elements has to move once it becomes aware that a vulnerability in that product is being actively exploited, or that a severe security incident has affected it. An early warning goes in within 24 hours, a fuller notification describing the fault and the work in hand follows inside 72 hours, and the final report comes no later than 14 days after a fix is available. A severe incident carries a month for that closing report instead. All of it goes through a single platform run by the European Union cybersecurity agency and reaches the national response team where the manufacturer is established, which passes it on to the teams in the other countries where the product is sold.
Why a European regulation reaches your desk
You manufacture nothing, so no part of this lands on your firm. The duty sits on whoever places the product on the European market, and that catches a good many of the companies selling software into the legal sector here. A practice management supplier with Irish clients is inside the scope whatever its own address, and so is a document automation tool sold across the continent. Part of your technology stack is therefore run by businesses keeping a 24 hour clock in September that they were not keeping in August.
That is worth something to you. Until now the honest answer to when a supplier would tell you about a hole in its own product was whenever it chose to, and the contract usually said less than you hoped. An outside authority now holds a record of what was reported and when. You will not see those reports, because they travel to response teams rather than to customers, but a filed report matters if you ever have to reconstruct who knew what and on which day.
What the clock does not do for you
Read this as tightening the supplier rather than relieving you. Your duty to keep client information confidential is yours, and it does not move because a manufacturer in Dublin or Munich now has a form to complete. The regulation imposes no obligation on your supplier to tell you, its paying customer, anything at all inside 24 hours. It addresses faults in the product rather than every mishap inside the supplier's own business, so a compromise of its support desk is a separate question. It says nothing at all about your client data, which stays governed by the UK GDPR and by whatever you signed.
The question to put to your suppliers
Ask each of the suppliers that matter whether the reporting duty catches them. Most will know by now, and one that says no should be able to explain why, because the answer tells you whether it sells into Europe at all. Then ask the question the regulation leaves open, being what the supplier undertakes to tell you, and within what period, when it files a report about a product your firm is running. A business keeping a 24 hour duty to a state authority can reach its customers inside the same day, and one that will not put that in writing has shown you where you sit in its order of priority. Put the answers in the file you keep on that supplier, next to where your data sits and how you would get it back.
Where this goes next
The larger part of the regulation, covering the security standards the products themselves have to meet, applies from 11 December 2027, and the stewards of open source software come in on the same date. Any supplier selling in Europe will then have to show its product meets those standards, so ask what work it has in hand at your next renewal rather than late in 2027. Put the reporting question on the agenda for the supplier review you have coming, and ask for the disclosure undertaking in writing while you still have a signature to withhold.
The European Commission's own page on the Cyber Resilience Act reporting obligations sets out the deadlines and the platform, and it opens without registration.
If you want the supplier questions in this piece turned into a short schedule you can send out this week, tell us which suppliers matter and we will draft it.
