A focused research drill for manufacturers of products with digital elements that need to operate under the Cyber Resilience Act reporting clock. From 11 September 2026, covered manufacturers must report actively exploited vulnerabilities and severe incidents through the EU Single Reporting Platform, with an early warning within 24 hours and a fuller notification within 72 hours.
The output is a workflow score, missing-control map and prioritized reporting runbook. It is not legal advice, compliance certification, a security assessment, or an official regulatory submission.
Broad CRA readiness checklists already exist. This experiment tests a narrower operational question: if a potentially reportable security event became known today, could your organisation establish the clock, classify the event, assemble the evidence, coordinate ownership and reach the submission point before the 24-hour and 72-hour deadlines?
Early-stage research experiment. No payment is being collected and no compliance determination is being made.