Investmentthese · Live
AI writes the exploits, Brussels writes the rules, and the certification labs write the invoices
The EU Cyber Resilience Act starts biting on 11 September 2026, turning product cybersecurity into a recurring audit fee collected by the TIC oligopoly.
Veröffentlicht am 28. August 2026 · Horizont 180 Tage · Regulierung
Diese Analyse ist noch nicht in Ihre Sprache übersetzt, deshalb zeigen wir das Original. Die Übersetzung folgt in Kürze.
Kausalkette: AI cuts exploit development from weeks to hours → EU Cyber Resilience Act reporting starts 11 Sep 2026 → Every connected product sold in the EU needs SBOM, vulnerability handling and a cyber CE m → Important and critical classes require third party conformity assessment → Notified body capacity is scarce, so audit slots are rationed and priced up → Certification becomes a recurring per product, per update fee → Testing and certification oligopoly collects the fee
What this thesis rests on
Each one is a statement that has to be true. We go back to every live thesis on a schedule and check these against public sources, so each leg carries either what we found or the date we look next.
Checked every 14 days. First review due 11. September 2026.
-
○
The EU does not postpone the Cyber Resilience Act's vulnerability reporting obligation beyond its 11 September 2026 start date.
regulatory · Open
First check due 11. September 2026
-
○
The Commission does not remove smart home devices, VPNs, password managers or network management systems from the Cyber Resilience Act's important product classes before 30 June 2027.
regulatory · Open
First check due 11. September 2026
-
○
At least 10 notified bodies are designated for the Cyber Resilience Act in the EU NANDO database before 30 June 2027.
operational · Open
First check due 11. September 2026
-
○
At least two of UL Solutions, Bureau Veritas, SGS and Intertek publicly launch a dedicated Cyber Resilience Act conformity or readiness service before 30 April 2027.
competitive · Open
First check due 11. September 2026
-
○
UL Solutions reports organic revenue growth of at least 5% year over year in each of the two quarterly results published after this thesis.
financial · Open
First check due 11. September 2026
Assumptions are written in English, because that is the language of most of the sources we check them against.
The date nobody in the market has circled
A hundred technology companies spent this week warning that AI is about to compress the time between a vulnerability being disclosed and a working exploit existing from weeks to hours. The market reflex is to buy cybersecurity software. That reflex misses the more mechanical consequence, which arrives on a fixed calendar date: on 11 September 2026, two weeks from now, the EU Cyber Resilience Act's reporting obligations switch on. From that day, any manufacturer placing a product with digital elements on the EU market must send an early warning to ENISA and the relevant national CSIRT within 24 hours of learning that a vulnerability in its product is being actively exploited, with a fuller notification inside 72 hours.
Die interaktive These öffnen
Interaktive Kausalkarte, der Korb im Chart gegen seinen Markt und die vollständige Zeitleiste.
In Invesaro öffnen →
This is analysis, not investment advice and not a recommendation to buy or sell anything. We publish it and track it in public, mistakes included. Any decision is yours and yours alone.