Zero Day
A vulnerability drops in your shipped product. The CRA reporting clock starts now.
You are the Product Security Lead at Kastos IoT, a 340-employee Dutch company that manufactures smart building access control systems — hardware panels, a companion mobile app, and a cloud management platform. Your flagship product, the Kastos K400, is CE-marked and deployed across 2,800 commercial buildings in 14 EU member states. It is Tuesday, 14 December 2027 — three days after the CRA's full application date. A security researcher has just emailed your PSIRT inbox.
- Kastos IoT — 340 employees, €62M revenue, HQ Rotterdam
- K400 smart access panel: hardware + mobile app + cloud backend
- CE-marked under CRA self-assessment (default category) in September 2027
- SBOM generated for v3.2 firmware — top-level dependencies documented
- PSIRT established 8 months ago. Vulnerability disclosure policy published
- CRA vulnerability reporting obligation active since 11 September 2026

