The EU Cyber Resilience Act's 24-Hour Clock Started 11 September. Your Connected Vending Machine Is Now a Regulated Product.
The EU Cyber Resilience Act’s first hard deadline landed on 11 September 2026, and a connected vending machine is squarely inside it. The CRA — Regulation (EU) 2024/2847 — treats every “product with digital elements” sold into the EU as a regulated product, and a smart vending machine, smart locker, or self-service kiosk with a cellular modem, a controller, and firmware is exactly that. From 11 September 2026 the manufacturer must report an actively exploited vulnerability to ENISA and the national CSIRT within 24 hours of becoming aware — 72 hours for the full notification, 14 days for the final report. The obligation is retroactive: it covers machines already on the market, even ones sold years ago. From 11 December 2027 every new machine needs Annex I cybersecurity by design, technical documentation, and CE marking. The difference between surviving this and failing it is who owns the software. A builder who designs hardware and firmware in-house can answer “are we affected” the moment a CVE lands. A reseller who bolts a third-party 4G module onto a cabinet cannot.
The clock already started.
Not in 2027.
Not when your next machine ships.
On 11 September 2026 — nine days ago.
If a vulnerability in your connected vending machine is being actively exploited right now, and you become aware of it, you owe ENISA a report within 24 hours.
That is not a draft proposal.
That is Article 14 of the EU Cyber Resilience Act, and it is live.
The Regulation
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the EU’s first binding cybersecurity law for hardware and software.
It entered into force on 10 December 2024.
It applies to every “product with digital elements” placed on the EU market.
A smart vending machine is one.
A smart locker is one.
A self-service kiosk with a cellular modem and firmware is one.
If the machine transmits data, processes data, or runs code, it is in scope.
The only thing outside scope is a genuinely dumb machine — coin-only, no modem, no controller.
Everything you have sold as “smart” or “connected” is regulated now.
Three Dates. One Already Passed.
| Date | Obligation |
|---|---|
| 11 June 2026 | Member states designate conformity assessment bodies |
| 11 September 2026 | Article 14 reporting starts — actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT |
| 11 December 2027 | Full compliance — Annex I security requirements, technical documentation, CE marking |
The first date is gone.
The second date is the one most manufacturers are not ready for.
The third is the one they are treating as the only deadline.
That is the mistake.
The 24-Hour Clock
Here is how the reporting cascade works once you become aware of an actively exploited vulnerability.
- 24 hours — early warning to ENISA and the coordinating national CSIRT.
- 72 hours — full notification, with the nature of the exploit, impact, and mitigations.
- 14 days — final report, after a fix becomes available. (One month for a severe incident.)
“Actively exploited” does not mean “vulnerable.”
A 9.8 CVE sitting in a dependency with no observed exploitation does not start the clock.
A 6.5 CVE that someone is using in the wild does — the moment you become aware.
And the clock is retroactive.
Article 69(3) extends the reporting obligation to products placed on the market before December 2027.
A machine you sold in 2023 is covered.
If it gets exploited and you learn about it, you report — regardless of whether it was ever designed against Annex I, whether it carries a CE mark, or when it shipped.
The Gap Most Buyers Miss
The obligation does not land on the distributor.
It lands on the entity that controls the product’s digital elements.
That is where the procurement question gets sharp.
| Builder who owns the stack | Reseller who assembles parts | |
|---|---|---|
| Knows what firmware is inside | Yes | No |
| Can produce a software bill of materials | Yes | No |
| Can sign and push a patch | Yes | No |
| Can answer “are we affected” when a CVE lands | Yes | No |
| CRA status when selling into the EU | Manufacturer — controls compliance | Importer — carries obligations it cannot meet |
When a reseller places a non-EU machine on the EU market, the CRA treats it as the importer.
The importer carries obligations.
The importer does not control the software.
That is a liability with no lever to pull.
What KioskForce Builds Instead
The security posture is not a bolt-on.
It is the consequence of who owns the design.
KioskForce designs its hardware and software in-house — the controller, the firmware, and the cloud layer are all built by the same team that builds the cabinet.
A smart vending machine whose code you own is a product you can secure, patch, and report on.
One whose code you rent is a liability you carry.
That means the answer to “are we affected” is knowable.
The firmware is signable.
The patch is pushable.
The software bill of materials exists because the software was written, not resold.
A connected PPE dispenser, tool vending machine, or smart locker is a product with digital elements under the CRA — and the entity that should own that compliance is the entity that wrote the code.
For a machine built around an off-the-shelf controller and a third-party 4G module, that ownership never existed.
Five Questions for Any Connected Machine You Buy
- Who wrote the firmware? If the answer is “a third-party controller vendor,” you do not control your CRA obligations.
- Can the builder produce a software bill of materials? If not, “are we affected” is unanswerable on the day a CVE lands.
- Can the machine receive signed firmware updates over the air? A patch you cannot deploy is a report you cannot close.
- Does the builder have an incident-response path to ENISA and a national CSIRT? The 24-hour clock does not wait for you to hire a security team.
- Is the machine’s connectivity segmented from your network? A vending machine is a device on your LAN — it should be treated as a network asset, not furniture.
If any of these has no answer, you are buying a liability, not a machine.
The Compliance Question Has a Supplier Answer
The Cyber Resilience Act did not change what a good builder does.
It changed what a bad one can get away with.
A manufacturer that owns its software stack was already doing firmware signing, patch management, and documentation.
The CRA just made those the legal floor instead of a differentiator.
From 11 December 2027, every connected machine needs CE marking under the CRA.
From 11 September 2026 — now — every connected machine already carries a 24-hour reporting duty.
The machine you buy next is either built by someone who can answer that clock, or it is not.
Spec who owns the code.
Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act); European Commission, “Cyber Resilience Act” and “Commission publishes new guidance to support timely Cyber Resilience Act implementation” (27 July 2026); cyberresilienceact.eu, “CRA Reporting: 24h, 72h & 14-Day Deadlines (Article 14)”; Finite State, “EU Cyber Resilience Act for IoT: Secure by Design Guide”; Consult Red, “EU Cyber Resilience Act (CRA): What You Need to Do Now.”
Want something like this built?
We design and manufacture custom vending machines, kiosks and the cloud software behind them. Tell us what you have in mind.
Contact Us for More Information