CRA, NIS2 and PSTI for Connected Devices | SIMSY

The evidence builds itself while you get on with it.

Regulation now expects you to know what your connected equipment is doing, keep it patched across its life, and prove both when somebody asks. SIMSY makes those three things a property of how the network works rather than a project you have to run alongside everything else.

11 September 2026: the first binding Cyber Resilience Act deadline. What it asks for

Four hard parts, made ordinary.

Every one of these regulations comes back to the same practical questions. Can you see it, can you limit it, can you prove it, and can you fix it.

You can see what is happening

Network level visibility across the whole estate. Usage patterns, connection behaviour, traffic capture. You find out a device has started behaving differently from the network itself, rather than waiting for the device to tell you or a customer to complain.

There is less to go wrong

Your devices are not reachable from the public internet, so they are not scanned, not probed and not swept up in opportunistic exploitation. The cheapest incident to report is the one that never happened.

The record already exists

Configuration changes, network activity and device state are recorded as normal operation. When an auditor or a customer asks what a device was doing on a given date, you are looking something up rather than reconstructing it.

You can actually fix it

Remote access and firmware management across every device, wherever it is. A fix goes out in an afternoon instead of becoming a schedule of site visits stretching into next month.

The last one carries more weight than it looks. Reporting duties are process, and process can be arranged in a fortnight. Deploying a fix to equipment scattered across the country is physical, and it is the part that runs out of time.

A vulnerability in your fleet.

An actively exploited flaw is disclosed in firmware running on eight hundred of your devices. Under the CRA the clock starts the moment you become aware. Here is where the difference actually shows up.

ClockThe usual positionWith SIMSY
Hour 0Are we affected? Which units run that firmware version, and where are they? Somebody starts building a spreadsheet.Query the estate. You already know which devices, which versions and which sites.
Hour 24Early warning due, with only partial knowledge of scope. You report what you have and hope it holds.Early warning submitted with accurate scope, because the numbers came from the network rather than an estimate.
Hour 72Full notification due. Has anything been exploited on your estate? Without traffic visibility this is difficult to answer either way.Traffic capture and connection history show what actually happened on affected devices, not what might have.
Days 3 to 30Deploy the fix. Eight hundred devices, many on customer sites, some needing appointments. This is where weeks go.Push firmware remotely across the estate. Done in an afternoon, and the ones that failed are visible immediately.
Final reportDue 14 days after a corrective measure is available. If the rollout is still running, that date keeps moving.The corrective measure was available on day three, so the clock stopped on day three.

How SIMSY helps you get there. Secure access to every device, an evidence trail recorded as normal network operation, reporting on your fleet's state at any point in time, and alerting the moment something changes.

These are all an important part of achieving compliance and maintaining it once you have it.

Deadline: 11 September 2026

September is a reporting duty, not a compliance audit.

Most coverage of the Cyber Resilience Act points at December 2027, however reporting requirements started in September 2026.

From 11 September 2026, if you become aware of an actively exploited vulnerability in your product, or a severe incident affecting its security, you have to report it. Two triggers, and if neither happens, Article 14 asks nothing of you. What makes it demanding is the clock.

24h

Early warning

From becoming aware, to your national CSIRT via the ENISA Single Reporting Platform.

72h

Full notification

A fuller account of the vulnerability or incident and what you are doing about it.

14d

Final report

After a corrective measure is available for an exploited vulnerability. A month for a severe incident.

How SIMSY makes the clock manageable. You can only report what you have detected, and you can only close a report once a fix has been deployed. SIMSY delivers both as standard.

Network level visibility surfaces events as they happen, and remote firmware and configuration lets you push a corrective measure across the estate in an afternoon rather than a schedule of site visits. Detection and remediation are what the clock actually tests, and both are built into how the platform runs.

What applies, and when

DateRegulationDetail
In force nowUK PSTIConsumer connectable products sold in the UK. No universal default passwords, a means of reporting vulnerabilities, and a published minimum support period.
In force nowNIS2Organisations in essential and important sectors across the EU. Risk management, supply chain security and incident reporting, transposed into national law by each member state.
11 Sep 2026CRA reporting, Article 14Manufacturers of products with digital elements report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT. Applies to products already on the market.
11 Dec 2027CRA in fullEssential cybersecurity requirements and vulnerability handling become binding, including secure default configuration, SBOM documentation and updates across the support period.

How they compare

RegulationApplies toBroadly asks for
UK PSTIManufacturers, importers and distributors of consumer connectable products sold in the UKNo universal default passwords, a vulnerability disclosure contact, a stated minimum security update period
EU CRAManufacturers of products with digital elements placed on the EU market, including products already soldVulnerability and incident reporting from September 2026, then essential requirements and vulnerability handling from December 2027
NIS2Organisations in essential and important sectors in the EU, and their suppliersRisk management, supply chain security, incident reporting and management accountability

Many organisations are caught by more than one. A manufacturer selling into both markets can be inside PSTI and the CRA at once, and inside NIS2 as a supplier to somebody who is.

See the evidence trail for yourself.

Get a SIM, connect a device, and look at what is recorded without anybody configuring anything. It is the quickest way to judge whether this makes your next audit shorter.

Sources: European Commission, CRA reporting obligations. Regulation (EU) 2024/2847. UK Product Security and Telecommunications Infrastructure Act 2022. Directive (EU) 2022/2555. Last reviewed 2026-08-29.