The evidence builds itself while you get on with it.
Regulation now expects you to know what your connected equipment is doing, keep it patched across its life, and prove both when somebody asks. SIMSY makes those three things a property of how the network works rather than a project you have to run alongside everything else.
11 September 2026: the first binding Cyber Resilience Act deadline. What it asks forFour hard parts, made ordinary.
Every one of these regulations comes back to the same practical questions. Can you see it, can you limit it, can you prove it, and can you fix it.
You can see what is happening
Network level visibility across the whole estate. Usage patterns, connection behaviour, traffic capture. You find out a device has started behaving differently from the network itself, rather than waiting for the device to tell you or a customer to complain.
There is less to go wrong
Your devices are not reachable from the public internet, so they are not scanned, not probed and not swept up in opportunistic exploitation. The cheapest incident to report is the one that never happened.
The record already exists
Configuration changes, network activity and device state are recorded as normal operation. When an auditor or a customer asks what a device was doing on a given date, you are looking something up rather than reconstructing it.
You can actually fix it
Remote access and firmware management across every device, wherever it is. A fix goes out in an afternoon instead of becoming a schedule of site visits stretching into next month.
The last one carries more weight than it looks. Reporting duties are process, and process can be arranged in a fortnight. Deploying a fix to equipment scattered across the country is physical, and it is the part that runs out of time.
A vulnerability in your fleet.
An actively exploited flaw is disclosed in firmware running on eight hundred of your devices. Under the CRA the clock starts the moment you become aware. Here is where the difference actually shows up.
| Clock | The usual position | With SIMSY |
|---|---|---|
| Hour 0 | Are we affected? Which units run that firmware version, and where are they? Somebody starts building a spreadsheet. | Query the estate. You already know which devices, which versions and which sites. |
| Hour 24 | Early warning due, with only partial knowledge of scope. You report what you have and hope it holds. | Early warning submitted with accurate scope, because the numbers came from the network rather than an estimate. |
| Hour 72 | Full notification due. Has anything been exploited on your estate? Without traffic visibility this is difficult to answer either way. | Traffic capture and connection history show what actually happened on affected devices, not what might have. |
| Days 3 to 30 | Deploy the fix. Eight hundred devices, many on customer sites, some needing appointments. This is where weeks go. | Push firmware remotely across the estate. Done in an afternoon, and the ones that failed are visible immediately. |
| Final report | Due 14 days after a corrective measure is available. If the rollout is still running, that date keeps moving. | The corrective measure was available on day three, so the clock stopped on day three. |
How SIMSY helps you get there. Secure access to every device, an evidence trail recorded as normal network operation, reporting on your fleet's state at any point in time, and alerting the moment something changes.
These are all an important part of achieving compliance and maintaining it once you have it.
September is a reporting duty, not a compliance audit.
Most coverage of the Cyber Resilience Act points at December 2027, however reporting requirements started in September 2026.
From 11 September 2026, if you become aware of an actively exploited vulnerability in your product, or a severe incident affecting its security, you have to report it. Two triggers, and if neither happens, Article 14 asks nothing of you. What makes it demanding is the clock.
Early warning
From becoming aware, to your national CSIRT via the ENISA Single Reporting Platform.
Full notification
A fuller account of the vulnerability or incident and what you are doing about it.
Final report
After a corrective measure is available for an exploited vulnerability. A month for a severe incident.
How SIMSY makes the clock manageable. You can only report what you have detected, and you can only close a report once a fix has been deployed. SIMSY delivers both as standard.
Network level visibility surfaces events as they happen, and remote firmware and configuration lets you push a corrective measure across the estate in an afternoon rather than a schedule of site visits. Detection and remediation are what the clock actually tests, and both are built into how the platform runs.
What applies, and when
| Date | Regulation | Detail |
|---|---|---|
| In force now | UK PSTI | Consumer connectable products sold in the UK. No universal default passwords, a means of reporting vulnerabilities, and a published minimum support period. |
| In force now | NIS2 | Organisations in essential and important sectors across the EU. Risk management, supply chain security and incident reporting, transposed into national law by each member state. |
| 11 Sep 2026 | CRA reporting, Article 14 | Manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT. Applies to products already on the market. |
| 11 Dec 2027 | CRA in full | Essential cybersecurity requirements and vulnerability handling become binding, including secure default configuration, SBOM documentation and updates across the support period. |
How they compare
| Regulation | Applies to | Broadly asks for |
|---|---|---|
| UK PSTI | Manufacturers, importers and distributors of consumer connectable products sold in the UK | No universal default passwords, a vulnerability disclosure contact, a stated minimum security update period |
| EU CRA | Manufacturers of products with digital elements placed on the EU market, including products already sold | Vulnerability and incident reporting from September 2026, then essential requirements and vulnerability handling from December 2027 |
| NIS2 | Organisations in essential and important sectors in the EU, and their suppliers | Risk management, supply chain security, incident reporting and management accountability |
Many organisations are caught by more than one. A manufacturer selling into both markets can be inside PSTI and the CRA at once, and inside NIS2 as a supplier to somebody who is.
See the evidence trail for yourself.
Get a SIM, connect a device, and look at what is recorded without anybody configuring anything. It is the quickest way to judge whether this makes your next audit shorter.
Sources: European Commission, CRA reporting obligations. Regulation (EU) 2024/2847. UK Product Security and Telecommunications Infrastructure Act 2022. Directive (EU) 2022/2555. Last reviewed 2026-08-29.